Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://AAYUSHRELOCATEPACKERSANDMOVERS.COM

Overview

General Information

Sample URL:https://AAYUSHRELOCATEPACKERSANDMOVERS.COM
Analysis ID:1586044
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 2596 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1900,i,1093151166700518159,15029610476940593397,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6556 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://AAYUSHRELOCATEPACKERSANDMOVERS.COM" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://cdn.jsinit.directfwd.com/sk-jspark_init.phpAvira URL Cloud: Label: malware
Source: https://aayushrelocatepackersandmovers.com/HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: aayushrelocatepackersandmovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aayushrelocatepackersandmovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://aayushrelocatepackersandmovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: aayushrelocatepackersandmovers.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Wed, 08 Jan 2025 15:53:48 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Sat, 13 Aug 2022 07:46:18 GMTAccept-Ranges: bytesContent-Length: 583Vary: Accept-EncodingContent-Type: text/html
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 08 Jan 2025 15:53:48 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Sat, 13 Aug 2022 07:48:48 GMTAccept-Ranges: bytesContent-Length: 583Vary: Accept-EncodingContent-Type: text/html
Source: chromecache_43.2.dr, chromecache_44.2.drString found in binary or memory: http://cdn.jsinit.directfwd.com/sk-jspark_init.php
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal48.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1900,i,1093151166700518159,15029610476940593397,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://AAYUSHRELOCATEPACKERSANDMOVERS.COM"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1900,i,1093151166700518159,15029610476940593397,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://AAYUSHRELOCATEPACKERSANDMOVERS.COM0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://cdn.jsinit.directfwd.com/sk-jspark_init.php100%Avira URL Cloudmalware
https://aayushrelocatepackersandmovers.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
aayushrelocatepackersandmovers.com
162.241.148.33
truefalse
    unknown
    www.google.com
    142.250.185.228
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://aayushrelocatepackersandmovers.com/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      https://aayushrelocatepackersandmovers.com/false
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://cdn.jsinit.directfwd.com/sk-jspark_init.phpchromecache_43.2.dr, chromecache_44.2.drfalse
        • Avira URL Cloud: malware
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        162.241.148.33
        aayushrelocatepackersandmovers.comUnited States
        46606UNIFIEDLAYER-AS-1USfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1586044
        Start date and time:2025-01-08 16:52:41 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 59s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://AAYUSHRELOCATEPACKERSANDMOVERS.COM
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@16/4@4/4
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.185.227, 216.58.206.78, 64.233.167.84, 142.250.186.174, 142.250.184.238, 142.250.181.238, 199.232.210.172, 192.229.221.95, 142.250.185.238, 142.250.185.174, 142.250.185.142, 142.250.184.206, 142.250.186.78, 142.250.186.131, 172.217.18.14, 23.56.254.164, 172.202.163.200, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://AAYUSHRELOCATEPACKERSANDMOVERS.COM
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):583
        Entropy (8bit):5.11550204447751
        Encrypted:false
        SSDEEP:12:vQ0AMyHWBFc+sc3Ea2KVdNxtNufiCRiTkJsU3++W6OQ4NbxBShQL:vQFrWMAEafVfN+iCR2kJe+P4NjSK
        MD5:59F6AE7C7F154EC74D418D4ED6FC5B0E
        SHA1:674860108A41AB23BA5F73635749332BD8A46B7E
        SHA-256:50E0767F2731DA7DDB56D719DC85A7F830C4A860D8F09D0F25401D3DC7097D7D
        SHA-512:501F35D5347BD1F20024A1C76172874E0026289F6DD60DE6A1F83EF2DEB0FFF07CD75C45B4DCF693A7C2FF903528BEDBD05C2B9F9BB439D294F5F904427173F7
        Malicious:false
        Reputation:low
        URL:https://aayushrelocatepackersandmovers.com/
        Preview:<html>.<head>. <style>. .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; }. @keyframes spin { 0% { transform: rotate(0deg); } 100% { transform: rotate(360deg); } }. </style>. <script language="Javascript">var _skz_pid = "9PO5645V6";</script>. <script language="Javascript" src="http://cdn.jsinit.directfwd.com/sk-jspark_init.php"></script>.</head>.<body>.<div class="loader" id="sk-loader"></div>.</body>.</html>.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):583
        Entropy (8bit):5.11550204447751
        Encrypted:false
        SSDEEP:12:vQ0AMyHWBFc+sc3Ea2KVdNxtNufiCRiTkJsU3++W6OQ4NbxBShQL:vQFrWMAEafVfN+iCR2kJe+P4NjSK
        MD5:59F6AE7C7F154EC74D418D4ED6FC5B0E
        SHA1:674860108A41AB23BA5F73635749332BD8A46B7E
        SHA-256:50E0767F2731DA7DDB56D719DC85A7F830C4A860D8F09D0F25401D3DC7097D7D
        SHA-512:501F35D5347BD1F20024A1C76172874E0026289F6DD60DE6A1F83EF2DEB0FFF07CD75C45B4DCF693A7C2FF903528BEDBD05C2B9F9BB439D294F5F904427173F7
        Malicious:false
        Reputation:low
        URL:https://aayushrelocatepackersandmovers.com/favicon.ico
        Preview:<html>.<head>. <style>. .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; }. @keyframes spin { 0% { transform: rotate(0deg); } 100% { transform: rotate(360deg); } }. </style>. <script language="Javascript">var _skz_pid = "9PO5645V6";</script>. <script language="Javascript" src="http://cdn.jsinit.directfwd.com/sk-jspark_init.php"></script>.</head>.<body>.<div class="loader" id="sk-loader"></div>.</body>.</html>.
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 16:53:38.231692076 CET49675443192.168.2.4173.222.162.32
        Jan 8, 2025 16:53:45.740295887 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:45.740328074 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:45.740408897 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:45.740669966 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:45.740689039 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.486336946 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.490052938 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:46.490072966 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.491162062 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.491215944 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:46.492392063 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:46.492465973 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.543065071 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:46.543075085 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:46.589977980 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:47.731978893 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.732002974 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:47.732074022 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.732521057 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.732546091 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:47.732765913 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.733046055 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.733059883 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:47.733565092 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:47.733577013 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.325351000 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.325927973 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.325942993 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.326946020 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.327023983 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.330404043 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.330632925 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.330647945 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.331707001 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.331778049 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.333098888 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.333170891 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.333468914 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.333539963 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.333594084 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.333606958 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.374299049 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.374300957 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.374306917 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.421474934 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.582071066 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.582148075 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.582196951 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.583446026 CET49740443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.583462954 CET44349740162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.642282009 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.683340073 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.804048061 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.808746099 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:48.808804035 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.809020042 CET49741443192.168.2.4162.241.148.33
        Jan 8, 2025 16:53:48.809036016 CET44349741162.241.148.33192.168.2.4
        Jan 8, 2025 16:53:49.912919998 CET49672443192.168.2.4173.222.162.32
        Jan 8, 2025 16:53:49.912965059 CET44349672173.222.162.32192.168.2.4
        Jan 8, 2025 16:53:53.697303057 CET4972380192.168.2.4199.232.214.172
        Jan 8, 2025 16:53:53.710247993 CET8049723199.232.214.172192.168.2.4
        Jan 8, 2025 16:53:53.710324049 CET4972380192.168.2.4199.232.214.172
        Jan 8, 2025 16:53:56.276705027 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:56.276781082 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:53:56.278775930 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:57.828457117 CET49737443192.168.2.4142.250.185.228
        Jan 8, 2025 16:53:57.828468084 CET44349737142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:42.094588995 CET4972480192.168.2.4199.232.214.172
        Jan 8, 2025 16:54:42.099546909 CET8049724199.232.214.172192.168.2.4
        Jan 8, 2025 16:54:42.099608898 CET4972480192.168.2.4199.232.214.172
        Jan 8, 2025 16:54:45.795555115 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:45.795598030 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:45.795676947 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:45.795921087 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:45.795932055 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:46.456247091 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:46.456629992 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:46.456644058 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:46.457003117 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:46.457515955 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:46.457590103 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:46.499699116 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:56.351455927 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:56.351509094 CET44349846142.250.185.228192.168.2.4
        Jan 8, 2025 16:54:56.351607084 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:57.829237938 CET49846443192.168.2.4142.250.185.228
        Jan 8, 2025 16:54:57.829262972 CET44349846142.250.185.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 16:53:41.350218058 CET53545281.1.1.1192.168.2.4
        Jan 8, 2025 16:53:41.477329016 CET53651621.1.1.1192.168.2.4
        Jan 8, 2025 16:53:42.469024897 CET53576931.1.1.1192.168.2.4
        Jan 8, 2025 16:53:45.731971979 CET5594253192.168.2.41.1.1.1
        Jan 8, 2025 16:53:45.732181072 CET5743853192.168.2.41.1.1.1
        Jan 8, 2025 16:53:45.738912106 CET53574381.1.1.1192.168.2.4
        Jan 8, 2025 16:53:45.739191055 CET53559421.1.1.1192.168.2.4
        Jan 8, 2025 16:53:47.354700089 CET5076053192.168.2.41.1.1.1
        Jan 8, 2025 16:53:47.354895115 CET5904253192.168.2.41.1.1.1
        Jan 8, 2025 16:53:47.666914940 CET53507601.1.1.1192.168.2.4
        Jan 8, 2025 16:53:47.814080954 CET53590421.1.1.1192.168.2.4
        Jan 8, 2025 16:53:53.686100006 CET138138192.168.2.4192.168.2.255
        Jan 8, 2025 16:53:59.524064064 CET53533931.1.1.1192.168.2.4
        Jan 8, 2025 16:54:18.365010023 CET53636351.1.1.1192.168.2.4
        Jan 8, 2025 16:54:41.000396013 CET53619581.1.1.1192.168.2.4
        Jan 8, 2025 16:54:41.488934040 CET53587111.1.1.1192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Jan 8, 2025 16:53:47.814204931 CET192.168.2.41.1.1.1c23c(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 8, 2025 16:53:45.731971979 CET192.168.2.41.1.1.10xb04bStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 8, 2025 16:53:45.732181072 CET192.168.2.41.1.1.10x9131Standard query (0)www.google.com65IN (0x0001)false
        Jan 8, 2025 16:53:47.354700089 CET192.168.2.41.1.1.10x15eeStandard query (0)aayushrelocatepackersandmovers.comA (IP address)IN (0x0001)false
        Jan 8, 2025 16:53:47.354895115 CET192.168.2.41.1.1.10x69b2Standard query (0)aayushrelocatepackersandmovers.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 8, 2025 16:53:45.738912106 CET1.1.1.1192.168.2.40x9131No error (0)www.google.com65IN (0x0001)false
        Jan 8, 2025 16:53:45.739191055 CET1.1.1.1192.168.2.40xb04bNo error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
        Jan 8, 2025 16:53:47.666914940 CET1.1.1.1192.168.2.40x15eeNo error (0)aayushrelocatepackersandmovers.com162.241.148.33A (IP address)IN (0x0001)false
        • aayushrelocatepackersandmovers.com
        • https:
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449740162.241.148.334435180C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-08 15:53:48 UTC677OUTGET / HTTP/1.1
        Host: aayushrelocatepackersandmovers.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-08 15:53:48 UTC261INHTTP/1.1 403 Forbidden
        Date: Wed, 08 Jan 2025 15:53:48 GMT
        Server: Apache
        Upgrade: h2,h2c
        Connection: Upgrade, close
        Last-Modified: Sat, 13 Aug 2022 07:46:18 GMT
        Accept-Ranges: bytes
        Content-Length: 583
        Vary: Accept-Encoding
        Content-Type: text/html
        2025-01-08 15:53:48 UTC583INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 2e 6c 6f 61 64 65 72 20 7b 20 62 6f 72 64 65 72 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 66 33 66 33 66 33 3b 20 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 33 34 39 38 64 62 3b 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 35 30 25 3b 20 77 69 64 74 68 3a 20 31 32 30 70 78 3b 20 68 65 69 67 68 74 3a 20 31 32 30 70 78 3b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 73 70 69 6e 20 32 73 20 6c 69 6e 65 61 72 20 69 6e 66 69 6e 69 74 65 3b 20 70 6f 73 69 74 69 6f 6e 3a 20 66 69 78 65 64 3b 20 74 6f 70 3a 20 34 30 25 3b 20 6c 65 66 74 3a 20 34 30 25 3b 20 7d 0a 20 20 20 20 20 20 20 20 40 6b 65 79 66 72 61 6d 65 73 20 73 70 69 6e 20 7b 20
        Data Ascii: <html><head> <style> .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; } @keyframes spin {


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449741162.241.148.334435180C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-08 15:53:48 UTC624OUTGET /favicon.ico HTTP/1.1
        Host: aayushrelocatepackersandmovers.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://aayushrelocatepackersandmovers.com/
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-08 15:53:48 UTC261INHTTP/1.1 404 Not Found
        Date: Wed, 08 Jan 2025 15:53:48 GMT
        Server: Apache
        Upgrade: h2,h2c
        Connection: Upgrade, close
        Last-Modified: Sat, 13 Aug 2022 07:48:48 GMT
        Accept-Ranges: bytes
        Content-Length: 583
        Vary: Accept-Encoding
        Content-Type: text/html
        2025-01-08 15:53:48 UTC583INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 2e 6c 6f 61 64 65 72 20 7b 20 62 6f 72 64 65 72 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 66 33 66 33 66 33 3b 20 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 33 34 39 38 64 62 3b 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 35 30 25 3b 20 77 69 64 74 68 3a 20 31 32 30 70 78 3b 20 68 65 69 67 68 74 3a 20 31 32 30 70 78 3b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 73 70 69 6e 20 32 73 20 6c 69 6e 65 61 72 20 69 6e 66 69 6e 69 74 65 3b 20 70 6f 73 69 74 69 6f 6e 3a 20 66 69 78 65 64 3b 20 74 6f 70 3a 20 34 30 25 3b 20 6c 65 66 74 3a 20 34 30 25 3b 20 7d 0a 20 20 20 20 20 20 20 20 40 6b 65 79 66 72 61 6d 65 73 20 73 70 69 6e 20 7b 20
        Data Ascii: <html><head> <style> .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; } @keyframes spin {


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:10:53:33
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:10:53:40
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1900,i,1093151166700518159,15029610476940593397,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:10:53:46
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://AAYUSHRELOCATEPACKERSANDMOVERS.COM"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly