Click to jump to signature section
Source: http://readermodeext.info | Avira URL Cloud: detection malicious, Label: malware |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.24:60845 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.24:60846 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60851 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60853 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60856 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60857 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60859 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60860 version: TLS 1.2 |
Source: chrome.exe | Memory has grown: Private usage: 16MB later: 35MB |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.221.95 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.137.3.145 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.221.95 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.137.3.145 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.209.209.135 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.209.209.135 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.209.209.135 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.209.209.135 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.198.118.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: global traffic | HTTP traffic detected: GET /r/r1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Cache-Control: max-age = 3600Connection: Keep-AliveAccept: */*If-Modified-Since: Mon, 12 Feb 2024 22:07:27 GMTIf-None-Match: "65ca969f-2cd"User-Agent: Microsoft-CryptoAPI/10.0Host: x1.c.lencr.org |
Source: global traffic | DNS traffic detected: DNS query: readermodeext.info |
Source: global traffic | DNS traffic detected: DNS query: google.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: unknown | Network traffic detected: HTTP traffic on port 60846 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60852 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60856 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60851 |
Source: unknown | Network traffic detected: HTTP traffic on port 60861 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60834 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60832 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60837 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60859 |
Source: unknown | Network traffic detected: HTTP traffic on port 60844 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60857 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60856 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60834 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60855 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60832 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60853 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60852 |
Source: unknown | Network traffic detected: HTTP traffic on port 60851 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49673 |
Source: unknown | Network traffic detected: HTTP traffic on port 60855 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60853 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60857 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60859 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60861 |
Source: unknown | Network traffic detected: HTTP traffic on port 60860 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60860 |
Source: unknown | Network traffic detected: HTTP traffic on port 60837 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60846 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60845 |
Source: unknown | Network traffic detected: HTTP traffic on port 60845 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60844 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.24:60845 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.24:60846 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60851 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60853 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60856 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60857 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60859 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.24:60860 version: TLS 1.2 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir1380_1126768196 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir1380_1126768196 |
Source: classification engine | Classification label: mal48.win@22/0@25/93 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=2156,i,5867893757064742665,16747209749079873557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2168 /prefetch:11 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://readermodeext.info" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=2156,i,5867893757064742665,16747209749079873557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2168 /prefetch:11 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |