Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://sos-de-muc-1.exo.io

Overview

General Information

Sample URL:https://sos-de-muc-1.exo.io
Analysis ID:1587379
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 1848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2028,i,13123938471122622945,3958590266739233860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sos-de-muc-1.exo.io" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://sos-de-muc-1.exo.ioAvira URL Cloud: detection malicious, Label: phishing
Source: global trafficTCP traffic: 192.168.2.4:62317 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sos-de-muc-1.exo.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sos-de-muc-1.exo.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sos-de-muc-1.exo.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: sos-de-muc-1.exo.io
Source: global trafficDNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbiddenx-amz-request-id: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6x-amzn-request-id: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6x-amz-id-2: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6content-length: 110content-type: application/xmlserver: Aleph/0.6.0date: Fri, 10 Jan 2025 08:55:55 GMThost: sos-de-muc-1.exo.ioconnection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundx-amz-request-id: 184859a9-ba4f-4051-b94e-0626e89998e9x-amzn-request-id: 184859a9-ba4f-4051-b94e-0626e89998e9x-amz-id-2: 184859a9-ba4f-4051-b94e-0626e89998e9content-length: 169content-type: application/xmlserver: Aleph/0.6.0date: Fri, 10 Jan 2025 08:55:55 GMThost: sos-de-muc-1.exo.ioconnection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62402 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62402
Source: classification engineClassification label: mal48.win@16/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2028,i,13123938471122622945,3958590266739233860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sos-de-muc-1.exo.io"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2028,i,13123938471122622945,3958590266739233860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://sos-de-muc-1.exo.io100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
lb-de-muc-1.exo.io
194.182.183.20
truefalse
    high
    www.google.com
    216.58.206.36
    truefalse
      high
      241.42.69.40.in-addr.arpa
      unknown
      unknownfalse
        high
        sos-de-muc-1.exo.io
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://sos-de-muc-1.exo.io/false
            high
            https://sos-de-muc-1.exo.io/favicon.icofalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.185.164
              unknownUnited States
              15169GOOGLEUSfalse
              194.182.183.20
              lb-de-muc-1.exo.ioSwitzerland
              61098EXOSCALECHfalse
              216.58.206.36
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1587379
              Start date and time:2025-01-10 09:54:50 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 57s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://sos-de-muc-1.exo.io
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal48.win@16/4@6/5
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.186.131, 74.125.133.84, 172.217.18.110, 142.250.181.238, 172.217.18.14, 142.250.185.174, 199.232.214.172, 192.229.221.95, 216.58.206.78, 142.250.185.163, 142.250.185.142, 2.23.242.162, 52.149.20.212, 40.69.42.241, 4.175.87.197, 13.107.246.45
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
              • Not all processes where analyzed, report is missing behavior information
              • VT rate limit hit for: https://sos-de-muc-1.exo.io
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):169
              Entropy (8bit):4.933248824592941
              Encrypted:false
              SSDEEP:3:vFWWMNHU8LdgCfIqZj++anCA/cAbWWUAVMABJRvWQBWRaWWU9nQkXTMJLMunQko2:TMVBd/IqZj7rAIWt5dTgRdW6sLMoiKvn
              MD5:3D6AA58C4F15BF83C29ACA18AAD95AB2
              SHA1:74540612914CDA9957CD2ECF9C6DB82E01F4CA70
              SHA-256:2686FB6EDE2A99746AA46E78B6704F20389EF6CE285819365F3D150A3252C140
              SHA-512:DD67B30E6B8A361F21F6D6476CF8E721BC390A16C4EA3156430E809238C68C40E5D8FCC267612807F914D7873155AE5C591E333D54C2AC9304EB48AAAE955AC3
              Malicious:false
              Reputation:low
              URL:https://sos-de-muc-1.exo.io/favicon.ico
              Preview:<?xml version="1.0" encoding="UTF-8"?><Error><Code>NoSuchBucket</Code><Message>The specified bucket does not exist.</Message><BucketName>favicon.ico</BucketName></Error>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):110
              Entropy (8bit):4.6232678388053445
              Encrypted:false
              SSDEEP:3:vFWWMNHU8LdgCfIqZj+PBMkmKqWWU66bukoL9KgqLn:TMVBd/IqZjZvKtWRV8g6n
              MD5:CCE2C8B7CEB5C2AD4147C8C2EDB1DD57
              SHA1:A45979D22E5F7A3B152C4F6EFAA9DFDFCFE7E5A7
              SHA-256:D9228B355C91A1939BE25F83F7D6ACC1F39DB8DFA5C37643FB710934F4E5CD40
              SHA-512:C902C049FEF3487CDC387E89E60068A9EDA89182249E1CFF77FEC50983DD9E4EB7529EC2BA280B89303149F2F3862186541530F79500C80726BE1DCC37C9895B
              Malicious:false
              Reputation:low
              URL:https://sos-de-muc-1.exo.io/
              Preview:<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Jan 10, 2025 09:55:47.176222086 CET49675443192.168.2.4173.222.162.32
              Jan 10, 2025 09:55:53.430762053 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:53.430804014 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:53.431109905 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:53.431299925 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:53.431318998 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.072165012 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.072453976 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:54.072472095 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.073627949 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.073692083 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:54.074934006 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:54.075001955 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.125796080 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:54.125819921 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:55:54.173115015 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:55:54.931679010 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.931777000 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:54.931972980 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.931999922 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:54.932017088 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.932193995 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.932318926 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.932372093 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:54.932543039 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:54.932554007 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.573998928 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.574278116 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.574290991 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.574620008 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.575126886 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.575170040 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.575328112 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.575386047 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.576683044 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.576761007 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.580965996 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.581201077 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.582472086 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.582576990 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.582711935 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.582719088 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.630873919 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.631042957 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.631083965 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.678538084 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.847239017 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.847351074 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:55.847407103 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.904238939 CET49742443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:55.904256105 CET44349742194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:56.009624004 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:56.051337957 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:56.198893070 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:56.199014902 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:55:56.199057102 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:56.199789047 CET49741443192.168.2.4194.182.183.20
              Jan 10, 2025 09:55:56.199815035 CET44349741194.182.183.20192.168.2.4
              Jan 10, 2025 09:56:03.327001095 CET4972380192.168.2.42.22.50.131
              Jan 10, 2025 09:56:03.332017899 CET80497232.22.50.131192.168.2.4
              Jan 10, 2025 09:56:03.332163095 CET4972380192.168.2.42.22.50.131
              Jan 10, 2025 09:56:03.983935118 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:56:03.984011889 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:56:03.984070063 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:56:05.097048044 CET49738443192.168.2.4216.58.206.36
              Jan 10, 2025 09:56:05.097076893 CET44349738216.58.206.36192.168.2.4
              Jan 10, 2025 09:56:15.601779938 CET6231753192.168.2.4162.159.36.2
              Jan 10, 2025 09:56:15.606524944 CET5362317162.159.36.2192.168.2.4
              Jan 10, 2025 09:56:15.606631994 CET6231753192.168.2.4162.159.36.2
              Jan 10, 2025 09:56:15.611361980 CET5362317162.159.36.2192.168.2.4
              Jan 10, 2025 09:56:16.060564041 CET6231753192.168.2.4162.159.36.2
              Jan 10, 2025 09:56:16.065596104 CET5362317162.159.36.2192.168.2.4
              Jan 10, 2025 09:56:16.065634966 CET6231753192.168.2.4162.159.36.2
              Jan 10, 2025 09:56:51.643239975 CET4972480192.168.2.4199.232.210.172
              Jan 10, 2025 09:56:51.657613039 CET8049724199.232.210.172192.168.2.4
              Jan 10, 2025 09:56:51.658021927 CET4972480192.168.2.4199.232.210.172
              Jan 10, 2025 09:56:53.009742022 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:56:53.009789944 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.010006905 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:56:53.010075092 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:56:53.010086060 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.662173033 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.662687063 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:56:53.662705898 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.663841963 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.664212942 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:56:53.664391041 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:56:53.722091913 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:57:03.583115101 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:57:03.583172083 CET44362402142.250.185.164192.168.2.4
              Jan 10, 2025 09:57:03.583354950 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:57:05.096470118 CET62402443192.168.2.4142.250.185.164
              Jan 10, 2025 09:57:05.096503019 CET44362402142.250.185.164192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Jan 10, 2025 09:55:48.292388916 CET53540581.1.1.1192.168.2.4
              Jan 10, 2025 09:55:48.298739910 CET53523041.1.1.1192.168.2.4
              Jan 10, 2025 09:55:49.342869997 CET53568121.1.1.1192.168.2.4
              Jan 10, 2025 09:55:52.939475060 CET5216453192.168.2.41.1.1.1
              Jan 10, 2025 09:55:52.939599991 CET4933453192.168.2.41.1.1.1
              Jan 10, 2025 09:55:53.429382086 CET53521641.1.1.1192.168.2.4
              Jan 10, 2025 09:55:53.429774046 CET53493341.1.1.1192.168.2.4
              Jan 10, 2025 09:55:54.906486034 CET5418053192.168.2.41.1.1.1
              Jan 10, 2025 09:55:54.906639099 CET4931353192.168.2.41.1.1.1
              Jan 10, 2025 09:55:54.925084114 CET53541801.1.1.1192.168.2.4
              Jan 10, 2025 09:55:54.931102037 CET53493131.1.1.1192.168.2.4
              Jan 10, 2025 09:56:03.229341030 CET138138192.168.2.4192.168.2.255
              Jan 10, 2025 09:56:06.352861881 CET53573721.1.1.1192.168.2.4
              Jan 10, 2025 09:56:15.601003885 CET5357346162.159.36.2192.168.2.4
              Jan 10, 2025 09:56:16.077666998 CET6384253192.168.2.41.1.1.1
              Jan 10, 2025 09:56:16.084901094 CET53638421.1.1.1192.168.2.4
              Jan 10, 2025 09:56:53.002043009 CET5370353192.168.2.41.1.1.1
              Jan 10, 2025 09:56:53.008811951 CET53537031.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jan 10, 2025 09:55:52.939475060 CET192.168.2.41.1.1.10x50d5Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Jan 10, 2025 09:55:52.939599991 CET192.168.2.41.1.1.10xfd17Standard query (0)www.google.com65IN (0x0001)false
              Jan 10, 2025 09:55:54.906486034 CET192.168.2.41.1.1.10x5f09Standard query (0)sos-de-muc-1.exo.ioA (IP address)IN (0x0001)false
              Jan 10, 2025 09:55:54.906639099 CET192.168.2.41.1.1.10x67ccStandard query (0)sos-de-muc-1.exo.io65IN (0x0001)false
              Jan 10, 2025 09:56:16.077666998 CET192.168.2.41.1.1.10xd912Standard query (0)241.42.69.40.in-addr.arpaPTR (Pointer record)IN (0x0001)false
              Jan 10, 2025 09:56:53.002043009 CET192.168.2.41.1.1.10x1aefStandard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jan 10, 2025 09:55:53.429382086 CET1.1.1.1192.168.2.40x50d5No error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
              Jan 10, 2025 09:55:53.429774046 CET1.1.1.1192.168.2.40xfd17No error (0)www.google.com65IN (0x0001)false
              Jan 10, 2025 09:55:54.925084114 CET1.1.1.1192.168.2.40x5f09No error (0)sos-de-muc-1.exo.iolb-de-muc-1.exo.ioCNAME (Canonical name)IN (0x0001)false
              Jan 10, 2025 09:55:54.925084114 CET1.1.1.1192.168.2.40x5f09No error (0)lb-de-muc-1.exo.io194.182.183.20A (IP address)IN (0x0001)false
              Jan 10, 2025 09:55:54.931102037 CET1.1.1.1192.168.2.40x67ccNo error (0)sos-de-muc-1.exo.iolb-de-muc-1.exo.ioCNAME (Canonical name)IN (0x0001)false
              Jan 10, 2025 09:56:16.084901094 CET1.1.1.1192.168.2.40xd912Name error (3)241.42.69.40.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
              Jan 10, 2025 09:56:53.008811951 CET1.1.1.1192.168.2.40x1aefNo error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
              • sos-de-muc-1.exo.io
              • https:
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449742194.182.183.204431440C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-01-10 08:55:55 UTC662OUTGET / HTTP/1.1
              Host: sos-de-muc-1.exo.io
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2025-01-10 08:55:55 UTC345INHTTP/1.1 403 Forbidden
              x-amz-request-id: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6
              x-amzn-request-id: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6
              x-amz-id-2: 335fbe19-a8eb-4884-95ff-e63d1d76dcb6
              content-length: 110
              content-type: application/xml
              server: Aleph/0.6.0
              date: Fri, 10 Jan 2025 08:55:55 GMT
              host: sos-de-muc-1.exo.io
              connection: close
              2025-01-10 08:55:55 UTC110INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449741194.182.183.204431440C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-01-10 08:55:56 UTC594OUTGET /favicon.ico HTTP/1.1
              Host: sos-de-muc-1.exo.io
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://sos-de-muc-1.exo.io/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2025-01-10 08:55:56 UTC345INHTTP/1.1 404 Not Found
              x-amz-request-id: 184859a9-ba4f-4051-b94e-0626e89998e9
              x-amzn-request-id: 184859a9-ba4f-4051-b94e-0626e89998e9
              x-amz-id-2: 184859a9-ba4f-4051-b94e-0626e89998e9
              content-length: 169
              content-type: application/xml
              server: Aleph/0.6.0
              date: Fri, 10 Jan 2025 08:55:55 GMT
              host: sos-de-muc-1.exo.io
              connection: close
              2025-01-10 08:55:56 UTC169INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 4e 6f 53 75 63 68 42 75 63 6b 65 74 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 62 75 63 6b 65 74 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 42 75 63 6b 65 74 4e 61 6d 65 3e 66 61 76 69 63 6f 6e 2e 69 63 6f 3c 2f 42 75 63 6b 65 74 4e 61 6d 65 3e 3c 2f 45 72 72 6f 72 3e
              Data Ascii: <?xml version="1.0" encoding="UTF-8"?><Error><Code>NoSuchBucket</Code><Message>The specified bucket does not exist.</Message><BucketName>favicon.ico</BucketName></Error>


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:03:55:43
              Start date:10/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:03:55:47
              Start date:10/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2028,i,13123938471122622945,3958590266739233860,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:03:55:54
              Start date:10/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sos-de-muc-1.exo.io"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly