Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://sign-as.allarknow.online/

Overview

General Information

Sample URL:https://sign-as.allarknow.online/
Analysis ID:1587424
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 1136 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2480 --field-trial-handle=2452,i,9742894001681465520,5373409887847056221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sign-as.allarknow.online/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://sign-as.allarknow.online/Avira URL Cloud: detection malicious, Label: malware
Source: https://sign-as.allarknow.online/HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sign-as.allarknow.onlineConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sign-as.allarknow.onlineConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sign-as.allarknow.online/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: sign-as.allarknow.online
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: AngieDate: Fri, 10 Jan 2025 10:22:11 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeVary: AcceptCache-Control: no-cache, privateX-Content-Type-Options: nosniff
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: AngieDate: Fri, 10 Jan 2025 10:22:11 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeVary: AcceptCache-Control: no-cache, privateX-Content-Type-Options: nosniff
Source: chromecache_41.2.drString found in binary or memory: https://sign-as.allarknow.online/
Source: chromecache_41.2.drString found in binary or memory: https://sign-as.allarknow.online/favicon.ico
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: mal48.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2480 --field-trial-handle=2452,i,9742894001681465520,5373409887847056221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sign-as.allarknow.online/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2480 --field-trial-handle=2452,i,9742894001681465520,5373409887847056221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://sign-as.allarknow.online/100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
plground.live
50.7.127.10
truefalse
    high
    www.google.com
    142.250.186.164
    truefalse
      high
      sign-as.allarknow.online
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://sign-as.allarknow.online/favicon.icofalse
          high
          https://sign-as.allarknow.online/false
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            50.7.127.10
            plground.liveUnited States
            174COGENT-174USfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.164
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1587424
            Start date and time:2025-01-10 11:21:05 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 55s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://sign-as.allarknow.online/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@16/4@4/4
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.186.46, 74.125.133.84, 142.250.186.78, 142.250.184.206, 199.232.214.172, 192.229.221.95, 142.250.185.206, 172.217.18.14, 216.58.206.78, 142.250.186.174, 142.250.181.227, 172.217.16.206, 2.23.242.162, 20.12.23.50, 4.175.87.197, 13.107.246.45
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://sign-as.allarknow.online/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, Unicode text, UTF-8 text
            Category:downloaded
            Size (bytes):1132
            Entropy (8bit):5.164457365345249
            Encrypted:false
            SSDEEP:24:hYiCN+DQ0uG9KNiGNjcBd+3lFK4gMVZ7k7Iu2vsR5KVcgaeJHtY:0+yTMGRUjXMVCcuSSvmHO
            MD5:55997C8EA4FA153A58ADAFB81835BB98
            SHA1:9426A7142E4CFA488BD13C8A6DA627449B5DD035
            SHA-256:EEF945779B10CBA55816CA86AD15B6AF965403B4BB997C6DE22A5A7712BED044
            SHA-512:49E996FE8CF916703561EE790D0D203D79421053B42699C9002DA095D31059A04EF84EAEDE6E2A96FF4FF55A0FC19101599A963409A49B5753DA4605131EB707
            Malicious:false
            Reputation:low
            URL:https://sign-as.allarknow.online/favicon.ico
            Preview:<!DOCTYPE html>.<html lang="ru">.<head>..<meta charset="UTF-8">..<meta name="viewport" content="width=device-width, initial-scale=1.0">..<meta name="robots" content="noindex,nofollow,noarchive">..<title>......!</title>..<style>...* {....margin: 0;....padding: 0;....outline: none !important;....-webkit-box-sizing: border-box !important;......box-sizing: border-box !important;....font-family: Verdana;...}...html, body {....height: 100%;....font: 12px 'Verdana', sans-serif;...}....body {....background: #000;....color: #fff;....position: relative;...}....error {....display: -webkit-box;....display: -ms-flexbox;....display: flex;....-webkit-box-align: center;.....-ms-flex-align: center;......align-items: center;....-webkit-box-pack: center;.....-ms-flex-pack: center;......justify-content: center;....height: 100%;....width: 100%;....text-align: center;....font-size: 18px;....max-width: 600px;....margin: auto;....padding: 15px;...}..</style>.</head>.<body>..<div class="error">.....No ro
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, Unicode text, UTF-8 text
            Category:downloaded
            Size (bytes):1178
            Entropy (8bit):5.405312496508255
            Encrypted:false
            SSDEEP:24:hYiCN+DQ0uG9KNiGNjcBd+3lFK4gMVZ7k7Iu2vsR5KVRu1TfCjkJkY:0+yTMGRUjXMVCcuSmT6jkJz
            MD5:669A3EEAEAFF2C0BF26FDB472C75E9D5
            SHA1:9241412049810F6A969AD1E4ADB7F7F4CA68C240
            SHA-256:8CEAD2B3F0E7A325ACB57E20B80DA36B07B6AD6625768E4C0160BD54AEE1F6F1
            SHA-512:38FACF135EC274FD927C48EF52FC63EA4E97FE0274D8521D3DDB23C277F405FBF0E0073A30C3F44A1840022313A884E9B5C3B2F9DA9025A1E80CAE7C33C2D57A
            Malicious:false
            Reputation:low
            URL:https://sign-as.allarknow.online/
            Preview:<!DOCTYPE html>.<html lang="ru">.<head>..<meta charset="UTF-8">..<meta name="viewport" content="width=device-width, initial-scale=1.0">..<meta name="robots" content="noindex,nofollow,noarchive">..<title>......!</title>..<style>...* {....margin: 0;....padding: 0;....outline: none !important;....-webkit-box-sizing: border-box !important;......box-sizing: border-box !important;....font-family: Verdana;...}...html, body {....height: 100%;....font: 12px 'Verdana', sans-serif;...}....body {....background: #000;....color: #fff;....position: relative;...}....error {....display: -webkit-box;....display: -ms-flexbox;....display: flex;....-webkit-box-align: center;.....-ms-flex-align: center;......align-items: center;....-webkit-box-pack: center;.....-ms-flex-pack: center;......justify-content: center;....height: 100%;....width: 100%;....text-align: center;....font-size: 18px;....max-width: 600px;....margin: auto;....padding: 15px;...}..</style>.</head>.<body>..<div class="error">...... .
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Jan 10, 2025 11:22:03.043966055 CET49675443192.168.2.4173.222.162.32
            Jan 10, 2025 11:22:08.427282095 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:08.427397966 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:08.427478075 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:08.427804947 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:08.427886009 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.081068993 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.081325054 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:09.081387043 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.083022118 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.083110094 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:09.083986998 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:09.084083080 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.137418032 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:09.137478113 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:09.186271906 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:10.700746059 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.700833082 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:10.700881004 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.700908899 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.700965881 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:10.701030970 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.701141119 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.701170921 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:10.701266050 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:10.701301098 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.328866005 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.329279900 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.329313040 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.330950022 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.331062078 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.335043907 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.335043907 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.335061073 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.335127115 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.340068102 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.340281963 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.340348005 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.342005968 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.342108965 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.342428923 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.342526913 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.390361071 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.390374899 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.390381098 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.390434980 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.438287973 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.438374996 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.681370020 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.681471109 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.684165955 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.684314013 CET49742443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.684360027 CET4434974250.7.127.10192.168.2.4
            Jan 10, 2025 11:22:11.733652115 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:11.775326014 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:12.004354954 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:12.004554033 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:12.009970903 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:12.009972095 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:12.313777924 CET49741443192.168.2.450.7.127.10
            Jan 10, 2025 11:22:12.313864946 CET4434974150.7.127.10192.168.2.4
            Jan 10, 2025 11:22:18.986197948 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:18.986298084 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:22:18.986368895 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:20.955176115 CET49738443192.168.2.4142.250.186.164
            Jan 10, 2025 11:22:20.955245018 CET44349738142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:08.481616020 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:08.481709957 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:08.481825113 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:08.482049942 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:08.482073069 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:09.115478992 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:09.115977049 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:09.116043091 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:09.116545916 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:09.116969109 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:09.117218018 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:09.167656898 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:19.048305988 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:19.048460960 CET44349826142.250.186.164192.168.2.4
            Jan 10, 2025 11:23:19.048527956 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:20.951322079 CET49826443192.168.2.4142.250.186.164
            Jan 10, 2025 11:23:20.951359034 CET44349826142.250.186.164192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Jan 10, 2025 11:22:04.575849056 CET53506961.1.1.1192.168.2.4
            Jan 10, 2025 11:22:04.622549057 CET53598801.1.1.1192.168.2.4
            Jan 10, 2025 11:22:05.589551926 CET53594141.1.1.1192.168.2.4
            Jan 10, 2025 11:22:08.419470072 CET6519753192.168.2.41.1.1.1
            Jan 10, 2025 11:22:08.419667006 CET5143053192.168.2.41.1.1.1
            Jan 10, 2025 11:22:08.426381111 CET53514301.1.1.1192.168.2.4
            Jan 10, 2025 11:22:08.426399946 CET53651971.1.1.1192.168.2.4
            Jan 10, 2025 11:22:10.689455986 CET5046753192.168.2.41.1.1.1
            Jan 10, 2025 11:22:10.689699888 CET5241253192.168.2.41.1.1.1
            Jan 10, 2025 11:22:10.697021961 CET53504671.1.1.1192.168.2.4
            Jan 10, 2025 11:22:10.697205067 CET53524121.1.1.1192.168.2.4
            Jan 10, 2025 11:22:18.521188021 CET138138192.168.2.4192.168.2.255
            Jan 10, 2025 11:22:22.613712072 CET53535241.1.1.1192.168.2.4
            Jan 10, 2025 11:22:41.575021982 CET53596031.1.1.1192.168.2.4
            Jan 10, 2025 11:23:03.910352945 CET53625411.1.1.1192.168.2.4
            Jan 10, 2025 11:23:04.349833012 CET53550451.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jan 10, 2025 11:22:08.419470072 CET192.168.2.41.1.1.10x438cStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:08.419667006 CET192.168.2.41.1.1.10xbfcfStandard query (0)www.google.com65IN (0x0001)false
            Jan 10, 2025 11:22:10.689455986 CET192.168.2.41.1.1.10x5536Standard query (0)sign-as.allarknow.onlineA (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.689699888 CET192.168.2.41.1.1.10xb40cStandard query (0)sign-as.allarknow.online65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jan 10, 2025 11:22:08.426381111 CET1.1.1.1192.168.2.40xbfcfNo error (0)www.google.com65IN (0x0001)false
            Jan 10, 2025 11:22:08.426399946 CET1.1.1.1192.168.2.40x438cNo error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.697021961 CET1.1.1.1192.168.2.40x5536No error (0)sign-as.allarknow.onlineplground.liveCNAME (Canonical name)IN (0x0001)false
            Jan 10, 2025 11:22:10.697021961 CET1.1.1.1192.168.2.40x5536No error (0)plground.live50.7.127.10A (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.697021961 CET1.1.1.1192.168.2.40x5536No error (0)plground.live185.234.65.5A (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.697021961 CET1.1.1.1192.168.2.40x5536No error (0)plground.live50.7.239.229A (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.697021961 CET1.1.1.1192.168.2.40x5536No error (0)plground.live45.120.177.212A (IP address)IN (0x0001)false
            Jan 10, 2025 11:22:10.697205067 CET1.1.1.1192.168.2.40xb40cNo error (0)sign-as.allarknow.onlineplground.liveCNAME (Canonical name)IN (0x0001)false
            • sign-as.allarknow.online
            • https:
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44974250.7.127.104431104C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-10 10:22:11 UTC667OUTGET / HTTP/1.1
            Host: sign-as.allarknow.online
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-10 10:22:11 UTC246INHTTP/1.1 404 Not Found
            Server: Angie
            Date: Fri, 10 Jan 2025 10:22:11 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept
            Cache-Control: no-cache, private
            X-Content-Type-Options: nosniff
            2025-01-10 10:22:11 UTC1190INData Raw: 34 39 61 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 72 75 22 3e 0a 3c 68 65 61 64 3e 0a 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 2c 6e 6f 61 72 63 68 69 76 65 22 3e 0a 09 3c 74 69 74 6c 65 3e d0 9e d1 88 d0 b8 d0 b1 d0 ba d0 b0 21 3c 2f 74 69 74 6c 65 3e 0a 09 3c 73 74 79 6c 65 3e 0a 09 09 2a 20 7b 0a 09 09 09 6d 61 72 67 69 6e 3a
            Data Ascii: 49a<!DOCTYPE html><html lang="ru"><head><meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="robots" content="noindex,nofollow,noarchive"><title>!</title><style>* {margin:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44974150.7.127.104431104C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-10 10:22:11 UTC604OUTGET /favicon.ico HTTP/1.1
            Host: sign-as.allarknow.online
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://sign-as.allarknow.online/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-10 10:22:12 UTC246INHTTP/1.1 404 Not Found
            Server: Angie
            Date: Fri, 10 Jan 2025 10:22:11 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept
            Cache-Control: no-cache, private
            X-Content-Type-Options: nosniff
            2025-01-10 10:22:12 UTC1144INData Raw: 34 36 63 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 72 75 22 3e 0a 3c 68 65 61 64 3e 0a 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 2c 6e 6f 61 72 63 68 69 76 65 22 3e 0a 09 3c 74 69 74 6c 65 3e d0 9e d1 88 d0 b8 d0 b1 d0 ba d0 b0 21 3c 2f 74 69 74 6c 65 3e 0a 09 3c 73 74 79 6c 65 3e 0a 09 09 2a 20 7b 0a 09 09 09 6d 61 72 67 69 6e 3a
            Data Ascii: 46c<!DOCTYPE html><html lang="ru"><head><meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="robots" content="noindex,nofollow,noarchive"><title>!</title><style>* {margin:


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:05:21:58
            Start date:10/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:05:22:02
            Start date:10/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2480 --field-trial-handle=2452,i,9742894001681465520,5373409887847056221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:05:22:09
            Start date:10/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sign-as.allarknow.online/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly