Click to jump to signature section
Source: Yara match | File source: dropped/chromecache_124, type: DROPPED |
Source: https://bur.tabilicit.ru/HgSlh/#Xbenson.lin@vhacorp.com | HTTP Parser: No favicon |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61528 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.24:61529 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.24:61531 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61532 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61533 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61535 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61539 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61542 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61548 version: TLS 1.2 |
Source: chrome.exe | Memory has grown: Private usage: 22MB later: 35MB |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.198.118.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.159.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.149.20.212 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /r/r1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Cache-Control: max-age = 3600Connection: Keep-AliveAccept: */*If-Modified-Since: Mon, 12 Feb 2024 22:07:27 GMTIf-None-Match: "65ca969f-2cd"User-Agent: Microsoft-CryptoAPI/10.0Host: x1.c.lencr.org |
Source: global traffic | DNS traffic detected: DNS query: unikuesolutions.com |
Source: global traffic | DNS traffic detected: DNS query: bur.tabilicit.ru |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: unknown | Network traffic detected: HTTP traffic on port 61522 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61541 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61507 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61549 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61545 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61545 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61546 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61547 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61548 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61549 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61506 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61507 |
Source: unknown | Network traffic detected: HTTP traffic on port 61539 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61531 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61541 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61542 |
Source: unknown | Network traffic detected: HTTP traffic on port 61535 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61544 |
Source: unknown | Network traffic detected: HTTP traffic on port 61546 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61521 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61525 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61529 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61542 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61519 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 61532 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61510 |
Source: unknown | Network traffic detected: HTTP traffic on port 61519 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61520 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61524 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61547 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61528 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61523 |
Source: unknown | Network traffic detected: HTTP traffic on port 61510 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61524 |
Source: unknown | Network traffic detected: HTTP traffic on port 61533 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61525 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61528 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61529 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61520 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61521 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61522 |
Source: unknown | Network traffic detected: HTTP traffic on port 61523 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49673 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61506 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61548 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61544 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61535 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61539 |
Source: unknown | Network traffic detected: HTTP traffic on port 61530 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61530 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61531 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61532 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61533 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61528 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.24:61529 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.24:61531 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61532 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61533 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61535 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61539 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61542 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.24:61548 version: TLS 1.2 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir6216_718514871 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir6216_718514871 |
Source: classification engine | Classification label: mal48.phis.win@19/2@8/104 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1952,i,13276525319229935709,13562326071932144126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2212 /prefetch:11 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://unikuesolutions.com/ck/bd/%7BRANDOM_NUMBER05%7D/YmVuc29uLmxpbkB2aGFjb3JwLmNvbQ==" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1952,i,13276525319229935709,13562326071932144126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2212 /prefetch:11 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |