Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://ossinquati.com

Overview

General Information

Sample URL:http://ossinquati.com
Analysis ID:1590235
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 6092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1612 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1996,i,1978041673627843244,3152792575378621742,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ossinquati.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://ossinquati.comAvira URL Cloud: detection malicious, Label: malware
Source: http://ossinquati.com/favicon.icoAvira URL Cloud: Label: malware
Source: http://ossinquati.com/HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ossinquati.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ossinquati.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ossinquati.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: ossinquati.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.24.0Date: Mon, 13 Jan 2025 18:37:23 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveContent-Encoding: gzipData Raw: 37 31 0d 0a 1f 8b 08 00 00 00 00 00 04 03 b3 c9 28 c9 cd b1 e3 b2 c9 48 4d 4c b1 b3 29 c9 2c c9 49 b5 33 31 30 56 70 cb 2f 4a ca 4c 49 49 cd b3 d1 87 08 da e8 83 95 70 d9 24 e5 a7 54 02 35 24 a7 e6 95 a4 16 d9 d9 64 18 a2 ab 07 8a d8 e8 43 a5 81 06 03 d5 40 39 79 e9 99 79 15 fa 86 7a 46 26 7a 06 48 2a f4 a1 26 ea 83 9d 02 00 0b cc 3f cb 91 00 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: 71(HML),I310Vp/JLIIp$T5$dC@9yyzF&zH*&?0
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.24.0Date: Mon, 13 Jan 2025 18:37:23 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-aliveContent-Encoding: gzipData Raw: 62 30 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 90 c1 0a c2 30 10 44 ef 82 ff b0 7e 40 9a 56 7a 5c 72 11 05 0f 7a f1 0b 52 77 6d 02 69 22 31 82 fd 7b 13 6d 41 3c 7b f4 b8 b3 6f 86 61 d0 a4 c1 a9 e5 02 0d 6b 52 98 6c 72 ac da ba 85 63 48 b0 0b 77 4f 28 df 22 ca 17 92 d1 2e d0 58 2c 67 f6 89 a3 42 d3 7c 3b b2 82 72 7a 97 ec 0c 4d 97 ef ad 7f c8 a6 5a b7 55 fd 89 c8 39 54 ce 85 56 42 80 86 ab 26 b2 be 87 14 80 ec 4d 77 8e e1 70 da 6f 41 7b 82 8d 89 61 60 b8 44 cb 9e dc 08 1c 63 88 d9 d1 33 08 51 0a fe 23 7e b9 c5 13 7b 1b 44 21 2b 02 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: b00D~@Vz\rzRwmi"1{mA<{oakRlrcHwO(".X,gB|;rzMZU9TVB&MwpoA{a`Dc3Q#~{D!+0
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal56.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1996,i,1978041673627843244,3152792575378621742,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ossinquati.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1996,i,1978041673627843244,3152792575378621742,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ossinquati.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ossinquati.com/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.184.228
truefalse
    high
    ossinquati.com
    3.23.37.103
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://ossinquati.com/true
        unknown
        http://ossinquati.com/favicon.icotrue
        • Avira URL Cloud: malware
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        3.23.37.103
        ossinquati.comUnited States
        16509AMAZON-02USfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.184.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1590235
        Start date and time:2025-01-13 19:36:23 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 57s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://ossinquati.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@16/4@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.163, 216.58.206.78, 64.233.166.84, 142.250.181.238, 172.217.18.110, 199.232.210.172, 192.229.221.95, 216.58.212.174, 142.250.184.206, 172.217.16.206, 142.250.184.238, 216.58.212.131, 142.250.186.78, 2.23.242.162, 52.149.20.212, 20.109.210.53, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: http://ossinquati.com
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 555
        Category:downloaded
        Size (bytes):176
        Entropy (8bit):6.738206067673969
        Encrypted:false
        SSDEEP:3:FttIVhlb5XDu3SnodW47noYrBks1gD2SnPyptdCQ6jlrugx82sO1cMcg23ll:XtIXodWMXVA2S8CNxruLE1cMRk/
        MD5:7EF182B31A0C40B31FE7F37CC04E1319
        SHA1:223172DFC3094B518D4088E4B822340CB713C895
        SHA-256:159A25C1BFC7DD370445CCE2C68F09AA1E30407F38D84282BD07C3B64E5E32F0
        SHA-512:6C1D5F136BA602534785A6FB5D9D18A481807292D649AB750577C33BB1C62C64496CE8363593DB8985E124344E586C017A1A7F3A9F6ACB60AA78707CEACFFABF
        Malicious:false
        Reputation:low
        URL:http://ossinquati.com/favicon.ico
        Preview:..............0.D...~@.Vz\r...z..Rwm.i"1..{.mA<{...o.a......kR.lr...cH..wO(."......X,g...B.|;..rz...M....Z.U...9T.VB...&......Mw..p.oA{...a`.D....c...3.Q..#~...{.D!+...
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 145
        Category:downloaded
        Size (bytes):113
        Entropy (8bit):6.020146856274416
        Encrypted:false
        SSDEEP:3:FttjG8t0UWMRZ6Ckxnouiv90xaqjfXpa0Eln:XtjJt0U1Z3wotv95qal
        MD5:FD718796F7F0273B1BC66903026B1CBD
        SHA1:22908DA1857416111C1EBCD4C5E3D99460E6E633
        SHA-256:55E153CEF31C35B316CFB0845048294772167EE274157614797ACE35DE27C0C2
        SHA-512:ABE6DA44EDABD5398D8C390F1DE7F868E10662B0FAC612E3CDC836F7331AB3D034E92581F7FB8FE126EDEB4C09A4DA2F5856C190BB80B23B39CF85903E98DF37
        Malicious:false
        Reputation:low
        URL:http://ossinquati.com/
        Preview:............(....HML..).,.I.310Vp./J.LII.....p.$.T.5$.....d.......C.....@9y.y...zF&z.H*..&.....?....
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jan 13, 2025 19:37:17.612565041 CET49675443192.168.2.4173.222.162.32
        Jan 13, 2025 19:37:21.977713108 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:21.977771044 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:21.977852106 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:21.978030920 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:21.978049994 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.636173964 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.636531115 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:22.636565924 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.638197899 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.638268948 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:22.639261007 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:22.639374018 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.691180944 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:22.691211939 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:22.737972975 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:23.303152084 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.303520918 CET4974180192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.308017015 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:37:23.308087111 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.308222055 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.308418036 CET80497413.23.37.103192.168.2.4
        Jan 13, 2025 19:37:23.308501005 CET4974180192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.312999010 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:37:23.816690922 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:37:23.862246037 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.863635063 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:23.868444920 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:37:23.981090069 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:37:24.036653996 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:37:32.553533077 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:32.553664923 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:37:32.553874969 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:33.602071047 CET49737443192.168.2.4142.250.184.228
        Jan 13, 2025 19:37:33.602139950 CET44349737142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:08.315751076 CET4974180192.168.2.43.23.37.103
        Jan 13, 2025 19:38:08.321060896 CET80497413.23.37.103192.168.2.4
        Jan 13, 2025 19:38:08.987497091 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:38:08.992841959 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:38:21.942087889 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:21.942177057 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:21.942286015 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:21.942501068 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:21.942519903 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:22.620142937 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:22.620826960 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:22.620893002 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:22.621603012 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:22.621885061 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:22.622154951 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:22.675618887 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:23.598865986 CET4974180192.168.2.43.23.37.103
        Jan 13, 2025 19:38:23.604231119 CET80497413.23.37.103192.168.2.4
        Jan 13, 2025 19:38:23.604419947 CET4974180192.168.2.43.23.37.103
        Jan 13, 2025 19:38:28.981234074 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:38:28.981515884 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:38:29.598795891 CET4974080192.168.2.43.23.37.103
        Jan 13, 2025 19:38:29.604206085 CET80497403.23.37.103192.168.2.4
        Jan 13, 2025 19:38:32.521486044 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:32.521610022 CET44349803142.250.184.228192.168.2.4
        Jan 13, 2025 19:38:32.521790981 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:33.599298954 CET49803443192.168.2.4142.250.184.228
        Jan 13, 2025 19:38:33.599370003 CET44349803142.250.184.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jan 13, 2025 19:37:17.393080950 CET53610341.1.1.1192.168.2.4
        Jan 13, 2025 19:37:18.512056112 CET53533191.1.1.1192.168.2.4
        Jan 13, 2025 19:37:21.879504919 CET5161453192.168.2.41.1.1.1
        Jan 13, 2025 19:37:21.879506111 CET6119453192.168.2.41.1.1.1
        Jan 13, 2025 19:37:21.974725962 CET53516141.1.1.1192.168.2.4
        Jan 13, 2025 19:37:21.976485968 CET53611941.1.1.1192.168.2.4
        Jan 13, 2025 19:37:23.288283110 CET6275953192.168.2.41.1.1.1
        Jan 13, 2025 19:37:23.288466930 CET6534653192.168.2.41.1.1.1
        Jan 13, 2025 19:37:23.301708937 CET53627591.1.1.1192.168.2.4
        Jan 13, 2025 19:37:23.302531004 CET53653461.1.1.1192.168.2.4
        Jan 13, 2025 19:37:35.524565935 CET53641881.1.1.1192.168.2.4
        Jan 13, 2025 19:37:36.603629112 CET138138192.168.2.4192.168.2.255
        Jan 13, 2025 19:37:54.512492895 CET53508731.1.1.1192.168.2.4
        Jan 13, 2025 19:38:17.138691902 CET53499461.1.1.1192.168.2.4
        Jan 13, 2025 19:38:17.341049910 CET53591281.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 13, 2025 19:37:21.879504919 CET192.168.2.41.1.1.10xaf00Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 13, 2025 19:37:21.879506111 CET192.168.2.41.1.1.10x2021Standard query (0)www.google.com65IN (0x0001)false
        Jan 13, 2025 19:37:23.288283110 CET192.168.2.41.1.1.10x6b08Standard query (0)ossinquati.comA (IP address)IN (0x0001)false
        Jan 13, 2025 19:37:23.288466930 CET192.168.2.41.1.1.10x6454Standard query (0)ossinquati.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 13, 2025 19:37:21.974725962 CET1.1.1.1192.168.2.40xaf00No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
        Jan 13, 2025 19:37:21.976485968 CET1.1.1.1192.168.2.40x2021No error (0)www.google.com65IN (0x0001)false
        Jan 13, 2025 19:37:23.301708937 CET1.1.1.1192.168.2.40x6b08No error (0)ossinquati.com3.23.37.103A (IP address)IN (0x0001)false
        • ossinquati.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.4497403.23.37.103801612C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jan 13, 2025 19:37:23.308222055 CET429OUTGET / HTTP/1.1
        Host: ossinquati.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Jan 13, 2025 19:37:23.816690922 CET325INHTTP/1.1 403 Forbidden
        Server: nginx/1.24.0
        Date: Mon, 13 Jan 2025 18:37:23 GMT
        Content-Type: text/html; charset=UTF-8
        Transfer-Encoding: chunked
        Connection: keep-alive
        Content-Encoding: gzip
        Data Raw: 37 31 0d 0a 1f 8b 08 00 00 00 00 00 04 03 b3 c9 28 c9 cd b1 e3 b2 c9 48 4d 4c b1 b3 29 c9 2c c9 49 b5 33 31 30 56 70 cb 2f 4a ca 4c 49 49 cd b3 d1 87 08 da e8 83 95 70 d9 24 e5 a7 54 02 35 24 a7 e6 95 a4 16 d9 d9 64 18 a2 ab 07 8a d8 e8 43 a5 81 06 03 d5 40 39 79 e9 99 79 15 fa 86 7a 46 26 7a 06 48 2a f4 a1 26 ea 83 9d 02 00 0b cc 3f cb 91 00 00 00 0d 0a 30 0d 0a 0d 0a
        Data Ascii: 71(HML),I310Vp/JLIIp$T5$dC@9yyzF&zH*&?0
        Jan 13, 2025 19:37:23.863635063 CET372OUTGET /favicon.ico HTTP/1.1
        Host: ossinquati.com
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://ossinquati.com/
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Jan 13, 2025 19:37:23.981090069 CET373INHTTP/1.1 404 Not Found
        Server: nginx/1.24.0
        Date: Mon, 13 Jan 2025 18:37:23 GMT
        Content-Type: text/html
        Transfer-Encoding: chunked
        Connection: keep-alive
        Content-Encoding: gzip
        Data Raw: 62 30 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 90 c1 0a c2 30 10 44 ef 82 ff b0 7e 40 9a 56 7a 5c 72 11 05 0f 7a f1 0b 52 77 6d 02 69 22 31 82 fd 7b 13 6d 41 3c 7b f4 b8 b3 6f 86 61 d0 a4 c1 a9 e5 02 0d 6b 52 98 6c 72 ac da ba 85 63 48 b0 0b 77 4f 28 df 22 ca 17 92 d1 2e d0 58 2c 67 f6 89 a3 42 d3 7c 3b b2 82 72 7a 97 ec 0c 4d 97 ef ad 7f c8 a6 5a b7 55 fd 89 c8 39 54 ce 85 56 42 80 86 ab 26 b2 be 87 14 80 ec 4d 77 8e e1 70 da 6f 41 7b 82 8d 89 61 60 b8 44 cb 9e dc 08 1c 63 88 d9 d1 33 08 51 0a fe 23 7e b9 c5 13 7b 1b 44 21 2b 02 00 00 0d 0a 30 0d 0a 0d 0a
        Data Ascii: b00D~@Vz\rzRwmi"1{mA<{oakRlrcHwO(".X,gB|;rzMZU9TVB&MwpoA{a`Dc3Q#~{D!+0
        Jan 13, 2025 19:38:08.987497091 CET6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.4497413.23.37.103801612C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jan 13, 2025 19:38:08.315751076 CET6OUTData Raw: 00
        Data Ascii:


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:13:37:12
        Start date:13/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:13:37:15
        Start date:13/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1996,i,1978041673627843244,3152792575378621742,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:13:37:22
        Start date:13/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ossinquati.com"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly