Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Subscription_Renewal_Receipt_2025.htm

Overview

General Information

Sample name:Subscription_Renewal_Receipt_2025.htm
Analysis ID:1592477
MD5:285e5dd90510772b1bf7c5fe08eeb8c6
SHA1:3d7b63c71a01be23a07807242bd13b60f8c259e5
SHA256:d6c92415e04c02bd1d0f8b5b838d8993cdf8bccf9bc31796173125a985891044
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Suricata IDS alerts for network traffic
Detected javascript redirector / loader
HTML document with suspicious name
Suspicious Javascript code found in HTML file
Detected non-DNS traffic on DNS port
IP address seen in connection with other malware
Internet Provider seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 2476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\Subscription_Renewal_Receipt_2025.htm" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=2000,i,2848020951146539357,7329775341439803869,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-16T07:42:52.599874+010020573331Successful Credential Theft Detected192.168.2.44973968.178.204.95443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://hartmantoothpaste.com/js/epEQA/albert.schoberAvira URL Cloud: Label: phishing
Source: https://hartmantoothpaste.com/favicon.icoAvira URL Cloud: Label: phishing

Phishing

barindex
Source: Subscription_Renewal_Receipt_2025.htmHTTP Parser: Low number of body elements: 0
Source: Subscription_Renewal_Receipt_2025.htmHTTP Parser: .location
Source: Subscription_Renewal_Receipt_2025.htmHTTP Parser: .location
Source: Subscription_Renewal_Receipt_2025.htmHTTP Parser: No favicon

Networking

barindex
Source: Network trafficSuricata IDS: 2057333 - Severity 1 - ET PHISHING MAMBA Credential Phish Landing Page 2024-11-08 : 192.168.2.4:49739 -> 68.178.204.95:443
Source: global trafficTCP traffic: 192.168.2.4:62978 -> 1.1.1.1:53
Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox ViewASN Name: AS-26496-GO-DADDY-COM-LLCUS AS-26496-GO-DADDY-COM-LLCUS
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /js/epEQA/albert.schober@poeschl-tobacco.de HTTP/1.1Host: hartmantoothpaste.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: hartmantoothpaste.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://hartmantoothpaste.com/js/epEQA/albert.schober@poeschl-tobacco.deAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.de HTTP/1.1Host: airductcleaningrosenbergtx.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://hartmantoothpaste.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: airductcleaningrosenbergtx.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://airductcleaningrosenbergtx.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.deAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: hartmantoothpaste.com
Source: global trafficDNS traffic detected: DNS query: airductcleaningrosenbergtx.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 16 Jan 2025 06:42:52 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 16 Jan 2025 06:42:52 GMTServer: ApacheLast-Modified: Wed, 21 Feb 2024 10:07:10 GMTAccept-Ranges: bytesContent-Length: 1102Vary: User-AgentStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadConnection: closeContent-Type: text/html; charset=utf-8Content-Language: en-Us
Source: chromecache_72.2.drString found in binary or memory: https://airductcleaningrosenbergtx.com
Source: Subscription_Renewal_Receipt_2025.htmString found in binary or memory: https://hartmantoothpaste.com/js/epEQA/albert.schober
Source: chromecache_72.2.drString found in binary or memory: https://www.googletagmanager.com/gtag/js?id=G-V9L39L2JXG
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62983 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62983
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443

System Summary

barindex
Source: Name includes: Subscription_Renewal_Receipt_2025.htmInitial sample: receipt
Source: classification engineClassification label: mal68.phis.winHTM@26/6@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\Subscription_Renewal_Receipt_2025.htm"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=2000,i,2848020951146539357,7329775341439803869,262144 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=2000,i,2848020951146539357,7329775341439803869,262144 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Subscription_Renewal_Receipt_2025.htm0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://airductcleaningrosenbergtx.com/favicon.ico0%Avira URL Cloudsafe
https://hartmantoothpaste.com/js/epEQA/albert.schober100%Avira URL Cloudphishing
https://hartmantoothpaste.com/favicon.ico100%Avira URL Cloudphishing
https://airductcleaningrosenbergtx.com0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
hartmantoothpaste.com
172.93.120.103
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      high
      airductcleaningrosenbergtx.com
      68.178.204.95
      truetrue
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://hartmantoothpaste.com/js/epEQA/albert.schober@poeschl-tobacco.defalse
          unknown
          https://airductcleaningrosenbergtx.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.defalse
            unknown
            https://airductcleaningrosenbergtx.com/favicon.icotrue
            • Avira URL Cloud: safe
            unknown
            https://hartmantoothpaste.com/favicon.icofalse
            • Avira URL Cloud: phishing
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://hartmantoothpaste.com/js/epEQA/albert.schoberSubscription_Renewal_Receipt_2025.htmfalse
            • Avira URL Cloud: phishing
            unknown
            https://airductcleaningrosenbergtx.comchromecache_72.2.drfalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            68.178.204.95
            airductcleaningrosenbergtx.comUnited States
            26496AS-26496-GO-DADDY-COM-LLCUStrue
            172.93.120.103
            hartmantoothpaste.comUnited States
            393960HOST4GEEKS-LLCUSfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            192.168.2.5
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1592477
            Start date and time:2025-01-16 07:41:47 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 5m 6s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowshtmlcookbook.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:Subscription_Renewal_Receipt_2025.htm
            Detection:MAL
            Classification:mal68.phis.winHTM@26/6@6/6
            Cookbook Comments:
            • Found application associated with file extension: .htm
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.18.3, 172.217.16.206, 142.251.168.84, 142.250.186.78, 216.58.206.46, 199.232.210.172, 172.217.18.106, 216.58.212.170, 142.250.184.202, 172.217.16.202, 216.58.206.74, 142.250.185.138, 142.250.184.234, 172.217.18.10, 142.250.181.234, 142.250.186.170, 142.250.185.234, 142.250.185.74, 142.250.186.138, 142.250.186.106, 216.58.206.42, 142.250.185.106, 2.23.77.188, 142.250.184.206, 142.250.186.174, 172.217.18.14, 142.250.186.46, 142.250.181.238, 216.58.206.35, 142.250.80.46, 74.125.0.102, 142.250.185.206, 142.250.185.142, 184.28.90.27, 4.245.163.56, 13.107.246.45
            • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com, optimizationguide-pa.googleapis.com
            • Not all processes where analyzed, report is missing behavior information
            No simulations
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            239.255.255.250https://contract.nacap-holding.com/gas25/Get hashmaliciousUnknownBrowse
              https://guf1.xemirax.ru/Get hashmaliciousUnknownBrowse
                https://guf1.xemirax.ru/6XAVE/#S#ZWRtb25kLmxlZUBpbm5vY2FwLmNvbQ==Get hashmaliciousUnknownBrowse
                  https://yt1s.com/en115Get hashmaliciousUnknownBrowse
                    Subscription_Renewal_Invoice_2025_FGHDCS.htmlGet hashmaliciousHTMLPhisherBrowse
                      https://yogalisbon.gitcz.pw/sign-inGet hashmaliciousUnknownBrowse
                        http://com-evaluate-fanpage30127.pages.dev/help/contact/671203900952887Get hashmaliciousHTMLPhisherBrowse
                          http://docs-wltconnect.gitbook.io/us-enGet hashmaliciousHTMLPhisherBrowse
                            https://inhospitality.shop/Get hashmaliciousUnknownBrowse
                              https://docusign6478.weebly.com/Get hashmaliciousUnknownBrowse
                                172.93.120.103https://q89x88qh.r.ap-southeast-1.awstrack.me/L0/https:%2F%2Fblackdoor.in%2Fcazxccall%2Frtyucallingzxc%2F/1/010e01946a4fedf7-6a14e9da-4611-4b34-a7c5-f58f00519f0d-000000/p9HvzYrykwYBivTgZCa5Kf2-wBc=194Get hashmaliciousUnknownBrowse
                                  https://garfieldthecat.tech/Receipt.htmlGet hashmaliciousWinSearchAbuseBrowse
                                    https://www.google.im/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s/naimestyles.com%2Frtwo%2Fn%2FNUaX8EOAfixpQMTfRAnHcKww/eGlzaEBub3ZvenltZXMuY29tGet hashmaliciousHTMLPhisherBrowse
                                      https://naimestyles.com/rtwo/n/3rrLaAvg41CM3J4mAJYroltS/c3BhY2VpbnZpZGVvc0Blc2EuaW50Get hashmaliciousHTMLPhisherBrowse
                                        No context
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        HOST4GEEKS-LLCUShttps://google.com.vn/url?q=IEQBZO82U018ETYNCV6WTYH64K0BD9FgQiApLjODz3yh4nNeW8uuQi&rct=bbc6b8ec37f99d3559160eb2c01fcbb8wDnNeW8yycT&sa=t&esrc=nTgV8Fbbc6b8ec37f99d3559160eb2c01fcbb8A0xys8Em2FL&source=&cd=tS6T8bbc6b8ec37f99d3559160eb2c01fcbb8Tiw9XH&cad=JxWzDfBPbbc6b8ec37f99d3559160eb2c01fcbb8VS0Y&ved=xjnktlqryYWwVTDrgvK&uact=&url=amp%2Ftechnicdude.in/opuyc/bbc6b8ec37f99d3559160eb2c01fcbb8/ZnJlZC5uZXdjb21AY29sb25pYWxjaGVtLmNvbQ==Get hashmaliciousUnknownBrowse
                                        • 185.221.216.102
                                        https://google.com.vn/url?q=IEQBZO82U018ETYNCV6WTYH64K0BD9FgQiApLjODz3yh4nNeW8uuQi&rct=152c27645d86ba0833d5001d33047642wDnNeW8yycT&sa=t&esrc=nTgV8F152c27645d86ba0833d5001d33047642A0xys8Em2FL&source=&cd=tS6T8152c27645d86ba0833d5001d33047642Tiw9XH&cad=JxWzDfBP152c27645d86ba0833d5001d33047642VS0Y&ved=xjnktlqryYWwVTDrgvK&uact=&url=amp%2Fsexado.nl/helosuns/152c27645d86ba0833d5001d33047642/bWlzdHkuYWxuYWhhb2lAdGV4YW5hY2VudGVyLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                        • 185.221.216.128
                                        https://google.com.vn/url?q=IEQBZO82U018ETYNCV6WTYH64K0BD9FgQiApLjODz3yh4nNeW8uuQi&rct=152c27645d86ba0833d5001d33047642wDnNeW8yycT&sa=t&esrc=nTgV8F152c27645d86ba0833d5001d33047642A0xys8Em2FL&source=&cd=tS6T8152c27645d86ba0833d5001d33047642Tiw9XH&cad=JxWzDfBP152c27645d86ba0833d5001d33047642VS0Y&ved=xjnktlqryYWwVTDrgvK&uact=&url=amp%2Fsexado.nl/helosuns/152c27645d86ba0833d5001d33047642/bWlzdHkuYWxuYWhhb2lAdGV4YW5hY2VudGVyLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                        • 185.221.216.128
                                        https://q89x88qh.r.ap-southeast-1.awstrack.me/L0/https:%2F%2Fblackdoor.in%2Fcazxccall%2Frtyucallingzxc%2F/1/010e01946a4fedf7-6a14e9da-4611-4b34-a7c5-f58f00519f0d-000000/p9HvzYrykwYBivTgZCa5Kf2-wBc=194Get hashmaliciousUnknownBrowse
                                        • 172.93.120.103
                                        Subscription_Renewal_Receipt_2025.htmGet hashmaliciousHTMLPhisherBrowse
                                        • 185.221.216.102
                                        Statements.pdfGet hashmaliciousWinSearchAbuseBrowse
                                        • 172.93.120.113
                                        https://garfieldthecat.tech/Receipt.htmlGet hashmaliciousWinSearchAbuseBrowse
                                        • 172.93.120.103
                                        https://www.google.com.hk/url?q=KWUZMS42J831JSWOSF4KEIP36T3IE7YuQiApLjODz3yh4nNeW8uuQi&rct=XS%25RANDOM4%25wDnNeW8yycT&sa=t&esrc=nNeW8F%25RANDOM3%25A0xys8Em2FL&source=&cd=tS6T8%25RANDOM3%25Tiw9XH&cad=XpPkDfJX%25RANDOM4%25VS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2Fasubiad.online/grieksm/366a15ae094dd43620eb959537cb323e8fcdb76b/bWZpbm5lZ2FuQHVzY2hhbWJlci5jb20=Get hashmaliciousUnknownBrowse
                                        • 185.221.216.117
                                        https://listafrica.org/Receipt.htmlGet hashmaliciousWinSearchAbuseBrowse
                                        • 172.93.120.138
                                        https://stoorm5.activehosted.com/content/PNNm1e/2024/11/29/296d9a00-ab7c-413b-8445-d50603229893.pdfGet hashmaliciousHTMLPhisherBrowse
                                        • 185.221.216.128
                                        AS-26496-GO-DADDY-COM-LLCUShttp://petruccilaw.com/Get hashmaliciousUnknownBrowse
                                        • 107.180.51.237
                                        NLWfV87ouS.dllGet hashmaliciousWannacryBrowse
                                        • 72.167.90.1
                                        http://www.northamericaniron.comGet hashmaliciousUnknownBrowse
                                        • 50.63.8.11
                                        https://www.xrmtoolbox.com/Get hashmaliciousUnknownBrowse
                                        • 50.63.8.184
                                        mips.elfGet hashmaliciousUnknownBrowse
                                        • 68.178.237.155
                                        UTstKgkJNY.exeGet hashmaliciousDBatLoaderBrowse
                                        • 166.62.27.188
                                        On9ahUpI4R.exeGet hashmaliciousDBatLoaderBrowse
                                        • 166.62.27.188
                                        JDQS879kiy.exeGet hashmaliciousDBatLoaderBrowse
                                        • 166.62.27.188
                                        UAHIzSm2x2.exeGet hashmaliciousDBatLoaderBrowse
                                        • 166.62.27.188
                                        LbZ88q4uPa.exeGet hashmaliciousDBatLoaderBrowse
                                        • 166.62.27.188
                                        No context
                                        No context
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:very short file (no magic)
                                        Category:downloaded
                                        Size (bytes):1
                                        Entropy (8bit):0.0
                                        Encrypted:false
                                        SSDEEP:3:v:v
                                        MD5:68B329DA9893E34099C7D8AD5CB9C940
                                        SHA1:ADC83B19E793491B1C6EA0FD8B46CD9F32E592FC
                                        SHA-256:01BA4719C80B6FE911B091A7C05124B64EEECE964E09C058EF8F9805DACA546B
                                        SHA-512:BE688838CA8686E5C90689BF2AB585CEF1137C999B48C70B92F67A5C34DC15697B5D11C982ED6D71BE1E1E7F7B4E0733884AA97C3F7A339A8ED03577CF74BE09
                                        Malicious:false
                                        Reputation:high, very likely benign file
                                        URL:https://airductcleaningrosenbergtx.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.de
                                        Preview:.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:HTML document, ASCII text
                                        Category:downloaded
                                        Size (bytes):315
                                        Entropy (8bit):5.0572271090563765
                                        Encrypted:false
                                        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
                                        MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
                                        SHA1:A82190FC530C265AA40A045C21770D967F4767B8
                                        SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
                                        SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
                                        Malicious:false
                                        Reputation:high, very likely benign file
                                        URL:https://hartmantoothpaste.com/favicon.ico
                                        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:HTML document, ASCII text
                                        Category:downloaded
                                        Size (bytes):1102
                                        Entropy (8bit):5.192228407449722
                                        Encrypted:false
                                        SSDEEP:24:hYwf5/v/hVkXi5C0l0eJGTfGCQvPZWhNcfP/bykKCJPV4gM:Ff53sSrNJ+fRiPgNuRKCJigM
                                        MD5:1132B133E792E16D5DB600A21D829A77
                                        SHA1:FAF7BDBC77984FB259601EA329C834E997D6E9DA
                                        SHA-256:D0D7E43579370148934A84E290ED77E01A8CFB9E82751F23A4F0CCD83D70136F
                                        SHA-512:75C4912231405B5A9FF4E3657DDB9EFA5362FEFC05F2409499B781C091BAC32BA046D3FF46EB265C7C51204CF4142E8BB3EB9DCC1F3DCCBDF3407EF876E1D8AC
                                        Malicious:false
                                        Reputation:low
                                        URL:https://airductcleaningrosenbergtx.com/favicon.ico
                                        Preview:<!DOCTYPE html>.<html lang="en">..<head>. Google tag (gtag.js) -->.<script async src="https://www.googletagmanager.com/gtag/js?id=G-V9L39L2JXG"></script>.<script>. window.dataLayer = window.dataLayer || [];. function gtag(){dataLayer.push(arguments);}. gtag('js', new Date());.. gtag('config', 'G-V9L39L2JXG');.</script>.. <meta charset="UTF-8">. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>Not Found Page</title>.. <link rel="stylesheet" href="dist/css/bootstrap.min.css">. <link rel="stylesheet" href="dist/css/themify-icons.css">. <link rel="stylesheet" href="dist/css/main.css">...</head>..<body style="background-color: #fff;">. <main>. <div class="not-found">. <img src="dist/assets/404-error.webp" alt="Not Found" title="not found" class="img-fluid" width="1000". height="1000">. </div>. <a href="https://airductcleaningrosenbergtx.com" class="not-found-btn rounded-
                                        File type:HTML document, ASCII text
                                        Entropy (8bit):5.076866861297601
                                        TrID:
                                        • HyperText Markup Language (12001/1) 40.67%
                                        • HyperText Markup Language (11501/1) 38.98%
                                        • HyperText Markup Language (6006/1) 20.35%
                                        File name:Subscription_Renewal_Receipt_2025.htm
                                        File size:241 bytes
                                        MD5:285e5dd90510772b1bf7c5fe08eeb8c6
                                        SHA1:3d7b63c71a01be23a07807242bd13b60f8c259e5
                                        SHA256:d6c92415e04c02bd1d0f8b5b838d8993cdf8bccf9bc31796173125a985891044
                                        SHA512:41f6f37dd7aae9a32bef4c93ec827ea6972488014f279c5c6787dc2b79331f513a8fc8d59c4649dacfe29309e112f9d47e7f3e27442342a0ea685bf371fe2fe3
                                        SSDEEP:6:qv3uGuJG+wESThcmWi9a9Zm9aL8iIB03b:41BiY7a9gJSr
                                        TLSH:62D097FB88609C0281B283BD12835AD8F2A33068208ACA6E4340E060000066CD747348
                                        File Content Preview:<html> .<head> .<title>Detail notification for www.cbc.ca</title> .</head> .<body> .<SCRIPT LANGUAGE="JavaScript"> . .self.location = 'https://hartmantoothpaste.com/js/epEQA/albert.schober@poeschl-tobacco.de'; .//--> .</SCRIPT> .</body>
                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                        2025-01-16T07:42:52.599874+01002057333ET PHISHING MAMBA Credential Phish Landing Page 2024-11-081192.168.2.44973968.178.204.95443TCP
                                        TimestampSource PortDest PortSource IPDest IP
                                        Jan 16, 2025 07:42:48.345994949 CET49675443192.168.2.4173.222.162.32
                                        Jan 16, 2025 07:42:50.275393963 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.275444984 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.275597095 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.276001930 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.276048899 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.276106119 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.276575089 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.276592016 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.277008057 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.277024984 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.934160948 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.934413910 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.934439898 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.936079025 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.936177015 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.937356949 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.937385082 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.937390089 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.937618971 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.949181080 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.949421883 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.949453115 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.953440905 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:50.953634977 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.954149961 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:50.954334021 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.036474943 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.036488056 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.036523104 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.036551952 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.144669056 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.144736052 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.214610100 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.214783907 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.214840889 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.238157988 CET49733443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.238179922 CET44349733172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.308145046 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.355407953 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.501646996 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.501812935 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.501867056 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.506190062 CET49734443192.168.2.4172.93.120.103
                                        Jan 16, 2025 07:42:51.506210089 CET44349734172.93.120.103192.168.2.4
                                        Jan 16, 2025 07:42:51.594613075 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.594703913 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:51.594794035 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.595027924 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.595082045 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:51.595153093 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.597032070 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.597083092 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:51.597382069 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:51.597404003 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.190207005 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.192915916 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.192949057 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.194430113 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.194509029 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.196115971 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.196207047 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.196516991 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.196527004 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.199758053 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.199985027 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.200047970 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.201725006 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.201833963 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.202770948 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.202872038 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.255278111 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.255368948 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.289324999 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.301491022 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.599977016 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.600142002 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.600353003 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.671624899 CET49739443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.671703100 CET4434973968.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:52.900041103 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:52.943367958 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:53.056464911 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:53.056653023 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:53.056739092 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:53.057415009 CET49738443192.168.2.468.178.204.95
                                        Jan 16, 2025 07:42:53.057456970 CET4434973868.178.204.95192.168.2.4
                                        Jan 16, 2025 07:42:53.433279991 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:53.433309078 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:53.433381081 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:53.433578968 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:53.433592081 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.073627949 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.073935986 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:54.073960066 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.075639963 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.075723886 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:54.076828003 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:54.077110052 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.126338005 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:42:54.126349926 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:42:54.173216105 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:02.641201019 CET4972380192.168.2.4199.232.214.172
                                        Jan 16, 2025 07:43:02.646440983 CET8049723199.232.214.172192.168.2.4
                                        Jan 16, 2025 07:43:02.646652937 CET4972380192.168.2.4199.232.214.172
                                        Jan 16, 2025 07:43:03.966859102 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:03.967034101 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:03.967112064 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:04.342015028 CET49741443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:04.342044115 CET44349741142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:49.627032042 CET4972480192.168.2.4199.232.214.172
                                        Jan 16, 2025 07:43:49.632051945 CET8049724199.232.214.172192.168.2.4
                                        Jan 16, 2025 07:43:49.632111073 CET4972480192.168.2.4199.232.214.172
                                        Jan 16, 2025 07:43:52.915101051 CET6297853192.168.2.41.1.1.1
                                        Jan 16, 2025 07:43:52.919855118 CET53629781.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:52.919933081 CET6297853192.168.2.41.1.1.1
                                        Jan 16, 2025 07:43:52.919965982 CET6297853192.168.2.41.1.1.1
                                        Jan 16, 2025 07:43:52.924757004 CET53629781.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:53.363533974 CET53629781.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:53.364161015 CET6297853192.168.2.41.1.1.1
                                        Jan 16, 2025 07:43:53.369210005 CET53629781.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:53.369297028 CET6297853192.168.2.41.1.1.1
                                        Jan 16, 2025 07:43:53.487615108 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:53.487628937 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:53.487704039 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:53.487930059 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:53.487940073 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:54.150814056 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:54.151135921 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:54.151144028 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:54.151429892 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:54.151716948 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:43:54.151770115 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:43:54.204931974 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:44:04.051222086 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:44:04.051292896 CET44362983142.250.186.100192.168.2.4
                                        Jan 16, 2025 07:44:04.051353931 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:44:04.628951073 CET62983443192.168.2.4142.250.186.100
                                        Jan 16, 2025 07:44:04.628971100 CET44362983142.250.186.100192.168.2.4
                                        TimestampSource PortDest PortSource IPDest IP
                                        Jan 16, 2025 07:42:49.644591093 CET53634531.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:49.712970972 CET53494241.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:49.929167986 CET5170753192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:49.929246902 CET6550253192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:50.109884024 CET53655021.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:50.258816004 CET53517071.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:50.766720057 CET53621071.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:51.296668053 CET6033653192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:51.296823025 CET5549453192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:51.575638056 CET53554941.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:51.593668938 CET53603361.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:53.424240112 CET6179653192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:53.424432039 CET5463753192.168.2.41.1.1.1
                                        Jan 16, 2025 07:42:53.431828022 CET53546371.1.1.1192.168.2.4
                                        Jan 16, 2025 07:42:53.432243109 CET53617961.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:01.212393999 CET138138192.168.2.4192.168.2.255
                                        Jan 16, 2025 07:43:02.274796009 CET53633911.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:07.749829054 CET53533511.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:26.447957993 CET53637301.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:48.869669914 CET53572931.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:49.308326006 CET53591161.1.1.1192.168.2.4
                                        Jan 16, 2025 07:43:52.914663076 CET53517151.1.1.1192.168.2.4
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Jan 16, 2025 07:42:49.929167986 CET192.168.2.41.1.1.10x5ddcStandard query (0)hartmantoothpaste.comA (IP address)IN (0x0001)false
                                        Jan 16, 2025 07:42:49.929246902 CET192.168.2.41.1.1.10x2fc5Standard query (0)hartmantoothpaste.com65IN (0x0001)false
                                        Jan 16, 2025 07:42:51.296668053 CET192.168.2.41.1.1.10x1ba3Standard query (0)airductcleaningrosenbergtx.comA (IP address)IN (0x0001)false
                                        Jan 16, 2025 07:42:51.296823025 CET192.168.2.41.1.1.10xadbStandard query (0)airductcleaningrosenbergtx.com65IN (0x0001)false
                                        Jan 16, 2025 07:42:53.424240112 CET192.168.2.41.1.1.10x764Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                        Jan 16, 2025 07:42:53.424432039 CET192.168.2.41.1.1.10xe3bfStandard query (0)www.google.com65IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Jan 16, 2025 07:42:50.258816004 CET1.1.1.1192.168.2.40x5ddcNo error (0)hartmantoothpaste.com172.93.120.103A (IP address)IN (0x0001)false
                                        Jan 16, 2025 07:42:51.593668938 CET1.1.1.1192.168.2.40x1ba3No error (0)airductcleaningrosenbergtx.com68.178.204.95A (IP address)IN (0x0001)false
                                        Jan 16, 2025 07:42:53.431828022 CET1.1.1.1192.168.2.40xe3bfNo error (0)www.google.com65IN (0x0001)false
                                        Jan 16, 2025 07:42:53.432243109 CET1.1.1.1192.168.2.40x764No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
                                        • hartmantoothpaste.com
                                        • https:
                                          • airductcleaningrosenbergtx.com
                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        0192.168.2.449733172.93.120.1034431364C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2025-01-16 06:42:50 UTC692OUTGET /js/epEQA/albert.schober@poeschl-tobacco.de HTTP/1.1
                                        Host: hartmantoothpaste.com
                                        Connection: keep-alive
                                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                        sec-ch-ua-mobile: ?0
                                        sec-ch-ua-platform: "Windows"
                                        Upgrade-Insecure-Requests: 1
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                        Sec-Fetch-Site: cross-site
                                        Sec-Fetch-Mode: navigate
                                        Sec-Fetch-Dest: document
                                        Accept-Encoding: gzip, deflate, br
                                        Accept-Language: en-US,en;q=0.9
                                        2025-01-16 06:42:51 UTC321INHTTP/1.1 200 OK
                                        Date: Thu, 16 Jan 2025 06:42:52 GMT
                                        Server: Apache
                                        refresh: 0;url= https://airductcleaningrosenbergtx.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.de
                                        Content-Length: 0
                                        Connection: close
                                        Content-Type: text/html; charset=UTF-8


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        1192.168.2.449734172.93.120.1034431364C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2025-01-16 06:42:51 UTC640OUTGET /favicon.ico HTTP/1.1
                                        Host: hartmantoothpaste.com
                                        Connection: keep-alive
                                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                        sec-ch-ua-mobile: ?0
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                        sec-ch-ua-platform: "Windows"
                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                        Sec-Fetch-Site: same-origin
                                        Sec-Fetch-Mode: no-cors
                                        Sec-Fetch-Dest: image
                                        Referer: https://hartmantoothpaste.com/js/epEQA/albert.schober@poeschl-tobacco.de
                                        Accept-Encoding: gzip, deflate, br
                                        Accept-Language: en-US,en;q=0.9
                                        2025-01-16 06:42:51 UTC164INHTTP/1.1 404 Not Found
                                        Date: Thu, 16 Jan 2025 06:42:52 GMT
                                        Server: Apache
                                        Content-Length: 315
                                        Connection: close
                                        Content-Type: text/html; charset=iso-8859-1
                                        2025-01-16 06:42:51 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
                                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        2192.168.2.44973968.178.204.954431364C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2025-01-16 06:42:52 UTC814OUTGET /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.de HTTP/1.1
                                        Host: airductcleaningrosenbergtx.com
                                        Connection: keep-alive
                                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                        sec-ch-ua-mobile: ?0
                                        sec-ch-ua-platform: "Windows"
                                        Upgrade-Insecure-Requests: 1
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                        Sec-Fetch-Site: cross-site
                                        Sec-Fetch-Mode: navigate
                                        Sec-Fetch-Dest: document
                                        Referer: https://hartmantoothpaste.com/
                                        Accept-Encoding: gzip, deflate, br
                                        Accept-Language: en-US,en;q=0.9
                                        2025-01-16 06:42:52 UTC364INHTTP/1.1 200 OK
                                        Date: Thu, 16 Jan 2025 06:42:52 GMT
                                        Server: Apache
                                        Cache-Control: max-age=31536000
                                        Expires: Fri, 16 Jan 2026 06:42:52 GMT
                                        Vary: Accept-Encoding,User-Agent
                                        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                        Connection: close
                                        Transfer-Encoding: chunked
                                        Content-Type: text/html; charset=UTF-8
                                        Content-Language: en-Us
                                        2025-01-16 06:42:52 UTC11INData Raw: 31 0d 0a 0a 0d 0a 30 0d 0a 0d 0a
                                        Data Ascii: 10


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        3192.168.2.44973868.178.204.954431364C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2025-01-16 06:42:52 UTC730OUTGET /favicon.ico HTTP/1.1
                                        Host: airductcleaningrosenbergtx.com
                                        Connection: keep-alive
                                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                        sec-ch-ua-mobile: ?0
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                        sec-ch-ua-platform: "Windows"
                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                        Sec-Fetch-Site: same-origin
                                        Sec-Fetch-Mode: no-cors
                                        Sec-Fetch-Dest: image
                                        Referer: https://airductcleaningrosenbergtx.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVJEaHhZMUU9JnVpZD1VU0VSMDgwMTIwMjVVNTQwMTA4MjU=N0123Nalbert.schober@poeschl-tobacco.de
                                        Accept-Encoding: gzip, deflate, br
                                        Accept-Language: en-US,en;q=0.9
                                        2025-01-16 06:42:53 UTC344INHTTP/1.1 404 Not Found
                                        Date: Thu, 16 Jan 2025 06:42:52 GMT
                                        Server: Apache
                                        Last-Modified: Wed, 21 Feb 2024 10:07:10 GMT
                                        Accept-Ranges: bytes
                                        Content-Length: 1102
                                        Vary: User-Agent
                                        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                        Connection: close
                                        Content-Type: text/html; charset=utf-8
                                        Content-Language: en-Us
                                        2025-01-16 06:42:53 UTC1102INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 3c 21 2d 2d 20 47 6f 6f 67 6c 65 20 74 61 67 20 28 67 74 61 67 2e 6a 73 29 20 2d 2d 3e 0a 3c 73 63 72 69 70 74 20 61 73 79 6e 63 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 74 61 67 6d 61 6e 61 67 65 72 2e 63 6f 6d 2f 67 74 61 67 2f 6a 73 3f 69 64 3d 47 2d 56 39 4c 33 39 4c 32 4a 58 47 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 3e 0a 20 20 77 69 6e 64 6f 77 2e 64 61 74 61 4c 61 79 65 72 20 3d 20 77 69 6e 64 6f 77 2e 64 61 74 61 4c 61 79 65 72 20 7c 7c 20 5b 5d 3b 0a 20 20 66 75 6e 63 74 69 6f 6e 20 67 74 61 67 28 29 7b 64 61 74 61 4c 61 79 65 72 2e 70 75 73 68 28 61 72 67 75 6d 65 6e 74 73 29
                                        Data Ascii: <!DOCTYPE html><html lang="en"><head>... Google tag (gtag.js) --><script async src="https://www.googletagmanager.com/gtag/js?id=G-V9L39L2JXG"></script><script> window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments)


                                        Click to jump to process

                                        Click to jump to process

                                        Click to jump to process

                                        Target ID:0
                                        Start time:01:42:44
                                        Start date:16/01/2025
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\Subscription_Renewal_Receipt_2025.htm"
                                        Imagebase:0x7ff76e190000
                                        File size:3'242'272 bytes
                                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:false

                                        Target ID:2
                                        Start time:01:42:47
                                        Start date:16/01/2025
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=2000,i,2848020951146539357,7329775341439803869,262144 /prefetch:8
                                        Imagebase:0x7ff76e190000
                                        File size:3'242'272 bytes
                                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:false

                                        No disassembly