Edit tour

Windows Analysis Report
https://bs.yandex.ru

Overview

General Information

Sample URL:https://bs.yandex.ru
Analysis ID:1596306
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64native
  • chrome.exe (PID: 3644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: BB7C48CDDDE076E7EB44022520F40F77)
    • chrome.exe (PID: 7104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2200,i,7155160346389576464,13776737258751094368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2212 /prefetch:3 MD5: BB7C48CDDDE076E7EB44022520F40F77)
  • chrome.exe (PID: 8132 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bs.yandex.ru" MD5: BB7C48CDDDE076E7EB44022520F40F77)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\scoped_dir3644_985836869Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_3644_92290103Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.21.237
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.179.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.11.104
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.179.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.11.104
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bs.yandex.ruConnection: keep-alivesec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bs.yandex.ruConnection: keep-alivesec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bs.yandex.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: i=wRbpCQtWbz++RRnNVZnVXpMtGq0JvIO8MyFdQM0OW7EK1AgMpi73ovzJfOhriVRiqqXNEsKrC5wWVJpPWhHuQCGbrsU=; yandexuid=4469008961737497628; yashr=9251108951737497628; bh=EkEiQ2hyb21pdW0iO3Y9IjEyOCIsICJOb3Q7QT1CcmFuZCI7dj0iMjQiLCAiR29vZ2xlIENocm9tZSI7dj0iMTI4IioCPzA6CSJXaW5kb3dzImCcuMC8Bmoe3Mrh/wiS2KGxA5/P4eoD+/rw5w3r//32D7bGzIcI
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: bs.yandex.ru
Source: global trafficTCP traffic: 192.168.11.20:59642 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:59642 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:59642 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:59642 -> 239.255.255.250:1900
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: private, no-cache, no-store, must-revalidate, max-age=0Connection: CloseContent-Length: 29Content-Type: text/html; charset=windows-1251Date: Tue, 21 Jan 2025 22:13:48 GMTExpires: Tue, 21 Jan 2025 22:13:48 GMTLast-Modified: Tue, 21 Jan 2025 22:13:48 GMTPragma: no-cacheSet-Cookie: i=wRbpCQtWbz++RRnNVZnVXpMtGq0JvIO8MyFdQM0OW7EK1AgMpi73ovzJfOhriVRiqqXNEsKrC5wWVJpPWhHuQCGbrsU=; Expires=Thu, 21-Jan-2027 22:13:48 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly; SameSite=NoneSet-Cookie: yandexuid=4469008961737497628; Expires=Thu, 21-Jan-2027 22:13:48 GMT; Domain=.yandex.ru; Path=/; Secure; SameSite=NoneSet-Cookie: yashr=9251108951737497628; Path=/; Domain=.yandex.ru; Expires=Wed, 21 Jan 2026 22:13:48 GMT; SameSite=None; Secure; HttpOnlySet-Cookie: bh=EkEiQ2hyb21pdW0iO3Y9IjEyOCIsICJOb3Q7QT1CcmFuZCI7dj0iMjQiLCAiR29vZ2xlIENocm9tZSI7dj0iMTI4IioCPzA6CSJXaW5kb3dzImCcuMC8Bmoe3Mrh/wiS2KGxA5/P4eoD+/rw5w3r//32D7bGzIcI; Path=/; Domain=.yandex.ru; Expires=Wed, 25 Feb 2026 22:13:48 GMT; SameSite=None; SecureStrict-Transport-Security: max-age=31536000Timing-Allow-Origin: *X-XSS-Protection: 1; mode=block
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: private, no-cache, no-store, must-revalidate, max-age=0Connection: CloseContent-Length: 29Content-Type: text/html; charset=windows-1251Date: Tue, 21 Jan 2025 22:13:48 GMTExpires: Tue, 21 Jan 2025 22:13:48 GMTLast-Modified: Tue, 21 Jan 2025 22:13:48 GMTPragma: no-cacheStrict-Transport-Security: max-age=31536000Timing-Allow-Origin: *X-XSS-Protection: 1; mode=block
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: classification engineClassification label: clean0.win@16/0@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\scoped_dir3644_985836869Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2200,i,7155160346389576464,13776737258751094368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2212 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bs.yandex.ru"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2200,i,7155160346389576464,13776737258751094368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2212 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\scoped_dir3644_985836869Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_3644_92290103Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential Dumping1
Network Service Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1596306 URL: https://bs.yandex.ru Startdate: 21/01/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.11.20, 137, 1900, 443 unknown unknown 5->13 15 239.255.255.250, 1900 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 bs.yandex.ru 93.158.134.90, 443, 49777, 49778 YANDEXRU Russian Federation 10->17 19 www.google.com 142.251.167.104, 443, 49776, 49786 GOOGLEUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://bs.yandex.ru0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
bs.yandex.ru
93.158.134.90
truefalse
    high
    www.google.com
    142.251.167.104
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://bs.yandex.ru/favicon.icofalse
        high
        https://bs.yandex.ru/false
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          93.158.134.90
          bs.yandex.ruRussian Federation
          13238YANDEXRUfalse
          142.251.167.104
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.11.20
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1596306
          Start date and time:2025-01-21 23:11:35 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 4m 25s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://bs.yandex.ru
          Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 128, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
          Run name:Potential for more IOCs and behavior
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/0@4/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.167.94, 142.251.111.113, 142.251.111.100, 142.251.111.101, 142.251.111.139, 142.251.111.102, 142.251.111.138, 142.251.179.84, 142.251.16.113, 142.251.16.101, 142.251.16.138, 142.251.16.139, 142.251.16.102, 142.251.16.100, 172.253.122.138, 172.253.122.102, 172.253.122.100, 172.253.122.139, 172.253.122.113, 172.253.122.101, 142.251.163.101, 142.251.163.138, 142.251.163.139, 142.251.163.100, 142.251.163.102, 142.251.163.113, 142.251.167.138, 142.251.167.100, 142.251.167.102, 142.251.167.101, 142.251.167.139, 142.251.167.113, 64.233.180.113, 64.233.180.101, 64.233.180.102, 64.233.180.100, 64.233.180.138, 64.233.180.139, 172.253.62.100, 172.253.62.101, 172.253.62.139, 172.253.62.113, 172.253.62.102, 172.253.62.138, 142.251.16.95, 172.253.115.95, 172.253.62.95, 172.253.63.95, 142.251.163.95, 142.250.31.95, 142.251.167.95, 64.233.180.95, 142.251.111.95, 142.251.179.95, 172.253.122.95, 199.232.214.172, 142.250.31.138, 142.250.31.101, 142.250.31.102, 142.250.31.100, 14
          • Excluded domains from analysis (whitelisted): clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.googleapis.com, dns.msftncsi.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: https://bs.yandex.ru
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 53
          • 1900 undefined
          • 443 (HTTPS)
          • 80 (HTTP)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Jan 21, 2025 23:13:46.105429888 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.105470896 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.105647087 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.105947018 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.105971098 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.529584885 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.530004978 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.530016899 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.530931950 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.531168938 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.531768084 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.531846046 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.581717968 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:46.581728935 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:46.628470898 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:47.309658051 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.309695959 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:47.309880972 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.309972048 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.310019016 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:47.310173035 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.310173035 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.310199022 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:47.310503960 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:47.310528994 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.009459019 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.009850025 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.009888887 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.012635946 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.012980938 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.013637066 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.013780117 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.013911009 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.018378019 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.018706083 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.018738031 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.021560907 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.021794081 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.022053003 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.022274971 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.064994097 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.065032959 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.065035105 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.065069914 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.114269018 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.114301920 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.477355003 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.477554083 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.477735043 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.478240967 CET49777443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.478283882 CET4434977793.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.505419016 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.546256065 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.763717890 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.763911009 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:48.764072895 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.764265060 CET49778443192.168.11.2093.158.134.90
          Jan 21, 2025 23:13:48.764298916 CET4434977893.158.134.90192.168.11.20
          Jan 21, 2025 23:13:56.562503099 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:56.562567949 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:13:56.562756062 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:57.441385984 CET49776443192.168.11.20142.251.167.104
          Jan 21, 2025 23:13:57.441415071 CET44349776142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:23.004509926 CET49768443192.168.11.2013.107.21.237
          Jan 21, 2025 23:14:23.174294949 CET4976980192.168.11.20142.251.179.94
          Jan 21, 2025 23:14:23.174294949 CET4976780192.168.11.2023.53.11.104
          Jan 21, 2025 23:14:23.283966064 CET804976723.53.11.104192.168.11.20
          Jan 21, 2025 23:14:23.283977032 CET8049769142.251.179.94192.168.11.20
          Jan 21, 2025 23:14:23.284128904 CET4976980192.168.11.20142.251.179.94
          Jan 21, 2025 23:14:23.284207106 CET4976780192.168.11.2023.53.11.104
          Jan 21, 2025 23:14:46.050081968 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:46.050112963 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.050288916 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:46.050753117 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:46.050767899 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.476706982 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.477148056 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:46.477201939 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.478812933 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.479300022 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:46.479669094 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:46.533611059 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:56.480484009 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:56.480642080 CET44349786142.251.167.104192.168.11.20
          Jan 21, 2025 23:14:56.480874062 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:57.441446066 CET49786443192.168.11.20142.251.167.104
          Jan 21, 2025 23:14:57.441493988 CET44349786142.251.167.104192.168.11.20
          TimestampSource PortDest PortSource IPDest IP
          Jan 21, 2025 23:13:34.009926081 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:34.744728088 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:35.509829998 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:41.287081003 CET596421900192.168.11.20239.255.255.250
          Jan 21, 2025 23:13:41.319607019 CET53566051.1.1.1192.168.11.20
          Jan 21, 2025 23:13:41.366626024 CET53596411.1.1.1192.168.11.20
          Jan 21, 2025 23:13:42.208003998 CET53533591.1.1.1192.168.11.20
          Jan 21, 2025 23:13:42.288134098 CET596421900192.168.11.20239.255.255.250
          Jan 21, 2025 23:13:43.299276114 CET596421900192.168.11.20239.255.255.250
          Jan 21, 2025 23:13:43.780488014 CET53491851.1.1.1192.168.11.20
          Jan 21, 2025 23:13:44.314677954 CET596421900192.168.11.20239.255.255.250
          Jan 21, 2025 23:13:44.711016893 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:45.456885099 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:45.989814997 CET6189153192.168.11.201.1.1.1
          Jan 21, 2025 23:13:45.989878893 CET4962453192.168.11.201.1.1.1
          Jan 21, 2025 23:13:46.104732037 CET53618911.1.1.1192.168.11.20
          Jan 21, 2025 23:13:46.104773045 CET53496241.1.1.1192.168.11.20
          Jan 21, 2025 23:13:46.222398043 CET137137192.168.11.20192.168.11.255
          Jan 21, 2025 23:13:47.190248966 CET6229653192.168.11.201.1.1.1
          Jan 21, 2025 23:13:47.190367937 CET6405353192.168.11.201.1.1.1
          Jan 21, 2025 23:13:47.307532072 CET53622961.1.1.1192.168.11.20
          Jan 21, 2025 23:13:47.309200048 CET53640531.1.1.1192.168.11.20
          Jan 21, 2025 23:14:03.897799969 CET53577471.1.1.1192.168.11.20
          Jan 21, 2025 23:14:11.056092024 CET53563781.1.1.1192.168.11.20
          Jan 21, 2025 23:14:25.819854975 CET53529251.1.1.1192.168.11.20
          Jan 21, 2025 23:14:41.359694958 CET53531651.1.1.1192.168.11.20
          Jan 21, 2025 23:14:51.521059036 CET53628391.1.1.1192.168.11.20
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Jan 21, 2025 23:13:45.989814997 CET192.168.11.201.1.1.10x85b7Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:45.989878893 CET192.168.11.201.1.1.10xeadbStandard query (0)www.google.com65IN (0x0001)false
          Jan 21, 2025 23:13:47.190248966 CET192.168.11.201.1.1.10xa0e7Standard query (0)bs.yandex.ruA (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:47.190367937 CET192.168.11.201.1.1.10x8d38Standard query (0)bs.yandex.ru65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.104A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.99A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.147A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.103A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.105A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104732037 CET1.1.1.1192.168.11.200x85b7No error (0)www.google.com142.251.167.106A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:46.104773045 CET1.1.1.1192.168.11.200xeadbNo error (0)www.google.com65IN (0x0001)false
          Jan 21, 2025 23:13:47.307532072 CET1.1.1.1192.168.11.200xa0e7No error (0)bs.yandex.ru93.158.134.90A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:47.307532072 CET1.1.1.1192.168.11.200xa0e7No error (0)bs.yandex.ru87.250.250.90A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:47.307532072 CET1.1.1.1192.168.11.200xa0e7No error (0)bs.yandex.ru77.88.21.90A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:47.307532072 CET1.1.1.1192.168.11.200xa0e7No error (0)bs.yandex.ru213.180.204.90A (IP address)IN (0x0001)false
          Jan 21, 2025 23:13:47.307532072 CET1.1.1.1192.168.11.200xa0e7No error (0)bs.yandex.ru213.180.193.90A (IP address)IN (0x0001)false
          • bs.yandex.ru
          • https:
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.11.204977793.158.134.904437104C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-01-21 22:13:48 UTC662OUTGET / HTTP/1.1
          Host: bs.yandex.ru
          Connection: keep-alive
          sec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-01-21 22:13:48 UTC1170INHTTP/1.1 404 Not Found
          Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
          Connection: Close
          Content-Length: 29
          Content-Type: text/html; charset=windows-1251
          Date: Tue, 21 Jan 2025 22:13:48 GMT
          Expires: Tue, 21 Jan 2025 22:13:48 GMT
          Last-Modified: Tue, 21 Jan 2025 22:13:48 GMT
          Pragma: no-cache
          Set-Cookie: i=wRbpCQtWbz++RRnNVZnVXpMtGq0JvIO8MyFdQM0OW7EK1AgMpi73ovzJfOhriVRiqqXNEsKrC5wWVJpPWhHuQCGbrsU=; Expires=Thu, 21-Jan-2027 22:13:48 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly; SameSite=None
          Set-Cookie: yandexuid=4469008961737497628; Expires=Thu, 21-Jan-2027 22:13:48 GMT; Domain=.yandex.ru; Path=/; Secure; SameSite=None
          Set-Cookie: yashr=9251108951737497628; Path=/; Domain=.yandex.ru; Expires=Wed, 21 Jan 2026 22:13:48 GMT; SameSite=None; Secure; HttpOnly
          Set-Cookie: bh=EkEiQ2hyb21pdW0iO3Y9IjEyOCIsICJOb3Q7QT1CcmFuZCI7dj0iMjQiLCAiR29vZ2xlIENocm9tZSI7dj0iMTI4IioCPzA6CSJXaW5kb3dzImCcuMC8Bmoe3Mrh/wiS2KGxA5/P4eoD+/rw5w3r//32D7bGzIcI; Path=/; Domain=.yandex.ru; Expires=Wed, 25 Feb 2026 22:13:48 GMT; SameSite=None; Secure
          Strict-Transport-Security: max-age=31536000
          Timing-Allow-Origin: *
          X-XSS-Protection: 1; mode=block
          2025-01-21 22:13:48 UTC29INData Raw: 3c 21 2d 2d 20 48 61 6e 64 6c 65 72 20 69 73 20 6e 6f 74 20 66 6f 75 6e 64 20 2d 2d 3e
          Data Ascii: ... Handler is not found -->


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.11.204977893.158.134.904437104C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-01-21 22:13:48 UTC914OUTGET /favicon.ico HTTP/1.1
          Host: bs.yandex.ru
          Connection: keep-alive
          sec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://bs.yandex.ru/
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          Cookie: i=wRbpCQtWbz++RRnNVZnVXpMtGq0JvIO8MyFdQM0OW7EK1AgMpi73ovzJfOhriVRiqqXNEsKrC5wWVJpPWhHuQCGbrsU=; yandexuid=4469008961737497628; yashr=9251108951737497628; bh=EkEiQ2hyb21pdW0iO3Y9IjEyOCIsICJOb3Q7QT1CcmFuZCI7dj0iMjQiLCAiR29vZ2xlIENocm9tZSI7dj0iMTI4IioCPzA6CSJXaW5kb3dzImCcuMC8Bmoe3Mrh/wiS2KGxA5/P4eoD+/rw5w3r//32D7bGzIcI
          2025-01-21 22:13:48 UTC427INHTTP/1.1 404 Not Found
          Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
          Connection: Close
          Content-Length: 29
          Content-Type: text/html; charset=windows-1251
          Date: Tue, 21 Jan 2025 22:13:48 GMT
          Expires: Tue, 21 Jan 2025 22:13:48 GMT
          Last-Modified: Tue, 21 Jan 2025 22:13:48 GMT
          Pragma: no-cache
          Strict-Transport-Security: max-age=31536000
          Timing-Allow-Origin: *
          X-XSS-Protection: 1; mode=block
          2025-01-21 22:13:48 UTC29INData Raw: 3c 21 2d 2d 20 48 61 6e 64 6c 65 72 20 69 73 20 6e 6f 74 20 66 6f 75 6e 64 20 2d 2d 3e
          Data Ascii: ... Handler is not found -->


          020406080s020406080100

          Click to jump to process

          020406080s0.0050100MB

          Click to jump to process

          Target ID:0
          Start time:17:13:39
          Start date:21/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff794780000
          File size:2'742'376 bytes
          MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:17:13:40
          Start date:21/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2200,i,7155160346389576464,13776737258751094368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2212 /prefetch:3
          Imagebase:0x7ff794780000
          File size:2'742'376 bytes
          MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:5
          Start time:17:13:46
          Start date:21/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bs.yandex.ru"
          Imagebase:0x7ff794780000
          File size:2'742'376 bytes
          MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

          No disassembly