Edit tour

Windows Analysis Report
https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid={yandexuid}

Overview

General Information

Sample URL:https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid={yandexuid}
Analysis ID:1601567
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4624 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2020,i,10018040059736857036,4510827888525748768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7DHTTP Parser: No favicon
Source: global trafficTCP traffic: 192.168.2.4:49497 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D HTTP/1.1Host: an.yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: an.yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7DAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=WDWZZsLPZXN+vwMvmbscTeeZ8DY1tcNpeCWC81z73OmI2OmPMPP2a1oEXx+UvJSRE4nJwgg5kwJXaD59mNQmPq02thM=; yandexuid=7535826161738082737; yashr=7985338881738082737; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYLGT5LwGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: an.yandex.ru
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: private, no-cache, no-store, must-revalidate, max-age=0Connection: CloseContent-Length: 43Content-Type: image/gif; charset=utf-8Date: Tue, 28 Jan 2025 16:45:37 GMTExpires: Tue, 28 Jan 2025 16:45:37 GMTLast-Modified: Tue, 28 Jan 2025 16:45:37 GMTPragma: no-cacheSet-Cookie: i=WDWZZsLPZXN+vwMvmbscTeeZ8DY1tcNpeCWC81z73OmI2OmPMPP2a1oEXx+UvJSRE4nJwgg5kwJXaD59mNQmPq02thM=; Expires=Thu, 28-Jan-2027 16:45:37 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly; SameSite=NoneSet-Cookie: yandexuid=7535826161738082737; Expires=Thu, 28-Jan-2027 16:45:37 GMT; Domain=.yandex.ru; Path=/; Secure; SameSite=NoneSet-Cookie: yashr=7985338881738082737; Path=/; Domain=.yandex.ru; Expires=Wed, 28 Jan 2026 16:45:37 GMT; SameSite=None; Secure; HttpOnlySet-Cookie: bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYLGT5LwGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=; Path=/; Domain=.yandex.ru; Expires=Wed, 04 Mar 2026 16:45:37 GMT; SameSite=None; SecureStrict-Transport-Security: max-age=31536000Timing-Allow-Origin: *X-XSS-Protection: 1; mode=block
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: private, no-cache, no-store, must-revalidate, max-age=0Connection: CloseContent-Length: 29Content-Type: text/html; charset=windows-1251Date: Tue, 28 Jan 2025 16:45:37 GMTExpires: Tue, 28 Jan 2025 16:45:37 GMTLast-Modified: Tue, 28 Jan 2025 16:45:37 GMTPragma: no-cacheStrict-Transport-Security: max-age=31536000Timing-Allow-Origin: *X-XSS-Protection: 1; mode=block
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49590 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49590
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: clean0.win@16/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2020,i,10018040059736857036,4510827888525748768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2020,i,10018040059736857036,4510827888525748768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1601567 URL: https://an.yandex.ru/mapuid... Startdate: 28/01/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49497 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 an.yandex.ru 77.88.21.90, 443, 49740, 49741 YANDEXRU Russian Federation 10->17 19 www.google.com 142.250.185.164, 443, 49590, 49738 GOOGLEUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
an.yandex.ru
77.88.21.90
truefalse
    high
    www.google.com
    142.250.185.164
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7Dfalse
        high
        https://an.yandex.ru/favicon.icofalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.185.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          77.88.21.90
          an.yandex.ruRussian Federation
          13238YANDEXRUfalse
          IP
          192.168.2.4
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1601567
          Start date and time:2025-01-28 17:44:30 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 58s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid={yandexuid}
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/0@4/4
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.186.174, 142.251.168.84, 216.58.212.174, 142.250.185.110, 142.250.186.110, 199.232.214.172, 2.23.77.188, 216.58.206.78, 142.250.185.238, 142.250.81.238, 74.125.0.137, 142.250.186.131, 23.56.254.164, 172.202.163.200, 13.107.246.61
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, r4.sn-ab5l6nk6.gvt1.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, r4---sn-ab5l6nk6.gvt1.com, update.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: https://an.yandex.ru/mapuid/yandex?ssp-id=10500&amp;gdpr=0&amp;gdpr_consent=&amp;location=https://prebid.pixad.com.tr/setuid?bidder=yandex&amp;gdpr=0&amp;gdpr_consent=&amp;f=i&amp;uid=%7Byandexuid%7D
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 51
          • 443 (HTTPS)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Jan 28, 2025 17:45:20.302536011 CET49675443192.168.2.4173.222.162.32
          Jan 28, 2025 17:45:30.021161079 CET49675443192.168.2.4173.222.162.32
          Jan 28, 2025 17:45:34.591532946 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:34.591588974 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:34.591660023 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:34.591949940 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:34.591965914 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.249212980 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.251771927 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:35.251811028 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.252804041 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.252908945 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:35.254242897 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:35.254307032 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.301116943 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:35.301132917 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:35.348007917 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:36.096107960 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.096127987 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.096188068 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.096466064 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.096502066 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.096550941 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.097016096 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.097028017 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.097404003 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.097420931 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.808093071 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.808553934 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.808571100 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.809595108 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.809870958 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.814384937 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.814384937 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.814404964 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.814471006 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.851636887 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.852036953 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.852056980 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.855634928 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.855957985 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.856218100 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.856301069 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.867505074 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.867518902 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.898679972 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.898694038 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:36.913285017 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:36.944473982 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.163585901 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.163731098 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.164055109 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.165256023 CET49740443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.165270090 CET4434974077.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.207262993 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.247330904 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.445306063 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.445578098 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:37.445967913 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.448684931 CET49741443192.168.2.477.88.21.90
          Jan 28, 2025 17:45:37.448702097 CET4434974177.88.21.90192.168.2.4
          Jan 28, 2025 17:45:45.160830975 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:45.160921097 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:45:45.160968065 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:45.162993908 CET49738443192.168.2.4142.250.185.164
          Jan 28, 2025 17:45:45.163008928 CET44349738142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:18.247342110 CET4949753192.168.2.41.1.1.1
          Jan 28, 2025 17:46:18.252161026 CET53494971.1.1.1192.168.2.4
          Jan 28, 2025 17:46:18.252286911 CET4949753192.168.2.41.1.1.1
          Jan 28, 2025 17:46:18.252408981 CET4949753192.168.2.41.1.1.1
          Jan 28, 2025 17:46:18.257132053 CET53494971.1.1.1192.168.2.4
          Jan 28, 2025 17:46:18.704483032 CET53494971.1.1.1192.168.2.4
          Jan 28, 2025 17:46:18.705332041 CET4949753192.168.2.41.1.1.1
          Jan 28, 2025 17:46:18.711293936 CET53494971.1.1.1192.168.2.4
          Jan 28, 2025 17:46:18.711395979 CET4949753192.168.2.41.1.1.1
          Jan 28, 2025 17:46:34.646384001 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:34.646482944 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:34.646568060 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:34.646783113 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:34.646820068 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:35.280745029 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:35.281229973 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:35.281254053 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:35.281625986 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:35.282203913 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:35.282274961 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:35.332637072 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:45.196378946 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:45.196454048 CET44349590142.250.185.164192.168.2.4
          Jan 28, 2025 17:46:45.196515083 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:47.163723946 CET49590443192.168.2.4142.250.185.164
          Jan 28, 2025 17:46:47.163759947 CET44349590142.250.185.164192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Jan 28, 2025 17:45:30.513196945 CET53599001.1.1.1192.168.2.4
          Jan 28, 2025 17:45:30.514518976 CET53519021.1.1.1192.168.2.4
          Jan 28, 2025 17:45:31.516917944 CET53546511.1.1.1192.168.2.4
          Jan 28, 2025 17:45:34.583399057 CET6341853192.168.2.41.1.1.1
          Jan 28, 2025 17:45:34.583556890 CET6517253192.168.2.41.1.1.1
          Jan 28, 2025 17:45:34.590347052 CET53634181.1.1.1192.168.2.4
          Jan 28, 2025 17:45:34.590653896 CET53651721.1.1.1192.168.2.4
          Jan 28, 2025 17:45:36.086946964 CET5259053192.168.2.41.1.1.1
          Jan 28, 2025 17:45:36.087625027 CET5842553192.168.2.41.1.1.1
          Jan 28, 2025 17:45:36.093955040 CET53525901.1.1.1192.168.2.4
          Jan 28, 2025 17:45:36.094603062 CET53584251.1.1.1192.168.2.4
          Jan 28, 2025 17:45:43.950402021 CET138138192.168.2.4192.168.2.255
          Jan 28, 2025 17:45:48.481231928 CET53520501.1.1.1192.168.2.4
          Jan 28, 2025 17:46:07.185425997 CET53614661.1.1.1192.168.2.4
          Jan 28, 2025 17:46:18.246732950 CET53612501.1.1.1192.168.2.4
          Jan 28, 2025 17:46:29.940201998 CET53527131.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Jan 28, 2025 17:45:34.583399057 CET192.168.2.41.1.1.10xebd7Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:34.583556890 CET192.168.2.41.1.1.10xe7b1Standard query (0)www.google.com65IN (0x0001)false
          Jan 28, 2025 17:45:36.086946964 CET192.168.2.41.1.1.10xcf4eStandard query (0)an.yandex.ruA (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:36.087625027 CET192.168.2.41.1.1.10x8f8bStandard query (0)an.yandex.ru65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Jan 28, 2025 17:45:34.590347052 CET1.1.1.1192.168.2.40xebd7No error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:34.590653896 CET1.1.1.1192.168.2.40xe7b1No error (0)www.google.com65IN (0x0001)false
          Jan 28, 2025 17:45:36.093955040 CET1.1.1.1192.168.2.40xcf4eNo error (0)an.yandex.ru77.88.21.90A (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:36.093955040 CET1.1.1.1192.168.2.40xcf4eNo error (0)an.yandex.ru213.180.193.90A (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:36.093955040 CET1.1.1.1192.168.2.40xcf4eNo error (0)an.yandex.ru87.250.250.90A (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:36.093955040 CET1.1.1.1192.168.2.40xcf4eNo error (0)an.yandex.ru213.180.204.90A (IP address)IN (0x0001)false
          Jan 28, 2025 17:45:36.093955040 CET1.1.1.1192.168.2.40xcf4eNo error (0)an.yandex.ru93.158.134.90A (IP address)IN (0x0001)false
          • an.yandex.ru
          • https:
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44974077.88.21.904433328C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-01-28 16:45:36 UTC805OUTGET /mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D HTTP/1.1
          Host: an.yandex.ru
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2025-01-28 16:45:37 UTC1163INHTTP/1.1 404 Not Found
          Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
          Connection: Close
          Content-Length: 43
          Content-Type: image/gif; charset=utf-8
          Date: Tue, 28 Jan 2025 16:45:37 GMT
          Expires: Tue, 28 Jan 2025 16:45:37 GMT
          Last-Modified: Tue, 28 Jan 2025 16:45:37 GMT
          Pragma: no-cache
          Set-Cookie: i=WDWZZsLPZXN+vwMvmbscTeeZ8DY1tcNpeCWC81z73OmI2OmPMPP2a1oEXx+UvJSRE4nJwgg5kwJXaD59mNQmPq02thM=; Expires=Thu, 28-Jan-2027 16:45:37 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly; SameSite=None
          Set-Cookie: yandexuid=7535826161738082737; Expires=Thu, 28-Jan-2027 16:45:37 GMT; Domain=.yandex.ru; Path=/; Secure; SameSite=None
          Set-Cookie: yashr=7985338881738082737; Path=/; Domain=.yandex.ru; Expires=Wed, 28 Jan 2026 16:45:37 GMT; SameSite=None; Secure; HttpOnly
          Set-Cookie: bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYLGT5LwGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=; Path=/; Domain=.yandex.ru; Expires=Wed, 04 Mar 2026 16:45:37 GMT; SameSite=None; Secure
          Strict-Transport-Security: max-age=31536000
          Timing-Allow-Origin: *
          X-XSS-Protection: 1; mode=block
          2025-01-28 16:45:37 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
          Data Ascii: GIF89a!,D;


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44974177.88.21.904433328C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-01-28 16:45:37 UTC1057OUTGET /favicon.ico HTTP/1.1
          Host: an.yandex.ru
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          Cookie: i=WDWZZsLPZXN+vwMvmbscTeeZ8DY1tcNpeCWC81z73OmI2OmPMPP2a1oEXx+UvJSRE4nJwgg5kwJXaD59mNQmPq02thM=; yandexuid=7535826161738082737; yashr=7985338881738082737; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYLGT5LwGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
          2025-01-28 16:45:37 UTC427INHTTP/1.1 404 Not Found
          Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
          Connection: Close
          Content-Length: 29
          Content-Type: text/html; charset=windows-1251
          Date: Tue, 28 Jan 2025 16:45:37 GMT
          Expires: Tue, 28 Jan 2025 16:45:37 GMT
          Last-Modified: Tue, 28 Jan 2025 16:45:37 GMT
          Pragma: no-cache
          Strict-Transport-Security: max-age=31536000
          Timing-Allow-Origin: *
          X-XSS-Protection: 1; mode=block
          2025-01-28 16:45:37 UTC29INData Raw: 3c 21 2d 2d 20 48 61 6e 64 6c 65 72 20 69 73 20 6e 6f 74 20 66 6f 75 6e 64 20 2d 2d 3e
          Data Ascii: ... Handler is not found -->


          020406080s020406080100

          Click to jump to process

          020406080s0.0020406080100MB

          Click to jump to process

          Target ID:0
          Start time:11:45:24
          Start date:28/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:11:45:29
          Start date:28/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2020,i,10018040059736857036,4510827888525748768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:11:45:35
          Start date:28/01/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://an.yandex.ru/mapuid/yandex?ssp-id=10500&gdpr=0&gdpr_consent=&location=https://prebid.pixad.com.tr/setuid?bidder=yandex&gdpr=0&gdpr_consent=&f=i&uid=%7Byandexuid%7D"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

          No disassembly