Edit tour

Windows Analysis Report
https://urldn.com/aznY3

Overview

General Information

Sample URL:https://urldn.com/aznY3
Analysis ID:1606863
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2692 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2208,i,13408538171806119008,16757192466884648778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6500 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://urldn.com/aznY3" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://urldn.com/aznY3Avira URL Cloud: detection malicious, Label: phishing
Source: https://urldn.com/favicon.icoAvira URL Cloud: Label: phishing
Source: global trafficTCP traffic: 192.168.2.4:58365 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /aznY3 HTTP/1.1Host: urldn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: urldn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://urldn.com/aznY3Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: urldn.com
Source: sets.json.0.drString found in binary or memory: https://07c225f3.online
Source: sets.json.0.drString found in binary or memory: https://24.hu
Source: sets.json.0.drString found in binary or memory: https://aajtak.in
Source: sets.json.0.drString found in binary or memory: https://abczdrowie.pl
Source: sets.json.0.drString found in binary or memory: https://alice.tw
Source: sets.json.0.drString found in binary or memory: https://ambitionbox.com
Source: sets.json.0.drString found in binary or memory: https://autobild.de
Source: sets.json.0.drString found in binary or memory: https://baomoi.com
Source: sets.json.0.drString found in binary or memory: https://bild.de
Source: sets.json.0.drString found in binary or memory: https://blackrock.com
Source: sets.json.0.drString found in binary or memory: https://blackrockadvisorelite.it
Source: sets.json.0.drString found in binary or memory: https://bluradio.com
Source: sets.json.0.drString found in binary or memory: https://bolasport.com
Source: sets.json.0.drString found in binary or memory: https://bonvivir.com
Source: sets.json.0.drString found in binary or memory: https://bumbox.com
Source: sets.json.0.drString found in binary or memory: https://businessinsider.com.pl
Source: sets.json.0.drString found in binary or memory: https://businesstoday.in
Source: sets.json.0.drString found in binary or memory: https://cachematrix.com
Source: sets.json.0.drString found in binary or memory: https://cafemedia.com
Source: sets.json.0.drString found in binary or memory: https://caracoltv.com
Source: sets.json.0.drString found in binary or memory: https://carcostadvisor.be
Source: sets.json.0.drString found in binary or memory: https://carcostadvisor.com
Source: sets.json.0.drString found in binary or memory: https://carcostadvisor.fr
Source: sets.json.0.drString found in binary or memory: https://cardsayings.net
Source: sets.json.0.drString found in binary or memory: https://chatbot.com
Source: sets.json.0.drString found in binary or memory: https://chennien.com
Source: sets.json.0.drString found in binary or memory: https://citybibleforum.org
Source: sets.json.0.drString found in binary or memory: https://clarosports.com
Source: sets.json.0.drString found in binary or memory: https://clmbtech.com
Source: sets.json.0.drString found in binary or memory: https://closeronline.co.uk
Source: sets.json.0.drString found in binary or memory: https://clubelpais.com.uy
Source: sets.json.0.drString found in binary or memory: https://cmxd.com.mx
Source: sets.json.0.drString found in binary or memory: https://cognitive-ai.ru
Source: sets.json.0.drString found in binary or memory: https://cognitiveai.ru
Source: sets.json.0.drString found in binary or memory: https://commentcamarche.com
Source: sets.json.0.drString found in binary or memory: https://commentcamarche.net
Source: sets.json.0.drString found in binary or memory: https://computerbild.de
Source: sets.json.0.drString found in binary or memory: https://content-loader.com
Source: sets.json.0.drString found in binary or memory: https://cookreactor.com
Source: sets.json.0.drString found in binary or memory: https://cricbuzz.com
Source: sets.json.0.drString found in binary or memory: https://css-load.com
Source: sets.json.0.drString found in binary or memory: https://deccoria.pl
Source: sets.json.0.drString found in binary or memory: https://deere.com
Source: sets.json.0.drString found in binary or memory: https://desimartini.com
Source: sets.json.0.drString found in binary or memory: https://dewarmsteweek.be
Source: sets.json.0.drString found in binary or memory: https://drimer.io
Source: sets.json.0.drString found in binary or memory: https://drimer.travel
Source: sets.json.0.drString found in binary or memory: https://economictimes.com
Source: sets.json.0.drString found in binary or memory: https://een.be
Source: sets.json.0.drString found in binary or memory: https://efront.com
Source: sets.json.0.drString found in binary or memory: https://eleconomista.net
Source: sets.json.0.drString found in binary or memory: https://elfinancierocr.com
Source: sets.json.0.drString found in binary or memory: https://elgrafico.com
Source: sets.json.0.drString found in binary or memory: https://ella.sv
Source: sets.json.0.drString found in binary or memory: https://elpais.com.uy
Source: sets.json.0.drString found in binary or memory: https://elpais.uy
Source: sets.json.0.drString found in binary or memory: https://etfacademy.it
Source: sets.json.0.drString found in binary or memory: https://eworkbookcloud.com
Source: sets.json.0.drString found in binary or memory: https://eworkbookrequest.com
Source: sets.json.0.drString found in binary or memory: https://fakt.pl
Source: sets.json.0.drString found in binary or memory: https://finn.no
Source: sets.json.0.drString found in binary or memory: https://firstlook.biz
Source: sets.json.0.drString found in binary or memory: https://gallito.com.uy
Source: sets.json.0.drString found in binary or memory: https://geforcenow.com
Source: sets.json.0.drString found in binary or memory: https://gettalkdesk.com
Source: sets.json.0.drString found in binary or memory: https://gliadomain.com
Source: sets.json.0.drString found in binary or memory: https://gnttv.com
Source: sets.json.0.drString found in binary or memory: https://graziadaily.co.uk
Source: sets.json.0.drString found in binary or memory: https://grid.id
Source: sets.json.0.drString found in binary or memory: https://gridgames.app
Source: sets.json.0.drString found in binary or memory: https://growthrx.in
Source: sets.json.0.drString found in binary or memory: https://grupolpg.sv
Source: sets.json.0.drString found in binary or memory: https://gujaratijagran.com
Source: sets.json.0.drString found in binary or memory: https://hapara.com
Source: sets.json.0.drString found in binary or memory: https://hazipatika.com
Source: sets.json.0.drString found in binary or memory: https://hc1.com
Source: sets.json.0.drString found in binary or memory: https://hc1.global
Source: sets.json.0.drString found in binary or memory: https://hc1cas.com
Source: sets.json.0.drString found in binary or memory: https://hc1cas.global
Source: sets.json.0.drString found in binary or memory: https://healthshots.com
Source: sets.json.0.drString found in binary or memory: https://hearty.app
Source: sets.json.0.drString found in binary or memory: https://hearty.gift
Source: sets.json.0.drString found in binary or memory: https://hearty.me
Source: sets.json.0.drString found in binary or memory: https://heartymail.com
Source: sets.json.0.drString found in binary or memory: https://heatworld.com
Source: sets.json.0.drString found in binary or memory: https://helpdesk.com
Source: sets.json.0.drString found in binary or memory: https://hindustantimes.com
Source: sets.json.0.drString found in binary or memory: https://hj.rs
Source: sets.json.0.drString found in binary or memory: https://hjck.com
Source: sets.json.0.drString found in binary or memory: https://html-load.cc
Source: sets.json.0.drString found in binary or memory: https://html-load.com
Source: sets.json.0.drString found in binary or memory: https://human-talk.org
Source: sets.json.0.drString found in binary or memory: https://idbs-cloud.com
Source: sets.json.0.drString found in binary or memory: https://idbs-dev.com
Source: sets.json.0.drString found in binary or memory: https://idbs-eworkbook.com
Source: sets.json.0.drString found in binary or memory: https://idbs-staging.com
Source: sets.json.0.drString found in binary or memory: https://img-load.com
Source: sets.json.0.drString found in binary or memory: https://indiatimes.com
Source: sets.json.0.drString found in binary or memory: https://indiatoday.in
Source: sets.json.0.drString found in binary or memory: https://indiatodayne.in
Source: sets.json.0.drString found in binary or memory: https://infoedgeindia.com
Source: sets.json.0.drString found in binary or memory: https://interia.pl
Source: sets.json.0.drString found in binary or memory: https://intoday.in
Source: sets.json.0.drString found in binary or memory: https://iolam.it
Source: sets.json.0.drString found in binary or memory: https://ishares.com
Source: sets.json.0.drString found in binary or memory: https://jagran.com
Source: sets.json.0.drString found in binary or memory: https://johndeere.com
Source: sets.json.0.drString found in binary or memory: https://journaldesfemmes.com
Source: sets.json.0.drString found in binary or memory: https://journaldesfemmes.fr
Source: sets.json.0.drString found in binary or memory: https://journaldunet.com
Source: sets.json.0.drString found in binary or memory: https://journaldunet.fr
Source: sets.json.0.drString found in binary or memory: https://joyreactor.cc
Source: sets.json.0.drString found in binary or memory: https://joyreactor.com
Source: sets.json.0.drString found in binary or memory: https://kaksya.in
Source: sets.json.0.drString found in binary or memory: https://knowledgebase.com
Source: sets.json.0.drString found in binary or memory: https://kompas.com
Source: sets.json.0.drString found in binary or memory: https://kompas.tv
Source: sets.json.0.drString found in binary or memory: https://kompasiana.com
Source: sets.json.0.drString found in binary or memory: https://lanacion.com.ar
Source: sets.json.0.drString found in binary or memory: https://landyrev.com
Source: sets.json.0.drString found in binary or memory: https://landyrev.ru
Source: sets.json.0.drString found in binary or memory: https://laprensagrafica.com
Source: sets.json.0.drString found in binary or memory: https://lateja.cr
Source: sets.json.0.drString found in binary or memory: https://libero.it
Source: sets.json.0.drString found in binary or memory: https://linternaute.com
Source: sets.json.0.drString found in binary or memory: https://linternaute.fr
Source: sets.json.0.drString found in binary or memory: https://livechat.com
Source: sets.json.0.drString found in binary or memory: https://livechatinc.com
Source: sets.json.0.drString found in binary or memory: https://livehindustan.com
Source: sets.json.0.drString found in binary or memory: https://livemint.com
Source: sets.json.0.drString found in binary or memory: https://max.auto
Source: sets.json.0.drString found in binary or memory: https://medonet.pl
Source: sets.json.0.drString found in binary or memory: https://meo.pt
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.cl
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.co.cr
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.ar
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.bo
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.co
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.do
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.ec
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.gt
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.hn
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.mx
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.ni
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.pa
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.pe
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.py
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.sv
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.uy
Source: sets.json.0.drString found in binary or memory: https://mercadolibre.com.ve
Source: sets.json.0.drString found in binary or memory: https://mercadolivre.com
Source: sets.json.0.drString found in binary or memory: https://mercadolivre.com.br
Source: sets.json.0.drString found in binary or memory: https://mercadopago.cl
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.ar
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.br
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.co
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.ec
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.mx
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.pe
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.uy
Source: sets.json.0.drString found in binary or memory: https://mercadopago.com.ve
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.cl
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.com
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.com.ar
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.com.br
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.com.co
Source: sets.json.0.drString found in binary or memory: https://mercadoshops.com.mx
Source: sets.json.0.drString found in binary or memory: https://mighty-app.appspot.com
Source: sets.json.0.drString found in binary or memory: https://mightytext.net
Source: sets.json.0.drString found in binary or memory: https://mittanbud.no
Source: sets.json.0.drString found in binary or memory: https://money.pl
Source: sets.json.0.drString found in binary or memory: https://motherandbaby.com
Source: sets.json.0.drString found in binary or memory: https://mystudentdashboard.com
Source: sets.json.0.drString found in binary or memory: https://nacion.com
Source: sets.json.0.drString found in binary or memory: https://naukri.com
Source: sets.json.0.drString found in binary or memory: https://nidhiacademyonline.com
Source: sets.json.0.drString found in binary or memory: https://nien.co
Source: sets.json.0.drString found in binary or memory: https://nien.com
Source: sets.json.0.drString found in binary or memory: https://nien.org
Source: sets.json.0.drString found in binary or memory: https://nlc.hu
Source: sets.json.0.drString found in binary or memory: https://nosalty.hu
Source: sets.json.0.drString found in binary or memory: https://noticiascaracol.com
Source: sets.json.0.drString found in binary or memory: https://nourishingpursuits.com
Source: sets.json.0.drString found in binary or memory: https://nvidia.com
Source: sets.json.0.drString found in binary or memory: https://o2.pl
Source: sets.json.0.drString found in binary or memory: https://ocdn.eu
Source: sets.json.0.drString found in binary or memory: https://onet.pl
Source: sets.json.0.drString found in binary or memory: https://ottplay.com
Source: sets.json.0.drString found in binary or memory: https://p106.net
Source: sets.json.0.drString found in binary or memory: https://p24.hu
Source: sets.json.0.drString found in binary or memory: https://paula.com.uy
Source: sets.json.0.drString found in binary or memory: https://pdmp-apis.no
Source: sets.json.0.drString found in binary or memory: https://phonandroid.com
Source: sets.json.0.drString found in binary or memory: https://player.pl
Source: sets.json.0.drString found in binary or memory: https://plejada.pl
Source: sets.json.0.drString found in binary or memory: https://poalim.site
Source: sets.json.0.drString found in binary or memory: https://poalim.xyz
Source: sets.json.0.drString found in binary or memory: https://pomponik.pl
Source: sets.json.0.drString found in binary or memory: https://portalinmobiliario.com
Source: sets.json.0.drString found in binary or memory: https://prisjakt.no
Source: sets.json.0.drString found in binary or memory: https://pudelek.pl
Source: sets.json.0.drString found in binary or memory: https://punjabijagran.com
Source: sets.json.0.drString found in binary or memory: https://radio1.be
Source: sets.json.0.drString found in binary or memory: https://radio2.be
Source: sets.json.0.drString found in binary or memory: https://reactor.cc
Source: sets.json.0.drString found in binary or memory: https://repid.org
Source: sets.json.0.drString found in binary or memory: https://reshim.org
Source: sets.json.0.drString found in binary or memory: https://rws1nvtvt.com
Source: sets.json.0.drString found in binary or memory: https://rws2nvtvt.com
Source: sets.json.0.drString found in binary or memory: https://rws3nvtvt.com
Source: sets.json.0.drString found in binary or memory: https://sackrace.ai
Source: sets.json.0.drString found in binary or memory: https://salemoveadvisor.com
Source: sets.json.0.drString found in binary or memory: https://salemovefinancial.com
Source: sets.json.0.drString found in binary or memory: https://salemovetravel.com
Source: sets.json.0.drString found in binary or memory: https://samayam.com
Source: sets.json.0.drString found in binary or memory: https://sapo.io
Source: sets.json.0.drString found in binary or memory: https://sapo.pt
Source: sets.json.0.drString found in binary or memory: https://shock.co
Source: sets.json.0.drString found in binary or memory: https://smaker.pl
Source: sets.json.0.drString found in binary or memory: https://smoney.vn
Source: sets.json.0.drString found in binary or memory: https://smpn106jkt.sch.id
Source: sets.json.0.drString found in binary or memory: https://socket-to-me.vip
Source: sets.json.0.drString found in binary or memory: https://songshare.com
Source: sets.json.0.drString found in binary or memory: https://songstats.com
Source: sets.json.0.drString found in binary or memory: https://sporza.be
Source: sets.json.0.drString found in binary or memory: https://standardsandpraiserepurpose.com
Source: sets.json.0.drString found in binary or memory: https://startlap.hu
Source: sets.json.0.drString found in binary or memory: https://startupislandtaiwan.com
Source: sets.json.0.drString found in binary or memory: https://startupislandtaiwan.net
Source: sets.json.0.drString found in binary or memory: https://startupislandtaiwan.org
Source: sets.json.0.drString found in binary or memory: https://stripe.com
Source: sets.json.0.drString found in binary or memory: https://stripe.network
Source: sets.json.0.drString found in binary or memory: https://stripecdn.com
Source: sets.json.0.drString found in binary or memory: https://supereva.it
Source: sets.json.0.drString found in binary or memory: https://takeabreak.co.uk
Source: sets.json.0.drString found in binary or memory: https://talkdeskqaid.com
Source: sets.json.0.drString found in binary or memory: https://talkdeskstgid.com
Source: sets.json.0.drString found in binary or memory: https://teacherdashboard.com
Source: sets.json.0.drString found in binary or memory: https://technology-revealed.com
Source: sets.json.0.drString found in binary or memory: https://terazgotuje.pl
Source: sets.json.0.drString found in binary or memory: https://text.com
Source: sets.json.0.drString found in binary or memory: https://textyserver.appspot.com
Source: sets.json.0.drString found in binary or memory: https://the42.ie
Source: sets.json.0.drString found in binary or memory: https://thejournal.ie
Source: sets.json.0.drString found in binary or memory: https://thirdspace.org.au
Source: sets.json.0.drString found in binary or memory: https://timesinternet.in
Source: sets.json.0.drString found in binary or memory: https://timesofindia.com
Source: sets.json.0.drString found in binary or memory: https://tolteck.app
Source: sets.json.0.drString found in binary or memory: https://tolteck.com
Source: sets.json.0.drString found in binary or memory: https://top.pl
Source: sets.json.0.drString found in binary or memory: https://tribunnews.com
Source: sets.json.0.drString found in binary or memory: https://trytalkdesk.com
Source: sets.json.0.drString found in binary or memory: https://tucarro.com
Source: sets.json.0.drString found in binary or memory: https://tucarro.com.co
Source: sets.json.0.drString found in binary or memory: https://tucarro.com.ve
Source: sets.json.0.drString found in binary or memory: https://tvid.in
Source: sets.json.0.drString found in binary or memory: https://tvn.pl
Source: sets.json.0.drString found in binary or memory: https://tvn24.pl
Source: sets.json.0.drString found in binary or memory: https://unotv.com
Source: sets.json.0.drString found in binary or memory: https://victorymedium.com
Source: sets.json.0.drString found in binary or memory: https://vrt.be
Source: sets.json.0.drString found in binary or memory: https://vwo.com
Source: sets.json.0.drString found in binary or memory: https://welt.de
Source: sets.json.0.drString found in binary or memory: https://wieistmeineip.de
Source: sets.json.0.drString found in binary or memory: https://wildix.com
Source: sets.json.0.drString found in binary or memory: https://wildixin.com
Source: sets.json.0.drString found in binary or memory: https://wingify.com
Source: sets.json.0.drString found in binary or memory: https://wordle.at
Source: sets.json.0.drString found in binary or memory: https://wp.pl
Source: sets.json.0.drString found in binary or memory: https://wpext.pl
Source: sets.json.0.drString found in binary or memory: https://www.asadcdn.com
Source: sets.json.0.drString found in binary or memory: https://ya.ru
Source: sets.json.0.drString found in binary or memory: https://yours.co.uk
Source: sets.json.0.drString found in binary or memory: https://zalo.me
Source: sets.json.0.drString found in binary or memory: https://zdrowietvn.pl
Source: sets.json.0.drString found in binary or memory: https://zingmp3.vn
Source: sets.json.0.drString found in binary or memory: https://zoom.com
Source: sets.json.0.drString found in binary or memory: https://zoom.us
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 58381 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58381
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\sets.jsonJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\manifest.jsonJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\LICENSEJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\_metadata\Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\_metadata\verified_contents.jsonJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3332_586243589\manifest.fingerprintJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\chrome_BITS_3332_1712071416Jump to behavior
Source: classification engineClassification label: mal56.win@17/9@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2208,i,13408538171806119008,16757192466884648778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://urldn.com/aznY3"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2208,i,13408538171806119008,16757192466884648778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1606863 URL: https://urldn.com/aznY3 Startdate: 04/02/2025 Architecture: WINDOWS Score: 56 22 Antivirus detection for URL or domain 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 6 chrome.exe 8 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49490 unknown unknown 6->14 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 216.58.206.68, 443, 49739, 58381 GOOGLEUS United States 11->18 20 urldn.com 104.21.32.1, 443, 49742, 49743 CLOUDFLARENETUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://urldn.com/aznY3100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://urldn.com/favicon.ico100%Avira URL Cloudphishing

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
216.58.206.68
truefalse
    high
    urldn.com
    104.21.32.1
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://urldn.com/favicon.icofalse
      • Avira URL Cloud: phishing
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      https://wieistmeineip.desets.json.0.drfalse
        high
        https://mercadoshops.com.cosets.json.0.drfalse
          high
          https://gliadomain.comsets.json.0.drfalse
            high
            https://poalim.xyzsets.json.0.drfalse
              high
              https://mercadolivre.comsets.json.0.drfalse
                high
                https://reshim.orgsets.json.0.drfalse
                  high
                  https://nourishingpursuits.comsets.json.0.drfalse
                    high
                    https://medonet.plsets.json.0.drfalse
                      high
                      https://unotv.comsets.json.0.drfalse
                        high
                        https://mercadoshops.com.brsets.json.0.drfalse
                          high
                          https://joyreactor.ccsets.json.0.drfalse
                            high
                            https://zdrowietvn.plsets.json.0.drfalse
                              high
                              https://johndeere.comsets.json.0.drfalse
                                high
                                https://songstats.comsets.json.0.drfalse
                                  high
                                  https://baomoi.comsets.json.0.drfalse
                                    high
                                    https://supereva.itsets.json.0.drfalse
                                      high
                                      https://elfinancierocr.comsets.json.0.drfalse
                                        high
                                        https://bolasport.comsets.json.0.drfalse
                                          high
                                          https://rws1nvtvt.comsets.json.0.drfalse
                                            high
                                            https://desimartini.comsets.json.0.drfalse
                                              high
                                              https://hearty.appsets.json.0.drfalse
                                                high
                                                https://hearty.giftsets.json.0.drfalse
                                                  high
                                                  https://mercadoshops.comsets.json.0.drfalse
                                                    high
                                                    https://heartymail.comsets.json.0.drfalse
                                                      high
                                                      https://nlc.husets.json.0.drfalse
                                                        high
                                                        https://p106.netsets.json.0.drfalse
                                                          high
                                                          https://radio2.besets.json.0.drfalse
                                                            high
                                                            https://finn.nosets.json.0.drfalse
                                                              high
                                                              https://hc1.comsets.json.0.drfalse
                                                                high
                                                                https://kompas.tvsets.json.0.drfalse
                                                                  high
                                                                  https://mystudentdashboard.comsets.json.0.drfalse
                                                                    high
                                                                    https://songshare.comsets.json.0.drfalse
                                                                      high
                                                                      https://smaker.plsets.json.0.drfalse
                                                                        high
                                                                        https://mercadopago.com.mxsets.json.0.drfalse
                                                                          high
                                                                          https://p24.husets.json.0.drfalse
                                                                            high
                                                                            https://talkdeskqaid.comsets.json.0.drfalse
                                                                              high
                                                                              https://24.husets.json.0.drfalse
                                                                                high
                                                                                https://mercadopago.com.pesets.json.0.drfalse
                                                                                  high
                                                                                  https://cardsayings.netsets.json.0.drfalse
                                                                                    high
                                                                                    https://text.comsets.json.0.drfalse
                                                                                      high
                                                                                      https://mightytext.netsets.json.0.drfalse
                                                                                        high
                                                                                        https://pudelek.plsets.json.0.drfalse
                                                                                          high
                                                                                          https://hazipatika.comsets.json.0.drfalse
                                                                                            high
                                                                                            https://joyreactor.comsets.json.0.drfalse
                                                                                              high
                                                                                              https://cookreactor.comsets.json.0.drfalse
                                                                                                high
                                                                                                https://wildixin.comsets.json.0.drfalse
                                                                                                  high
                                                                                                  https://eworkbookcloud.comsets.json.0.drfalse
                                                                                                    high
                                                                                                    https://cognitiveai.rusets.json.0.drfalse
                                                                                                      high
                                                                                                      https://nacion.comsets.json.0.drfalse
                                                                                                        high
                                                                                                        https://chennien.comsets.json.0.drfalse
                                                                                                          high
                                                                                                          https://drimer.travelsets.json.0.drfalse
                                                                                                            high
                                                                                                            https://deccoria.plsets.json.0.drfalse
                                                                                                              high
                                                                                                              https://mercadopago.clsets.json.0.drfalse
                                                                                                                high
                                                                                                                https://talkdeskstgid.comsets.json.0.drfalse
                                                                                                                  high
                                                                                                                  https://naukri.comsets.json.0.drfalse
                                                                                                                    high
                                                                                                                    https://interia.plsets.json.0.drfalse
                                                                                                                      high
                                                                                                                      https://bonvivir.comsets.json.0.drfalse
                                                                                                                        high
                                                                                                                        https://carcostadvisor.besets.json.0.drfalse
                                                                                                                          high
                                                                                                                          https://salemovetravel.comsets.json.0.drfalse
                                                                                                                            high
                                                                                                                            https://sapo.iosets.json.0.drfalse
                                                                                                                              high
                                                                                                                              https://wpext.plsets.json.0.drfalse
                                                                                                                                high
                                                                                                                                https://welt.desets.json.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://poalim.sitesets.json.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://drimer.iosets.json.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://infoedgeindia.comsets.json.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://blackrockadvisorelite.itsets.json.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://cognitive-ai.rusets.json.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://cafemedia.comsets.json.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://graziadaily.co.uksets.json.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://thirdspace.org.ausets.json.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://mercadoshops.com.arsets.json.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://smpn106jkt.sch.idsets.json.0.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://elpais.uysets.json.0.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://landyrev.comsets.json.0.drfalse
                                                                                                                                                          high
                                                                                                                                                          https://the42.iesets.json.0.drfalse
                                                                                                                                                            high
                                                                                                                                                            https://commentcamarche.comsets.json.0.drfalse
                                                                                                                                                              high
                                                                                                                                                              https://tucarro.com.vesets.json.0.drfalse
                                                                                                                                                                high
                                                                                                                                                                https://rws3nvtvt.comsets.json.0.drfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://eleconomista.netsets.json.0.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://helpdesk.comsets.json.0.drfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://mercadolivre.com.brsets.json.0.drfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://clmbtech.comsets.json.0.drfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://standardsandpraiserepurpose.comsets.json.0.drfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://07c225f3.onlinesets.json.0.drfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://salemovefinancial.comsets.json.0.drfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://mercadopago.com.brsets.json.0.drfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://zoom.ussets.json.0.drfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://commentcamarche.netsets.json.0.drfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://etfacademy.itsets.json.0.drfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://mighty-app.appspot.comsets.json.0.drfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          https://hj.rssets.json.0.drfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://hearty.mesets.json.0.drfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              https://mercadolibre.com.gtsets.json.0.drfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://timesinternet.insets.json.0.drfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://indiatodayne.insets.json.0.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://idbs-staging.comsets.json.0.drfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://blackrock.comsets.json.0.drfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        https://idbs-eworkbook.comsets.json.0.drfalse
                                                                                                                                                                                                          high
                                                                                                                                                                                                          https://motherandbaby.comsets.json.0.drfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            • No. of IPs < 25%
                                                                                                                                                                                                            • 25% < No. of IPs < 50%
                                                                                                                                                                                                            • 50% < No. of IPs < 75%
                                                                                                                                                                                                            • 75% < No. of IPs
                                                                                                                                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                            239.255.255.250
                                                                                                                                                                                                            unknownReserved
                                                                                                                                                                                                            unknownunknownfalse
                                                                                                                                                                                                            104.21.32.1
                                                                                                                                                                                                            urldn.comUnited States
                                                                                                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                            216.58.206.68
                                                                                                                                                                                                            www.google.comUnited States
                                                                                                                                                                                                            15169GOOGLEUSfalse
                                                                                                                                                                                                            IP
                                                                                                                                                                                                            192.168.2.4
                                                                                                                                                                                                            Joe Sandbox version:42.0.0 Malachite
                                                                                                                                                                                                            Analysis ID:1606863
                                                                                                                                                                                                            Start date and time:2025-02-04 22:37:03 +01:00
                                                                                                                                                                                                            Joe Sandbox product:CloudBasic
                                                                                                                                                                                                            Overall analysis duration:0h 2m 57s
                                                                                                                                                                                                            Hypervisor based Inspection enabled:false
                                                                                                                                                                                                            Report type:full
                                                                                                                                                                                                            Cookbook file name:browseurl.jbs
                                                                                                                                                                                                            Sample URL:https://urldn.com/aznY3
                                                                                                                                                                                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                            Number of analysed new started processes analysed:8
                                                                                                                                                                                                            Number of new started drivers analysed:0
                                                                                                                                                                                                            Number of existing processes analysed:0
                                                                                                                                                                                                            Number of existing drivers analysed:0
                                                                                                                                                                                                            Number of injected processes analysed:0
                                                                                                                                                                                                            Technologies:
                                                                                                                                                                                                            • EGA enabled
                                                                                                                                                                                                            • AMSI enabled
                                                                                                                                                                                                            Analysis Mode:default
                                                                                                                                                                                                            Analysis stop reason:Timeout
                                                                                                                                                                                                            Detection:MAL
                                                                                                                                                                                                            Classification:mal56.win@17/9@4/4
                                                                                                                                                                                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                                                                                                                                            • Excluded IPs from analysis (whitelisted): 142.250.185.174, 142.250.184.227, 74.125.206.84, 142.250.74.206, 142.250.184.206, 199.232.214.172, 2.17.190.73, 142.250.181.238, 142.250.185.142, 216.58.206.78, 142.250.185.78, 172.217.16.195, 142.250.186.174, 34.104.35.123, 184.28.90.27, 4.175.87.197, 13.107.246.45
                                                                                                                                                                                                            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                                                                                                                                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                            • VT rate limit hit for: https://urldn.com/aznY3
                                                                                                                                                                                                            No simulations
                                                                                                                                                                                                            No context
                                                                                                                                                                                                            No context
                                                                                                                                                                                                            No context
                                                                                                                                                                                                            No context
                                                                                                                                                                                                            No context
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1558
                                                                                                                                                                                                            Entropy (8bit):5.11458514637545
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH
                                                                                                                                                                                                            MD5:EE002CB9E51BB8DFA89640A406A1090A
                                                                                                                                                                                                            SHA1:49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2
                                                                                                                                                                                                            SHA-256:3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B
                                                                                                                                                                                                            SHA-512:D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:// Copyright 2015 The Chromium Authors. All rights reserved..//.// Redistribution and use in source and binary forms, with or without.// modification, are permitted provided that the following conditions are.// met:.//.// * Redistributions of source code must retain the above copyright.// notice, this list of conditions and the following disclaimer..// * Redistributions in binary form must reproduce the above.// copyright notice, this list of conditions and the following disclaimer.// in the documentation and/or other materials provided with the.// distribution..// * Neither the name of Google Inc. nor the names of its.// contributors may be used to endorse or promote products derived from.// this software without specific prior written permission..//.// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS.// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.// A PARTICULAR
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1864
                                                                                                                                                                                                            Entropy (8bit):6.018989605004616
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:p/hUI1OwEU3AdIq7ak68O40E2szOxxUJ8BPFkf31U4PrHfqY3J5D:RnOwtQIq7aZ40E2sYUJAYRr/qYZ5D
                                                                                                                                                                                                            MD5:C4709C1D483C9233A3A66A7E157624EA
                                                                                                                                                                                                            SHA1:99A000EB5FE5CC1E94E3155EE075CD6E43DC7582
                                                                                                                                                                                                            SHA-256:225243DC75352D63B0B9B2F48C8AAA09D55F3FB9E385741B12A1956A941880D9
                                                                                                                                                                                                            SHA-512:B45E1FD999D1340CC5EB5A49A4CD967DC736EA3F4EC8B02227577CC3D1E903341BE3217FBB0B74765C72085AC51C63EEF6DCB169D137BBAF3CC49E21EA6468D7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiJMSUNFTlNFIiwicm9vdF9oYXNoIjoiUGIwc2tBVUxaUzFqWldTQnctV0hIRkltRlhVcExiZDlUcVkwR2ZHSHBWcyJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJVczFpOUt3Zm5uMThTVVR1RVItRXBDTTMwVzFkNTc0cGJwUlJSdGJYM0JVIn0seyJwYXRoIjoic2V0cy5qc29uIiwicm9vdF9oYXNoIjoiM0hiWThLc3poeEF6UDVSUU9fZEpvZGNwbEtpRXR0RWh2UmZMZEtjSTdjZyJ9XSwiZm9ybWF0IjoidHJlZWhhc2giLCJoYXNoX2Jsb2NrX3NpemUiOjQwOTZ9XSwiaXRlbV9pZCI6ImdvbnBlbWRna2pjZWNkZ2JuYWFiaXBwcGJtZ2ZnZ2JlIiwiaXRlbV92ZXJzaW9uIjoiMjAyNC4xMS44LjAiLCJwcm90b2NvbF92ZXJzaW9uIjoxfQ","signatures":[{"header":{"kid":"publisher"},"protected":"eyJhbGciOiJSUzI1NiJ9","signature":"lGxZ1-AH7F8MftKSBdZiFULmC8hZkIHy1_2XIoU81Z5mK0wHVwNV7-55CBTcuuvKjTje-AnKLDoG4S0A_Jeg4lSQK5V_Q4f6JVqp5Vj_ge86YkRZEv4m1bjKRY4N17SHobwuH8Hc_kAugFIlG1LIDHnrm1N7ZWIqo3fVlnVqgSstmvFXAhBazgs1UYRi3hPjPM6e1q1i2N1mIUbxLvG41frGo2QJ8W5J3buUjzs-0y250k-YkadKAR0
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):66
                                                                                                                                                                                                            Entropy (8bit):3.820000180714897
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SVzHL3phUmWRDNKydvgHVz:SBHLLUmWRbCp
                                                                                                                                                                                                            MD5:BBEC7670A2519FEB0627F17D0C0B5276
                                                                                                                                                                                                            SHA1:9C30B996F1B069F86EF7C0136DFAF7E614674DEA
                                                                                                                                                                                                            SHA-256:670A6F6BBADAB2C2BE63898525FCAF72E7454739E77C04D120BC1A46B6694CAC
                                                                                                                                                                                                            SHA-512:1ED4ED6AE2A2CBE86F9E8C6C7A2672EBB2F37DBE83D2BF09D875DB435ED63BF5F5CF60CA846865166F9A498095F6D61BD51B0A092E097430439E8A5A3A14CB15
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:1.03cccbb22b17080279ea1707c9ab093c59f4f4dd09580c841cfa794cb372228d
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):85
                                                                                                                                                                                                            Entropy (8bit):4.462192586591686
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:rR6TAulhFphifFCmMARWHJqS1kULJVPY:F6VlM8aRWpqS1kSJVg
                                                                                                                                                                                                            MD5:084E339C0C9FE898102815EAC9A7CDEA
                                                                                                                                                                                                            SHA1:6ABF7EAAA407D2EAB8706361E5A2E5F776D6C644
                                                                                                                                                                                                            SHA-256:52CD62F4AC1F9E7D7C4944EE111F84A42337D16D5DE7BE296E945146D6D7DC15
                                                                                                                                                                                                            SHA-512:0B67A89F3EBFF6FEC3796F481EC2AFBAC233CF64FDC618EC6BA1C12AE125F28B27EE09E8CD0FADB8F6C8785C83929EA6F751E0DDF592DD072AB2CF439BD28534
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:{. "manifest_version": 2,. "name": "First Party Sets",. "version": "2024.11.8.0".}
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9817
                                                                                                                                                                                                            Entropy (8bit):4.629347296880043
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Mon4mvC4qX19s1blbw/BNKLcxbdmf56MFJtRTGXvcxN43uP+8qJl:v5C4ql7BkIVmtRTGXvcxBsl
                                                                                                                                                                                                            MD5:8C702C686B703020BC0290BAFC90D7A0
                                                                                                                                                                                                            SHA1:EB08FF7885B4C1DE3EF3D61E40697C0C71903E27
                                                                                                                                                                                                            SHA-256:97D9E39021512305820F27B9662F0351E45639124F5BD29F0466E9072A9D0C62
                                                                                                                                                                                                            SHA-512:6137D0ED10E6A27924ED3AB6A0C5F9B21EB0E16A876447DADABD88338198F31BB9D89EF8F0630F4573EA34A24FB3FD3365D7EA78A97BA10028A0758E0A550739
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:{"primary":"https://bild.de","associatedSites":["https://welt.de","https://autobild.de","https://computerbild.de","https://wieistmeineip.de"],"serviceSites":["https://www.asadcdn.com"]}.{"primary":"https://blackrock.com","associatedSites":["https://blackrockadvisorelite.it","https://cachematrix.com","https://efront.com","https://etfacademy.it","https://ishares.com"]}.{"primary":"https://cafemedia.com","associatedSites":["https://cardsayings.net","https://nourishingpursuits.com"]}.{"primary":"https://caracoltv.com","associatedSites":["https://noticiascaracol.com","https://bluradio.com","https://shock.co","https://bumbox.com","https://hjck.com"]}.{"primary":"https://carcostadvisor.com","ccTLDs":{"https://carcostadvisor.com":["https://carcostadvisor.be","https://carcostadvisor.fr"]}}.{"primary":"https://citybibleforum.org","associatedSites":["https://thirdspace.org.au"]}.{"primary":"https://cognitiveai.ru","associatedSites":["https://cognitive-ai.ru"]}.{"primary":"https://drimer.io","asso
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                                                                                                            Category:downloaded
                                                                                                                                                                                                            Size (bytes):55
                                                                                                                                                                                                            Entropy (8bit):4.135841650542515
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:xiQ5RAadWFUfAiCjKRyL:x55RAaUFsAiCj
                                                                                                                                                                                                            MD5:1E8462F8FDE83981E63BA47FCFA189E7
                                                                                                                                                                                                            SHA1:197CC97D0101A4205BD174E9A39C8B29BD4A83ED
                                                                                                                                                                                                            SHA-256:68A87CC8E59C005917A5A9A00F24197F808E1A8C01FA3B45EB67A8D34C634727
                                                                                                                                                                                                            SHA-512:1CF399196A6F3C1A16F569CAD6AB1D307C782110F75EAE0446A362AE2D1A7B231AD25F14DE2006505A05A9B903D619C83894A5ADC4154A6281BF1AEF8E34B01F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            URL:https://urldn.com/favicon.ico
                                                                                                                                                                                                            Preview:Too many requests from this IP, please try again later.
                                                                                                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                                                                                                            Category:downloaded
                                                                                                                                                                                                            Size (bytes):55
                                                                                                                                                                                                            Entropy (8bit):4.135841650542515
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:xiQ5RAadWFUfAiCjKRyL:x55RAaUFsAiCj
                                                                                                                                                                                                            MD5:1E8462F8FDE83981E63BA47FCFA189E7
                                                                                                                                                                                                            SHA1:197CC97D0101A4205BD174E9A39C8B29BD4A83ED
                                                                                                                                                                                                            SHA-256:68A87CC8E59C005917A5A9A00F24197F808E1A8C01FA3B45EB67A8D34C634727
                                                                                                                                                                                                            SHA-512:1CF399196A6F3C1A16F569CAD6AB1D307C782110F75EAE0446A362AE2D1A7B231AD25F14DE2006505A05A9B903D619C83894A5ADC4154A6281BF1AEF8E34B01F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            URL:https://urldn.com/aznY3
                                                                                                                                                                                                            Preview:Too many requests from this IP, please try again later.
                                                                                                                                                                                                            No static file info

                                                                                                                                                                                                            Download Network PCAP: filteredfull

                                                                                                                                                                                                            • Total Packets: 52
                                                                                                                                                                                                            • 443 (HTTPS)
                                                                                                                                                                                                            • 80 (HTTP)
                                                                                                                                                                                                            • 53 (DNS)
                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                            Feb 4, 2025 22:38:05.471811056 CET49675443192.168.2.4173.222.162.32
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.855066061 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.855103016 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.855160952 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.855530024 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.855544090 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.514728069 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.515037060 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.515059948 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.516026020 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.516083002 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.517469883 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.517529964 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.564610958 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.564620972 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:10.611469984 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.012411118 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.012454987 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.012522936 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.013066053 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.013156891 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.013212919 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.013585091 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.013598919 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.014051914 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.014067888 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.502588034 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.502824068 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.502851009 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.504153013 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.504231930 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.505331993 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.512212992 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.512242079 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.513227940 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.513282061 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.514431000 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.514492035 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.514750957 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.514859915 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.515033960 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.515043020 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.566859961 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.566860914 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.566874981 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.615756989 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.896486998 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.896610022 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.896760941 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.897775888 CET49743443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.897792101 CET44349743104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.950525045 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.995331049 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:13.316514015 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:13.316654921 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:13.316715002 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:13.318000078 CET49742443192.168.2.4104.21.32.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:13.318017006 CET44349742104.21.32.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:20.420196056 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:20.420304060 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:20.420357943 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:20.459140062 CET49739443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:38:20.459163904 CET44349739216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:21.263480902 CET4972380192.168.2.4199.232.210.172
                                                                                                                                                                                                            Feb 4, 2025 22:38:21.268521070 CET8049723199.232.210.172192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:21.268590927 CET4972380192.168.2.4199.232.210.172
                                                                                                                                                                                                            Feb 4, 2025 22:39:05.049124956 CET4972480192.168.2.4199.232.210.172
                                                                                                                                                                                                            Feb 4, 2025 22:39:05.054157019 CET8049724199.232.210.172192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:05.054306030 CET4972480192.168.2.4199.232.210.172
                                                                                                                                                                                                            Feb 4, 2025 22:39:07.588038921 CET5836553192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:39:07.593801975 CET53583651.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:07.593878031 CET5836553192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:39:07.599615097 CET53583651.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:08.076009035 CET5836553192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:39:08.084140062 CET53583651.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:08.084208965 CET5836553192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:39:09.909742117 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:09.909768105 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:09.909852028 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:09.910094976 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:09.910104990 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.558778048 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.559066057 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.559082985 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.559398890 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.559720039 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.559792995 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:10.610605955 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:20.496150017 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:20.496202946 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:20.496345997 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:22.456800938 CET58381443192.168.2.4216.58.206.68
                                                                                                                                                                                                            Feb 4, 2025 22:39:22.456814051 CET44358381216.58.206.68192.168.2.4
                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                            Feb 4, 2025 22:38:05.916682959 CET53594301.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:05.956796885 CET53608501.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:06.957396030 CET53566011.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.846995115 CET5141553192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.847116947 CET5328153192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.853840113 CET53532811.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.853929996 CET53514151.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.966757059 CET5080853192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.966919899 CET4949053192.168.2.41.1.1.1
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET53508081.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.138895988 CET53494901.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:16.618093014 CET138138192.168.2.4192.168.2.255
                                                                                                                                                                                                            Feb 4, 2025 22:38:23.916475058 CET53542311.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:38:42.869111061 CET53510281.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:05.450691938 CET53606081.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:05.747632980 CET53619011.1.1.1192.168.2.4
                                                                                                                                                                                                            Feb 4, 2025 22:39:07.587645054 CET53612741.1.1.1192.168.2.4
                                                                                                                                                                                                            TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.138976097 CET192.168.2.41.1.1.1c2d7(Port unreachable)Destination Unreachable
                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.846995115 CET192.168.2.41.1.1.10xeab0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.847116947 CET192.168.2.41.1.1.10x35eeStandard query (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.966757059 CET192.168.2.41.1.1.10x34feStandard query (0)urldn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.966919899 CET192.168.2.41.1.1.10x46c3Standard query (0)urldn.com65IN (0x0001)false
                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.853840113 CET1.1.1.1192.168.2.40x35eeNo error (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:09.853929996 CET1.1.1.1192.168.2.40xeab0No error (0)www.google.com216.58.206.68A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.32.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.64.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.16.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.80.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.48.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.96.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:11.976572990 CET1.1.1.1192.168.2.40x34feNo error (0)urldn.com104.21.112.1A (IP address)IN (0x0001)false
                                                                                                                                                                                                            Feb 4, 2025 22:38:12.138895988 CET1.1.1.1192.168.2.40x46c3No error (0)urldn.com65IN (0x0001)false
                                                                                                                                                                                                            • urldn.com
                                                                                                                                                                                                            • https:
                                                                                                                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                            0192.168.2.449743104.21.32.14432692C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            TimestampBytes transferredDirectionData
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC657OUTGET /aznY3 HTTP/1.1
                                                                                                                                                                                                            Host: urldn.com
                                                                                                                                                                                                            Connection: keep-alive
                                                                                                                                                                                                            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                            sec-ch-ua-mobile: ?0
                                                                                                                                                                                                            sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                            Upgrade-Insecure-Requests: 1
                                                                                                                                                                                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                                                                                                            Sec-Fetch-Site: none
                                                                                                                                                                                                            Sec-Fetch-Mode: navigate
                                                                                                                                                                                                            Sec-Fetch-User: ?1
                                                                                                                                                                                                            Sec-Fetch-Dest: document
                                                                                                                                                                                                            Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                            Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC1366INHTTP/1.1 429 Too Many Requests
                                                                                                                                                                                                            Date: Tue, 04 Feb 2025 21:38:12 GMT
                                                                                                                                                                                                            Content-Type: text/html; charset=utf-8
                                                                                                                                                                                                            Transfer-Encoding: chunked
                                                                                                                                                                                                            Connection: close
                                                                                                                                                                                                            CF-Ray: 90cdce6c9d9d4344-EWR
                                                                                                                                                                                                            CF-Cache-Status: DYNAMIC
                                                                                                                                                                                                            Retry-After: 86
                                                                                                                                                                                                            ETag: W/"37-GXzJfQEBpCBb0XTpo5yLKb1Kg+0"
                                                                                                                                                                                                            Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                                                                                                            Vary: Accept-Encoding
                                                                                                                                                                                                            content-security-policy: default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google.com https://cdn.jsdelivr.net https://code.jquery.com https://challenges.cloudflare.com https://cdn.emailjs.com https://cdn.tailwindcss.com;connect-src 'self' https://www.googletagmanager.com https://challenges.cloudflare.com https://cdn.emailjs.com https://api.emailjs.com;frame-src 'self' https://www.googletagmanager.com https://challenges.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com;img-src 'self' https://res.cloudinary.com https://cdn.buymeacoffee.com https://flagcdn.com https://www.google-analytics.com data:;media-src 'self';child-src 'self' https://www.youtube.com;base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
                                                                                                                                                                                                            rndr-id: 1f1b9e8f-2744-474a
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC188INData Raw: 78 2d 70 6f 77 65 72 65 64 2d 62 79 3a 20 45 78 70 72 65 73 73 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 6c 69 6d 69 74 3a 20 32 30 30 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 72 65 6d 61 69 6e 69 6e 67 3a 20 30 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 72 65 73 65 74 3a 20 31 37 33 38 37 30 35 31 37 38 0d 0a 78 2d 72 65 6e 64 65 72 2d 6f 72 69 67 69 6e 2d 73 65 72 76 65 72 3a 20 52 65 6e 64 65 72 0d 0a 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                                                                                                            Data Ascii: x-powered-by: Expressx-ratelimit-limit: 200x-ratelimit-remaining: 0x-ratelimit-reset: 1738705178x-render-origin-server: RenderServer: cloudflarealt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC61INData Raw: 33 37 0d 0a 54 6f 6f 20 6d 61 6e 79 20 72 65 71 75 65 73 74 73 20 66 72 6f 6d 20 74 68 69 73 20 49 50 2c 20 70 6c 65 61 73 65 20 74 72 79 20 61 67 61 69 6e 20 6c 61 74 65 72 2e 0d 0a
                                                                                                                                                                                                            Data Ascii: 37Too many requests from this IP, please try again later.
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                            Data Ascii: 0


                                                                                                                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                            1192.168.2.449742104.21.32.14432692C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            TimestampBytes transferredDirectionData
                                                                                                                                                                                                            2025-02-04 21:38:12 UTC579OUTGET /favicon.ico HTTP/1.1
                                                                                                                                                                                                            Host: urldn.com
                                                                                                                                                                                                            Connection: keep-alive
                                                                                                                                                                                                            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                            sec-ch-ua-mobile: ?0
                                                                                                                                                                                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                            sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                            Sec-Fetch-Site: same-origin
                                                                                                                                                                                                            Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                            Sec-Fetch-Dest: image
                                                                                                                                                                                                            Referer: https://urldn.com/aznY3
                                                                                                                                                                                                            Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                            Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                            2025-02-04 21:38:13 UTC1366INHTTP/1.1 429 Too Many Requests
                                                                                                                                                                                                            Date: Tue, 04 Feb 2025 21:38:13 GMT
                                                                                                                                                                                                            Content-Type: text/html; charset=utf-8
                                                                                                                                                                                                            Transfer-Encoding: chunked
                                                                                                                                                                                                            Connection: close
                                                                                                                                                                                                            CF-Ray: 90cdce6f49ec72b9-EWR
                                                                                                                                                                                                            CF-Cache-Status: DYNAMIC
                                                                                                                                                                                                            Retry-After: 85
                                                                                                                                                                                                            ETag: W/"37-GXzJfQEBpCBb0XTpo5yLKb1Kg+0"
                                                                                                                                                                                                            Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                                                                                                            Vary: Accept-Encoding
                                                                                                                                                                                                            content-security-policy: default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google.com https://cdn.jsdelivr.net https://code.jquery.com https://challenges.cloudflare.com https://cdn.emailjs.com https://cdn.tailwindcss.com;connect-src 'self' https://www.googletagmanager.com https://challenges.cloudflare.com https://cdn.emailjs.com https://api.emailjs.com;frame-src 'self' https://www.googletagmanager.com https://challenges.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com;img-src 'self' https://res.cloudinary.com https://cdn.buymeacoffee.com https://flagcdn.com https://www.google-analytics.com data:;media-src 'self';child-src 'self' https://www.youtube.com;base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
                                                                                                                                                                                                            rndr-id: 1884d75f-0701-47c6
                                                                                                                                                                                                            2025-02-04 21:38:13 UTC188INData Raw: 78 2d 70 6f 77 65 72 65 64 2d 62 79 3a 20 45 78 70 72 65 73 73 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 6c 69 6d 69 74 3a 20 32 30 30 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 72 65 6d 61 69 6e 69 6e 67 3a 20 30 0d 0a 78 2d 72 61 74 65 6c 69 6d 69 74 2d 72 65 73 65 74 3a 20 31 37 33 38 37 30 35 31 37 38 0d 0a 78 2d 72 65 6e 64 65 72 2d 6f 72 69 67 69 6e 2d 73 65 72 76 65 72 3a 20 52 65 6e 64 65 72 0d 0a 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                                                                                                            Data Ascii: x-powered-by: Expressx-ratelimit-limit: 200x-ratelimit-remaining: 0x-ratelimit-reset: 1738705178x-render-origin-server: RenderServer: cloudflarealt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                            2025-02-04 21:38:13 UTC61INData Raw: 33 37 0d 0a 54 6f 6f 20 6d 61 6e 79 20 72 65 71 75 65 73 74 73 20 66 72 6f 6d 20 74 68 69 73 20 49 50 2c 20 70 6c 65 61 73 65 20 74 72 79 20 61 67 61 69 6e 20 6c 61 74 65 72 2e 0d 0a
                                                                                                                                                                                                            Data Ascii: 37Too many requests from this IP, please try again later.
                                                                                                                                                                                                            2025-02-04 21:38:13 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                            Data Ascii: 0


                                                                                                                                                                                                            020406080s020406080100

                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                            020406080s0.0020406080100MB

                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                            Target ID:0
                                                                                                                                                                                                            Start time:16:38:02
                                                                                                                                                                                                            Start date:04/02/2025
                                                                                                                                                                                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                                                                                                                                                                                                            Imagebase:0x7ff76e190000
                                                                                                                                                                                                            File size:3'242'272 bytes
                                                                                                                                                                                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Has exited:false

                                                                                                                                                                                                            Target ID:2
                                                                                                                                                                                                            Start time:16:38:04
                                                                                                                                                                                                            Start date:04/02/2025
                                                                                                                                                                                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2208,i,13408538171806119008,16757192466884648778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                                                                                                            Imagebase:0x7ff76e190000
                                                                                                                                                                                                            File size:3'242'272 bytes
                                                                                                                                                                                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Has exited:false

                                                                                                                                                                                                            Target ID:3
                                                                                                                                                                                                            Start time:16:38:11
                                                                                                                                                                                                            Start date:04/02/2025
                                                                                                                                                                                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://urldn.com/aznY3"
                                                                                                                                                                                                            Imagebase:0x7ff76e190000
                                                                                                                                                                                                            File size:3'242'272 bytes
                                                                                                                                                                                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Has exited:true

                                                                                                                                                                                                            No disassembly