Edit tour

Windows Analysis Report
https://sonarmedia.a2hosted.com/

Overview

General Information

Sample URL:https://sonarmedia.a2hosted.com/
Analysis ID:1632294
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Confidence:60%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5916 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2380,i,13228212794573036918,10812161052866168788,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2404 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6804 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sonarmedia.a2hosted.com/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.18.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.18.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.18.3
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.18.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.18.3
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sonarmedia.a2hosted.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sonarmedia.a2hosted.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sonarmedia.a2hosted.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: sonarmedia.a2hosted.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 20:05:34 GMTServer: ApacheX-Powered-By: PHP/8.2.27Cache-Control: no-storeStrict-Transport-Security: max-age=63072000; includeSubDomainsX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffContent-Length: 0Connection: closeContent-Type: text/html; charset=UTF-8
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 20:05:46 GMTServer: ApacheX-Powered-By: PHP/8.2.27Cache-Control: no-storeStrict-Transport-Security: max-age=63072000; includeSubDomainsX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffContent-Length: 0Connection: closeContent-Type: text/html; charset=UTF-8
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@20/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2380,i,13228212794573036918,10812161052866168788,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2404 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sonarmedia.a2hosted.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2380,i,13228212794573036918,10812161052866168788,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2404 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1632294 URL: https://sonarmedia.a2hosted.com/ Startdate: 07/03/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 443, 49448, 49709 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.250.185.68, 443, 49718 GOOGLEUS United States 10->15 17 sonarmedia.a2hosted.com 68.66.216.7, 443, 49724, 49725 A2HOSTINGUS United States 10->17

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://sonarmedia.a2hosted.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.68
truefalse
    high
    sonarmedia.a2hosted.com
    68.66.216.7
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://sonarmedia.a2hosted.com/false
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.68
        www.google.comUnited States
        15169GOOGLEUSfalse
        68.66.216.7
        sonarmedia.a2hosted.comUnited States
        55293A2HOSTINGUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1632294
        Start date and time:2025-03-07 21:04:27 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 1s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://sonarmedia.a2hosted.com/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:10
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@20/0@4/3
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.142, 142.250.186.35, 74.125.206.84, 142.250.185.78, 142.250.186.110, 172.217.16.142, 142.250.185.206, 88.221.110.64, 216.58.212.142, 142.250.185.238, 23.199.214.10
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://sonarmedia.a2hosted.com/
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 80
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Mar 7, 2025 21:05:25.654597044 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:26.140561104 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:26.763915062 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:27.746198893 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:27.746243954 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:27.746361971 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:27.746874094 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:27.746884108 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:28.049870968 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:29.817249060 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:29.818500996 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:29.818526983 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:29.819668055 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:29.819828033 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:29.821621895 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:29.821712971 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:29.862211943 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:29.862250090 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:29.909085035 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:30.385317087 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:30.385415077 CET44349718142.250.185.68192.168.2.4
        Mar 7, 2025 21:05:30.385462999 CET49718443192.168.2.4142.250.185.68
        Mar 7, 2025 21:05:30.455655098 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:31.868211031 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.868263960 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:31.868324041 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.868803024 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.868856907 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:31.868908882 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.869477034 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.869494915 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:31.869824886 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:31.869841099 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.885332108 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.885629892 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.885663033 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.886401892 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:33.887005091 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.887063026 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.887625933 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.888175964 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.888205051 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.888390064 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.888480902 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.888664961 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.888679028 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.889318943 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.889364958 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.889879942 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.889945030 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.932559967 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.932663918 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:33.932678938 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:33.978765965 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:34.191306114 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:34.538371086 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:34.538472891 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:34.538527012 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:34.540488958 CET49724443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:34.540520906 CET4434972468.66.216.7192.168.2.4
        Mar 7, 2025 21:05:34.801673889 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:35.268608093 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:36.002892017 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:37.334994078 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.336087942 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.336139917 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.340948105 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.341932058 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.341945887 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.441247940 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.441329002 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.476325989 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.482497931 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.573079109 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.573174000 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.578006983 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.583671093 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.684719086 CET44349709131.253.33.254192.168.2.4
        Mar 7, 2025 21:05:37.684916019 CET49709443192.168.2.4131.253.33.254
        Mar 7, 2025 21:05:37.690613985 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:37.690979004 CET49730443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:37.691034079 CET44349730204.79.197.222192.168.2.4
        Mar 7, 2025 21:05:37.691375017 CET49730443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:37.691664934 CET49730443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:37.691679001 CET44349730204.79.197.222192.168.2.4
        Mar 7, 2025 21:05:38.003730059 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:38.021359921 CET4973180192.168.2.4172.217.18.3
        Mar 7, 2025 21:05:38.026468992 CET8049731172.217.18.3192.168.2.4
        Mar 7, 2025 21:05:38.026535988 CET4973180192.168.2.4172.217.18.3
        Mar 7, 2025 21:05:38.026622057 CET4973180192.168.2.4172.217.18.3
        Mar 7, 2025 21:05:38.031665087 CET8049731172.217.18.3192.168.2.4
        Mar 7, 2025 21:05:38.409964085 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:38.611792088 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:38.657763958 CET8049731172.217.18.3192.168.2.4
        Mar 7, 2025 21:05:38.663438082 CET4973180192.168.2.4172.217.18.3
        Mar 7, 2025 21:05:38.668473959 CET8049731172.217.18.3192.168.2.4
        Mar 7, 2025 21:05:38.846695900 CET8049731172.217.18.3192.168.2.4
        Mar 7, 2025 21:05:38.894968987 CET4973180192.168.2.4172.217.18.3
        Mar 7, 2025 21:05:39.816852093 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:39.940064907 CET44349730204.79.197.222192.168.2.4
        Mar 7, 2025 21:05:39.940139055 CET49730443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:42.221697092 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:43.221488953 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 21:05:44.344954967 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.345005989 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:44.345089912 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.345839977 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.345849991 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:44.352336884 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.387928009 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:44.388008118 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:44.388101101 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.389514923 CET49725443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:44.389540911 CET4434972568.66.216.7192.168.2.4
        Mar 7, 2025 21:05:44.874479055 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 21:05:46.459897041 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:46.460186005 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:46.460210085 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:46.460546017 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:46.460860014 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:46.460916042 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:46.461034060 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:46.504369020 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:47.026710033 CET49680443192.168.2.4204.79.197.222
        Mar 7, 2025 21:05:47.462821960 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:47.463469028 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:47.463526011 CET4434973368.66.216.7192.168.2.4
        Mar 7, 2025 21:05:47.463628054 CET49733443192.168.2.468.66.216.7
        Mar 7, 2025 21:05:52.830607891 CET49678443192.168.2.420.189.173.27
        TimestampSource PortDest PortSource IPDest IP
        Mar 7, 2025 21:05:26.673746109 CET53521121.1.1.1192.168.2.4
        Mar 7, 2025 21:05:26.680980921 CET53558691.1.1.1192.168.2.4
        Mar 7, 2025 21:05:27.738284111 CET5831553192.168.2.41.1.1.1
        Mar 7, 2025 21:05:27.738423109 CET5149453192.168.2.41.1.1.1
        Mar 7, 2025 21:05:27.745321035 CET53514941.1.1.1192.168.2.4
        Mar 7, 2025 21:05:27.745336056 CET53583151.1.1.1192.168.2.4
        Mar 7, 2025 21:05:30.284148932 CET53544621.1.1.1192.168.2.4
        Mar 7, 2025 21:05:30.394479990 CET53527421.1.1.1192.168.2.4
        Mar 7, 2025 21:05:31.853099108 CET6104753192.168.2.41.1.1.1
        Mar 7, 2025 21:05:31.853292942 CET5681553192.168.2.41.1.1.1
        Mar 7, 2025 21:05:31.863989115 CET53610471.1.1.1192.168.2.4
        Mar 7, 2025 21:05:31.866614103 CET53568151.1.1.1192.168.2.4
        Mar 7, 2025 21:05:47.489674091 CET53494481.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 7, 2025 21:05:27.738284111 CET192.168.2.41.1.1.10x8b6Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 7, 2025 21:05:27.738423109 CET192.168.2.41.1.1.10xb3ffStandard query (0)www.google.com65IN (0x0001)false
        Mar 7, 2025 21:05:31.853099108 CET192.168.2.41.1.1.10x91d4Standard query (0)sonarmedia.a2hosted.comA (IP address)IN (0x0001)false
        Mar 7, 2025 21:05:31.853292942 CET192.168.2.41.1.1.10x5549Standard query (0)sonarmedia.a2hosted.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 7, 2025 21:05:27.745321035 CET1.1.1.1192.168.2.40xb3ffNo error (0)www.google.com65IN (0x0001)false
        Mar 7, 2025 21:05:27.745336056 CET1.1.1.1192.168.2.40x8b6No error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
        Mar 7, 2025 21:05:31.863989115 CET1.1.1.1192.168.2.40x91d4No error (0)sonarmedia.a2hosted.com68.66.216.7A (IP address)IN (0x0001)false
        • sonarmedia.a2hosted.com
        • c.pki.goog
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.449731172.217.18.380
        TimestampBytes transferredDirectionData
        Mar 7, 2025 21:05:38.026622057 CET202OUTGET /r/gsr1.crl HTTP/1.1
        Cache-Control: max-age = 3000
        Connection: Keep-Alive
        Accept: */*
        If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
        User-Agent: Microsoft-CryptoAPI/10.0
        Host: c.pki.goog
        Mar 7, 2025 21:05:38.657763958 CET222INHTTP/1.1 304 Not Modified
        Date: Fri, 07 Mar 2025 20:00:47 GMT
        Expires: Fri, 07 Mar 2025 20:50:47 GMT
        Age: 291
        Last-Modified: Tue, 07 Jan 2025 07:28:00 GMT
        Cache-Control: public, max-age=3000
        Vary: Accept-Encoding
        Mar 7, 2025 21:05:38.663438082 CET200OUTGET /r/r4.crl HTTP/1.1
        Cache-Control: max-age = 3000
        Connection: Keep-Alive
        Accept: */*
        If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
        User-Agent: Microsoft-CryptoAPI/10.0
        Host: c.pki.goog
        Mar 7, 2025 21:05:38.846695900 CET222INHTTP/1.1 304 Not Modified
        Date: Fri, 07 Mar 2025 20:00:47 GMT
        Expires: Fri, 07 Mar 2025 20:50:47 GMT
        Age: 291
        Last-Modified: Thu, 25 Jul 2024 14:48:00 GMT
        Cache-Control: public, max-age=3000
        Vary: Accept-Encoding


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44972468.66.216.74435916C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-03-07 20:05:33 UTC673OUTGET / HTTP/1.1
        Host: sonarmedia.a2hosted.com
        Connection: keep-alive
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-03-07 20:05:34 UTC334INHTTP/1.1 404 Not Found
        Date: Fri, 07 Mar 2025 20:05:34 GMT
        Server: Apache
        X-Powered-By: PHP/8.2.27
        Cache-Control: no-store
        Strict-Transport-Security: max-age=63072000; includeSubDomains
        X-Frame-Options: SAMEORIGIN
        X-Content-Type-Options: nosniff
        Content-Length: 0
        Connection: close
        Content-Type: text/html; charset=UTF-8


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44972568.66.216.74435916C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-03-07 20:05:44 UTC705OUTGET / HTTP/1.1
        Host: sonarmedia.a2hosted.com
        Connection: keep-alive
        Cache-Control: max-age=0
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: cross-site
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.44973368.66.216.74435916C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-03-07 20:05:46 UTC705OUTGET / HTTP/1.1
        Host: sonarmedia.a2hosted.com
        Connection: keep-alive
        Cache-Control: max-age=0
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: cross-site
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-03-07 20:05:47 UTC334INHTTP/1.1 404 Not Found
        Date: Fri, 07 Mar 2025 20:05:46 GMT
        Server: Apache
        X-Powered-By: PHP/8.2.27
        Cache-Control: no-store
        Strict-Transport-Security: max-age=63072000; includeSubDomains
        X-Frame-Options: SAMEORIGIN
        X-Content-Type-Options: nosniff
        Content-Length: 0
        Connection: close
        Content-Type: text/html; charset=UTF-8


        01020s020406080100

        Click to jump to process

        01020s0.0050100MB

        Click to jump to process

        Target ID:1
        Start time:15:05:21
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:15:05:22
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2380,i,13228212794573036918,10812161052866168788,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2404 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:15:05:30
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sonarmedia.a2hosted.com/"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly