Edit tour

Windows Analysis Report
https://kucoin-logzin.webflow.io/

Overview

General Information

Sample URL:https://kucoin-logzin.webflow.io/
Analysis ID:1637929
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
AI detected suspicious URL
Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1960 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6660 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2004 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5100 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7704 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kucoin-logzin.webflow.io/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://kucoin-logzin.webflow.io/Avira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://kucoin-logzin.webflow.ioJoe Sandbox AI: The URL 'kucoin-logzin.webflow.io' appears to be attempting to spoof the known cryptocurrency exchange 'KuCoin'. The legitimate URL for KuCoin is 'https://www.kucoin.com'. The analyzed URL uses 'kucoin' as a subdomain, which is a direct reference to the brand. The term 'logzin' is a misspelling of 'login', which is a common tactic in typosquatting to deceive users into thinking they are accessing a legitimate login page. The use of 'webflow.io' as the domain extension is not directly related to KuCoin and could be used to host a phishing page. The similarity score is high due to the direct use of the brand name and the deceptive misspelling. The likelihood of this being a typosquatting attempt is also high, given the context and structure of the URL.
Source: global trafficTCP traffic: 192.168.2.5:54015 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.199.58.43
Source: unknownTCP traffic detected without corresponding DNS query: 20.199.58.43
Source: unknownTCP traffic detected without corresponding DNS query: 20.199.58.43
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.77.188
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: kucoin-logzin.webflow.io
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 54022 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54016
Source: unknownNetwork traffic detected: HTTP traffic on port 54016 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54019
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54018
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54017
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54023
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54022
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54021
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54020
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 54019 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 54023 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 54020 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 54018 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 54021 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 54017 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: classification engineClassification label: mal52.win@23/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2004 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5100 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kucoin-logzin.webflow.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2004 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5100 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1637929 URL: https://kucoin-logzin.webflow.io/ Startdate: 14/03/2025 Architecture: WINDOWS Score: 52 22 Antivirus / Scanner detection for submitted sample 2->22 24 AI detected suspicious URL 2->24 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.5, 443, 49741, 49743 unknown unknown 6->16 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 18 kucoin-logzin.webflow.io 104.18.36.248, 443, 49747, 49748 CLOUDFLARENETUS United States 11->18 20 www.google.com 142.250.184.228, 443, 49741, 49743 GOOGLEUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://kucoin-logzin.webflow.io/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
kucoin-logzin.webflow.io
104.18.36.248
truetrue
    unknown
    www.google.com
    142.250.184.228
    truefalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      104.18.36.248
      kucoin-logzin.webflow.ioUnited States
      13335CLOUDFLARENETUStrue
      142.250.184.228
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.5
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1637929
      Start date and time:2025-03-14 01:20:50 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 1m 56s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://kucoin-logzin.webflow.io/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:14
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal52.win@23/0@4/3
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 184.86.251.27, 184.86.251.22, 23.60.203.209, 142.250.184.206, 142.250.186.99, 216.58.212.174, 64.233.167.84
      • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, www-www.bing.com.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, e86303.dscx.akamaiedge.net, clients2.google.com, www.bing.com.edgekey.net, clients.l.google.com, prod.fs.microsoft.com.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtOpenFile calls found.
      • VT rate limit hit for: https://kucoin-logzin.webflow.io/
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info

      Download Network PCAP: filteredfull

      • Total Packets: 103
      • 443 (HTTPS)
      • 80 (HTTP)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:21:36.343943119 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:21:36.706478119 CET49700443192.168.2.520.199.58.43
      Mar 14, 2025 01:21:36.706796885 CET49698443192.168.2.520.199.58.43
      Mar 14, 2025 01:21:36.706824064 CET49699443192.168.2.520.199.58.43
      Mar 14, 2025 01:21:36.706939936 CET4970180192.168.2.5199.232.210.172
      Mar 14, 2025 01:21:36.706994057 CET4970280192.168.2.5199.232.210.172
      Mar 14, 2025 01:21:36.707020998 CET4970380192.168.2.5199.232.210.172
      Mar 14, 2025 01:21:36.707072973 CET4970680192.168.2.52.23.77.188
      Mar 14, 2025 01:21:40.432925940 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:40.734555960 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:41.156455040 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:21:41.343967915 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:42.547059059 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:45.047060966 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:49.859579086 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:50.797064066 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:21:53.028126001 CET49741443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.028158903 CET44349741142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:53.028326988 CET49741443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.028666973 CET49741443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.028678894 CET44349741142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:53.229409933 CET44349741142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:53.230164051 CET49743443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.230207920 CET44349743142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:53.230278015 CET49743443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.230668068 CET49743443192.168.2.5142.250.184.228
      Mar 14, 2025 01:21:53.230689049 CET44349743142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:53.433337927 CET44349743142.250.184.228192.168.2.5
      Mar 14, 2025 01:21:55.119885921 CET49748443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.119890928 CET49747443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.119920969 CET44349748104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.119923115 CET44349747104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.120321989 CET49747443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.120335102 CET49748443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.120857000 CET49747443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.120873928 CET44349747104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.121301889 CET49748443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.121323109 CET44349748104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.321351051 CET44349748104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.321525097 CET44349747104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.321916103 CET49749443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.321959972 CET44349749104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.322082043 CET49749443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.322330952 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.322356939 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.322509050 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.322937012 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.322942019 CET49749443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:55.322948933 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.322968960 CET44349749104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.521805048 CET44349749104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:55.521954060 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.558186054 CET49754443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.558249950 CET44349754104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.558303118 CET49754443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.558623075 CET49755443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.558670044 CET44349755104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.558717966 CET49755443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.559684992 CET49754443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.559705019 CET44349754104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.560112953 CET49755443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.560133934 CET44349755104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.756985903 CET44349755104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.757550001 CET49756443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.757592916 CET44349756104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.757659912 CET49756443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.758018970 CET44349754104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.758085966 CET49756443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.758100033 CET44349756104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.758656979 CET49757443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.758708954 CET44349757104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.758764029 CET49757443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.759057045 CET49757443192.168.2.5104.18.36.248
      Mar 14, 2025 01:21:56.759073973 CET44349757104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.957356930 CET44349756104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:56.957429886 CET44349757104.18.36.248192.168.2.5
      Mar 14, 2025 01:21:57.332782984 CET49758443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.332834005 CET4434975820.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.332897902 CET49758443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.334439039 CET49758443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.334451914 CET4434975820.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.335170031 CET4434975820.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.356740952 CET49759443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.356802940 CET4434975920.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.356872082 CET49759443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.357250929 CET49759443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.357275963 CET4434975920.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.357891083 CET4434975920.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.394804955 CET49760443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.394841909 CET4434976020.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.395157099 CET49760443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.395503044 CET49760443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.395513058 CET4434976020.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.398854017 CET4434976020.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.409246922 CET49761443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.409285069 CET4434976120.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.409388065 CET49761443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.409682035 CET49761443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.409698009 CET4434976120.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.410293102 CET4434976120.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.461241007 CET49762443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.461289883 CET4434976220.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.461429119 CET49762443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.461859941 CET49762443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.461875916 CET4434976220.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.462490082 CET4434976220.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.473371983 CET49763443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.473408937 CET4434976320.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.473665953 CET49763443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.474028111 CET49763443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.474045038 CET4434976320.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.474427938 CET4434976320.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.498327971 CET49764443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.498367071 CET4434976420.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.498423100 CET49764443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.498733044 CET49764443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.498747110 CET4434976420.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.499213934 CET4434976420.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.513849020 CET49765443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.513885975 CET4434976520.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.514106989 CET49765443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.514369011 CET49765443192.168.2.520.12.23.50
      Mar 14, 2025 01:21:57.514384985 CET4434976520.12.23.50192.168.2.5
      Mar 14, 2025 01:21:57.514796972 CET4434976520.12.23.50192.168.2.5
      Mar 14, 2025 01:21:59.469711065 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:21:59.539263010 CET5401553192.168.2.51.1.1.1
      Mar 14, 2025 01:21:59.543948889 CET53540151.1.1.1192.168.2.5
      Mar 14, 2025 01:21:59.544008017 CET5401553192.168.2.51.1.1.1
      Mar 14, 2025 01:21:59.548690081 CET53540151.1.1.1192.168.2.5
      Mar 14, 2025 01:22:00.009563923 CET5401553192.168.2.51.1.1.1
      Mar 14, 2025 01:22:00.015117884 CET53540151.1.1.1192.168.2.5
      Mar 14, 2025 01:22:00.015214920 CET5401553192.168.2.51.1.1.1
      Mar 14, 2025 01:22:01.981498003 CET54016443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.981539011 CET44354016104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:01.981605053 CET54016443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.981842041 CET54017443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.981877089 CET44354017104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:01.981930017 CET54017443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.986278057 CET54017443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.986294985 CET44354017104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:01.986569881 CET54016443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:01.986587048 CET44354016104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.185017109 CET44354017104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.185600042 CET54018443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.185647011 CET44354018104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.185729980 CET44354016104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.186083078 CET54018443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.186213017 CET54019443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.186299086 CET44354019104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.186412096 CET54019443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.186734915 CET54018443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.186741114 CET54019443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:02.186753035 CET44354018104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.186779976 CET44354019104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.385471106 CET44354019104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:02.386286020 CET44354018104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.127146959 CET54021443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.127151966 CET54020443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.127197981 CET44354021104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.127213001 CET44354020104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.130331993 CET54021443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.130340099 CET54020443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.131145000 CET54020443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.131166935 CET44354020104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.131793022 CET54021443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.131812096 CET44354021104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.329421043 CET44354021104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.329936028 CET44354020104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.329974890 CET54022443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330014944 CET44354022104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.330251932 CET54022443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330256939 CET54023443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330307007 CET44354023104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.330600977 CET54022443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330616951 CET44354022104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.330646992 CET54023443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330960035 CET54023443192.168.2.5104.18.36.248
      Mar 14, 2025 01:22:04.330977917 CET44354023104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.529582024 CET44354023104.18.36.248192.168.2.5
      Mar 14, 2025 01:22:04.529949903 CET44354022104.18.36.248192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:21:51.541554928 CET53560611.1.1.1192.168.2.5
      Mar 14, 2025 01:21:51.646414995 CET53540961.1.1.1192.168.2.5
      Mar 14, 2025 01:21:53.018497944 CET6001353192.168.2.51.1.1.1
      Mar 14, 2025 01:21:53.018780947 CET5213953192.168.2.51.1.1.1
      Mar 14, 2025 01:21:53.026985884 CET53521391.1.1.1192.168.2.5
      Mar 14, 2025 01:21:53.026999950 CET53600131.1.1.1192.168.2.5
      Mar 14, 2025 01:21:55.100121021 CET5763353192.168.2.51.1.1.1
      Mar 14, 2025 01:21:55.100121021 CET5430553192.168.2.51.1.1.1
      Mar 14, 2025 01:21:55.110030890 CET53576331.1.1.1192.168.2.5
      Mar 14, 2025 01:21:55.110831022 CET53543051.1.1.1192.168.2.5
      Mar 14, 2025 01:21:59.538887978 CET53527721.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Mar 14, 2025 01:21:53.018497944 CET192.168.2.51.1.1.10xed83Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Mar 14, 2025 01:21:53.018780947 CET192.168.2.51.1.1.10x6e88Standard query (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:21:55.100121021 CET192.168.2.51.1.1.10x3577Standard query (0)kucoin-logzin.webflow.io65IN (0x0001)false
      Mar 14, 2025 01:21:55.100121021 CET192.168.2.51.1.1.10xd011Standard query (0)kucoin-logzin.webflow.ioA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Mar 14, 2025 01:21:53.026985884 CET1.1.1.1192.168.2.50x6e88No error (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:21:53.026999950 CET1.1.1.1192.168.2.50xed83No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
      Mar 14, 2025 01:21:55.110030890 CET1.1.1.1192.168.2.50x3577No error (0)kucoin-logzin.webflow.io65IN (0x0001)false
      Mar 14, 2025 01:21:55.110831022 CET1.1.1.1192.168.2.50xd011No error (0)kucoin-logzin.webflow.io104.18.36.248A (IP address)IN (0x0001)false
      Mar 14, 2025 01:21:55.110831022 CET1.1.1.1192.168.2.50xd011No error (0)kucoin-logzin.webflow.io172.64.151.8A (IP address)IN (0x0001)false
      0510152025s020406080100

      Click to jump to process

      0510152025s0.0050100MB

      Click to jump to process

      Target ID:3
      Start time:20:21:39
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff635c20000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:4
      Start time:20:21:46
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2004 /prefetch:3
      Imagebase:0x7ff635c20000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:6
      Start time:20:21:50
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,11621179257266418454,10153282501298767345,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5100 /prefetch:8
      Imagebase:0x7ff635c20000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:11
      Start time:20:21:54
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kucoin-logzin.webflow.io/"
      Imagebase:0x7ff635c20000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

      No disassembly