Edit tour

Windows Analysis Report
https://11775357.com/

Overview

General Information

Sample URL:https://11775357.com/
Analysis ID:1637946
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5576 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2176 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,1145935987004933934,10716230323472234756,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://11775357.com/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://11775357.com/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: 11775357.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: classification engineClassification label: mal48.win@21/0@5/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,1145935987004933934,10716230323472234756,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://11775357.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,1145935987004933934,10716230323472234756,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1637946 URL: https://11775357.com/ Startdate: 14/03/2025 Architecture: WINDOWS Score: 48 22 Antivirus / Scanner detection for submitted sample 2->22 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 443, 49708, 49735 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 www.google.com 142.250.186.100, 443, 49735, 49736 GOOGLEUS United States 11->16 18 xin.jump4mnydu.xyz 45.138.71.205, 443, 49739, 49740 AS40676US Italy 11->18 20 2 other IPs or domains 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://11775357.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
xin.jump4mnydu.xyz
45.138.71.205
truefalse
    high
    www.google.com
    142.250.186.100
    truefalse
      high
      11775357.com
      unknown
      unknownfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        45.138.71.205
        xin.jump4mnydu.xyzItaly
        40676AS40676USfalse
        142.250.186.100
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1637946
        Start date and time:2025-03-14 01:26:53 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 1m 57s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://11775357.com/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:12
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@21/0@5/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.18.3, 216.58.206.46, 108.177.15.84, 216.58.206.78, 2.23.77.188
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://11775357.com/
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 118
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Mar 14, 2025 01:27:51.157033920 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:27:51.562657118 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:27:52.259638071 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:27:53.469168901 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:27:55.875211954 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:27:56.196640015 CET49735443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.196687937 CET44349735142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:56.196914911 CET49735443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.197151899 CET49735443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.197166920 CET44349735142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:56.405304909 CET44349735142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:56.405867100 CET49736443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.405911922 CET44349736142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:56.406100035 CET49736443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.406380892 CET49736443192.168.2.4142.250.186.100
        Mar 14, 2025 01:27:56.406395912 CET44349736142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:56.605334044 CET44349736142.250.186.100192.168.2.4
        Mar 14, 2025 01:27:58.235276937 CET49739443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.235321999 CET4434973945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.235445976 CET49739443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.238044977 CET49740443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.238132954 CET4434974045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.238400936 CET49739443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.238425970 CET49740443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.238440990 CET4434973945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.245043993 CET49740443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.245078087 CET4434974045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.437407017 CET4434973945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.440323114 CET49741443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.440392017 CET4434974145.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.440457106 CET49741443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.440762997 CET49741443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.440777063 CET4434974145.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.445200920 CET4434974045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.445635080 CET49742443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.445688009 CET4434974245.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.445734978 CET49742443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.446019888 CET49742443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:58.446033001 CET4434974245.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.543680906 CET49744443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.543720961 CET4434974423.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.543808937 CET49744443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.552977085 CET49744443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.552992105 CET4434974423.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.553596973 CET4434974423.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.557790995 CET49745443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.557842016 CET4434974523.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.557909012 CET49745443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.558330059 CET49745443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.558345079 CET4434974523.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.559753895 CET4434974523.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.560415983 CET49746443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.560467958 CET4434974623.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.560640097 CET49746443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.565593958 CET49746443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.565639019 CET4434974623.199.214.10192.168.2.4
        Mar 14, 2025 01:27:58.565694094 CET49746443192.168.2.423.199.214.10
        Mar 14, 2025 01:27:58.641284943 CET4434974145.138.71.205192.168.2.4
        Mar 14, 2025 01:27:58.645875931 CET4434974245.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.684726000 CET49749443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.684782982 CET4434974945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.684923887 CET49749443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.685246944 CET49750443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.685288906 CET4434975045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.685336113 CET49750443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.687107086 CET49750443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.687124014 CET4434975045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.688014984 CET49749443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.688028097 CET4434974945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.885123968 CET4434975045.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.885498047 CET4434974945.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.885649920 CET49751443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.885699987 CET4434975145.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.885783911 CET49751443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.886059999 CET49752443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.886107922 CET4434975245.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.886168003 CET49752443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.886461020 CET49751443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.886475086 CET4434975145.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.886751890 CET49752443192.168.2.445.138.71.205
        Mar 14, 2025 01:27:59.886765957 CET4434975245.138.71.205192.168.2.4
        Mar 14, 2025 01:27:59.918755054 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:00.085196018 CET4434975145.138.71.205192.168.2.4
        Mar 14, 2025 01:28:00.085915089 CET4434975245.138.71.205192.168.2.4
        Mar 14, 2025 01:28:00.225027084 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:00.690810919 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:28:00.836364031 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:02.046603918 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:02.693380117 CET4968180192.168.2.42.17.190.73
        Mar 14, 2025 01:28:03.002245903 CET4968180192.168.2.42.17.190.73
        Mar 14, 2025 01:28:03.329665899 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.330404043 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.330719948 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.334419012 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.347769976 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.348047972 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.426412106 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.428693056 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.436148882 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.436248064 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.523233891 CET4434970852.113.196.254192.168.2.4
        Mar 14, 2025 01:28:03.523319960 CET49708443192.168.2.452.113.196.254
        Mar 14, 2025 01:28:03.609381914 CET4968180192.168.2.42.17.190.73
        Mar 14, 2025 01:28:04.453088999 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:04.722496986 CET49756443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.722543955 CET443497564.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.722613096 CET49756443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.723670006 CET49756443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.723685980 CET443497564.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.724345922 CET443497564.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.747154951 CET49757443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.747193098 CET443497574.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.747271061 CET49757443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.747612000 CET49757443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.747627974 CET443497574.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.748061895 CET443497574.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.779305935 CET49758443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.779406071 CET443497584.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.779485941 CET49758443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.779894114 CET49758443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.779931068 CET443497584.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.780378103 CET443497584.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.797552109 CET49759443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.797588110 CET443497594.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.797677994 CET49759443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.798209906 CET49759443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.798221111 CET443497594.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.798623085 CET443497594.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.812469959 CET4968180192.168.2.42.17.190.73
        Mar 14, 2025 01:28:04.838531017 CET49760443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.838562965 CET443497604.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.838634968 CET49760443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.839006901 CET49760443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.839020014 CET443497604.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.839503050 CET443497604.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.853219986 CET49761443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.853264093 CET443497614.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.853385925 CET49761443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.853795052 CET49761443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.853811979 CET443497614.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.854202986 CET443497614.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.887440920 CET49762443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.887489080 CET443497624.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.887700081 CET49762443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.888042927 CET49762443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.888057947 CET443497624.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.888473988 CET443497624.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.903414965 CET49763443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.903513908 CET443497634.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.903599024 CET49763443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.903899908 CET49763443192.168.2.44.245.163.56
        Mar 14, 2025 01:28:04.903943062 CET443497634.245.163.56192.168.2.4
        Mar 14, 2025 01:28:04.904377937 CET443497634.245.163.56192.168.2.4
        Mar 14, 2025 01:28:05.113780022 CET49764443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.113883018 CET4434976445.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.113933086 CET49765443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.113970995 CET49764443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.113990068 CET4434976545.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.114052057 CET49765443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.114895105 CET49765443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.114914894 CET4434976545.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.115494013 CET49764443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.115534067 CET4434976445.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.313271999 CET4434976545.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.313780069 CET4434976445.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.313852072 CET49766443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.313971996 CET4434976645.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.314066887 CET49766443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.314218998 CET49767443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.314275980 CET4434976745.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.314332008 CET49767443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.314716101 CET49766443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.314757109 CET4434976645.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.315145016 CET49767443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:05.315174103 CET4434976745.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.513005018 CET4434976645.138.71.205192.168.2.4
        Mar 14, 2025 01:28:05.513436079 CET4434976745.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.219474077 CET4968180192.168.2.42.17.190.73
        Mar 14, 2025 01:28:07.720478058 CET49770443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.720524073 CET4434977045.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.720616102 CET49770443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.720675945 CET49771443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.720730066 CET4434977145.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.720793962 CET49771443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.721307993 CET49770443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.721322060 CET4434977045.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.721724987 CET49771443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.721749067 CET4434977145.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.921480894 CET4434977045.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.921917915 CET4434977145.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.922298908 CET49772443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.922344923 CET4434977245.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.922430038 CET49772443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.922938108 CET49773443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.922982931 CET4434977345.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.923121929 CET49773443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.923294067 CET49772443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.923310041 CET4434977245.138.71.205192.168.2.4
        Mar 14, 2025 01:28:07.923511028 CET49773443192.168.2.445.138.71.205
        Mar 14, 2025 01:28:07.923525095 CET4434977345.138.71.205192.168.2.4
        Mar 14, 2025 01:28:08.121102095 CET4434977345.138.71.205192.168.2.4
        Mar 14, 2025 01:28:08.121486902 CET4434977245.138.71.205192.168.2.4
        Mar 14, 2025 01:28:09.265578032 CET49678443192.168.2.420.189.173.27
        Mar 14, 2025 01:28:10.296715021 CET49671443192.168.2.4204.79.197.203
        Mar 14, 2025 01:28:12.031207085 CET4968180192.168.2.42.17.190.73
        TimestampSource PortDest PortSource IPDest IP
        Mar 14, 2025 01:27:51.953118086 CET53559041.1.1.1192.168.2.4
        Mar 14, 2025 01:27:51.965507030 CET53551091.1.1.1192.168.2.4
        Mar 14, 2025 01:27:56.188720942 CET5733553192.168.2.41.1.1.1
        Mar 14, 2025 01:27:56.188891888 CET6219453192.168.2.41.1.1.1
        Mar 14, 2025 01:27:56.195424080 CET53621941.1.1.1192.168.2.4
        Mar 14, 2025 01:27:56.195585966 CET53573351.1.1.1192.168.2.4
        Mar 14, 2025 01:27:57.274158955 CET6155953192.168.2.41.1.1.1
        Mar 14, 2025 01:27:57.274339914 CET5388653192.168.2.41.1.1.1
        Mar 14, 2025 01:27:57.291121960 CET53538861.1.1.1192.168.2.4
        Mar 14, 2025 01:27:57.292232990 CET5479953192.168.2.41.1.1.1
        Mar 14, 2025 01:27:57.308542013 CET53547991.1.1.1192.168.2.4
        Mar 14, 2025 01:27:58.200006962 CET53615591.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 14, 2025 01:27:56.188720942 CET192.168.2.41.1.1.10x244bStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 14, 2025 01:27:56.188891888 CET192.168.2.41.1.1.10x4a8aStandard query (0)www.google.com65IN (0x0001)false
        Mar 14, 2025 01:27:57.274158955 CET192.168.2.41.1.1.10x464eStandard query (0)11775357.comA (IP address)IN (0x0001)false
        Mar 14, 2025 01:27:57.274339914 CET192.168.2.41.1.1.10xc569Standard query (0)11775357.com65IN (0x0001)false
        Mar 14, 2025 01:27:57.292232990 CET192.168.2.41.1.1.10x7d30Standard query (0)11775357.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 14, 2025 01:27:56.195424080 CET1.1.1.1192.168.2.40x4a8aNo error (0)www.google.com65IN (0x0001)false
        Mar 14, 2025 01:27:56.195585966 CET1.1.1.1192.168.2.40x244bNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
        Mar 14, 2025 01:27:57.291121960 CET1.1.1.1192.168.2.40xc569Server failure (2)11775357.comnonenone65IN (0x0001)false
        Mar 14, 2025 01:27:57.308542013 CET1.1.1.1192.168.2.40x7d30Server failure (2)11775357.comnonenone65IN (0x0001)false
        Mar 14, 2025 01:27:58.200006962 CET1.1.1.1192.168.2.40x464eNo error (0)11775357.comxin.cname66.comCNAME (Canonical name)IN (0x0001)false
        Mar 14, 2025 01:27:58.200006962 CET1.1.1.1192.168.2.40x464eNo error (0)xin.cname66.comxin.jump4mnydu.xyzCNAME (Canonical name)IN (0x0001)false
        Mar 14, 2025 01:27:58.200006962 CET1.1.1.1192.168.2.40x464eNo error (0)xin.jump4mnydu.xyz45.138.71.205A (IP address)IN (0x0001)false
        0510152025s020406080100

        Click to jump to process

        0510152025s0.0050100MB

        Click to jump to process

        Target ID:1
        Start time:20:27:47
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:20:27:49
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,1145935987004933934,10716230323472234756,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:20:27:55
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://11775357.com/"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly