Edit tour

Windows Analysis Report
https://metamaaskloogin.webflow.io/

Overview

General Information

Sample URL:https://metamaaskloogin.webflow.io/
Analysis ID:1637950
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
AI detected suspicious URL

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6884 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=1552 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5040 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7788 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://metamaaskloogin.webflow.io/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://metamaaskloogin.webflow.io/Avira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://metamaaskloogin.webflow.ioJoe Sandbox AI: The URL 'https://metamaaskloogin.webflow.io' appears to be a typosquatting attempt targeting the known brand MetaMask. The legitimate URL for MetaMask is 'https://metamask.io'. The analyzed URL uses a visual character substitution by adding an extra 'a' in 'metamaask' and includes 'loogin', which is a misspelling of 'login'. These changes are likely intended to deceive users into thinking they are accessing the legitimate MetaMask site. The use of 'webflow.io' as a domain extension is not inherently suspicious, as Webflow is a legitimate platform for hosting websites. However, the combination of the misspelled brand name and the context of 'login' suggests an attempt to mimic a login page, increasing the likelihood of user confusion. The structural similarity and context strongly indicate a typosquatting attempt.
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.74.47.205
Source: unknownTCP traffic detected without corresponding DNS query: 20.74.47.205
Source: unknownTCP traffic detected without corresponding DNS query: 20.74.47.205
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.77.188
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.15.178.200
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: metamaaskloogin.webflow.io
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal52.win@23/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=1552 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5040 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://metamaaskloogin.webflow.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=1552 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5040 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1637950 URL: https://metamaaskloogin.web... Startdate: 14/03/2025 Architecture: WINDOWS Score: 52 22 Antivirus / Scanner detection for submitted sample 2->22 24 AI detected suspicious URL 2->24 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.5, 443, 49723, 49724 unknown unknown 6->16 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 18 metamaaskloogin.webflow.io 172.64.151.8, 443, 49744, 49745 CLOUDFLARENETUS United States 11->18 20 www.google.com 142.250.185.132, 443, 49740, 49741 GOOGLEUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://metamaaskloogin.webflow.io/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
metamaaskloogin.webflow.io
172.64.151.8
truetrue
    unknown
    www.google.com
    142.250.185.132
    truefalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      142.250.185.132
      www.google.comUnited States
      15169GOOGLEUSfalse
      172.64.151.8
      metamaaskloogin.webflow.ioUnited States
      13335CLOUDFLARENETUStrue
      IP
      192.168.2.5
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1637950
      Start date and time:2025-03-14 01:29:54 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 1m 59s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://metamaaskloogin.webflow.io/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:15
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal52.win@23/0@4/3
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): sppsvc.exe, BackgroundTransferHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 2.16.185.191, 142.250.181.227, 142.250.185.142, 172.217.16.206, 74.125.133.84, 216.58.206.67, 52.165.164.15
      • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, glb.cws.prod.dcat.dsp.trafficmanager.net, clients.l.google.com, prod.fs.microsoft.com.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtOpenFile calls found.
      • VT rate limit hit for: https://metamaaskloogin.webflow.io/
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info

      Download Network PCAP: filteredfull

      • Total Packets: 219
      • 443 (HTTPS)
      • 80 (HTTP)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:30:39.747355938 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:30:43.591428041 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:43.903551102 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:44.512954950 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:44.559809923 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:30:45.716029882 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:48.122297049 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:52.926964045 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:30:54.286606073 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:30:54.564013958 CET49698443192.168.2.520.74.47.205
      Mar 14, 2025 01:30:54.564408064 CET49697443192.168.2.520.74.47.205
      Mar 14, 2025 01:30:54.564512014 CET49700443192.168.2.520.74.47.205
      Mar 14, 2025 01:30:54.564659119 CET4970180192.168.2.5199.232.210.172
      Mar 14, 2025 01:30:54.564726114 CET4970280192.168.2.5199.232.210.172
      Mar 14, 2025 01:30:54.564793110 CET4970480192.168.2.5199.232.210.172
      Mar 14, 2025 01:30:54.564821959 CET4970780192.168.2.52.23.77.188
      Mar 14, 2025 01:30:54.597138882 CET49723443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.597145081 CET49724443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.597189903 CET4434972423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.597189903 CET4434972323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.597265959 CET49723443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.597331047 CET49724443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.649624109 CET49724443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.649638891 CET4434972423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.649956942 CET49723443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.649990082 CET4434972323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.650243998 CET4434972423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.650532007 CET4434972323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.651046038 CET49726443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651086092 CET4434972623.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.651166916 CET49727443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651191950 CET49726443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651191950 CET4434972723.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.651377916 CET49727443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651540041 CET49726443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651557922 CET4434972623.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.651725054 CET49727443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.651740074 CET4434972723.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.651899099 CET4434972623.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.652160883 CET4434972723.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.652477026 CET49728443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.652494907 CET4434972823.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.652546883 CET49728443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.652776003 CET49729443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.652796030 CET4434972923.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.652812958 CET49728443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.652838945 CET4434972823.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.652842999 CET49729443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.652884007 CET49728443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.653023005 CET49729443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.653052092 CET4434972923.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.653103113 CET49729443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.829885006 CET49731443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.829927921 CET4434973123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.830025911 CET49731443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.830523968 CET49731443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.830543995 CET4434973123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.831141949 CET4434973123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.831695080 CET49732443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.831715107 CET4434973223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.831815958 CET49732443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.832227945 CET49732443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.832245111 CET4434973223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.832645893 CET4434973223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.833091974 CET49733443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.833142996 CET4434973323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.833204031 CET49733443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.833348989 CET49733443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.833378077 CET4434973323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.833460093 CET49733443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.839764118 CET49734443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.839787006 CET4434973423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.839886904 CET49734443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.840178013 CET49734443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.840188026 CET4434973423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.840625048 CET4434973423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.841099024 CET49735443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.841114044 CET4434973523.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.841222048 CET49735443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.841662884 CET49735443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.841677904 CET4434973523.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.842092991 CET4434973523.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.842538118 CET49736443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.842561960 CET4434973623.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.842628002 CET49736443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.842678070 CET49736443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:54.842706919 CET4434973623.15.178.200192.168.2.5
      Mar 14, 2025 01:30:54.842792988 CET49736443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:57.382436037 CET49740443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.382476091 CET44349740142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:57.382531881 CET49740443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.382855892 CET49740443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.382868052 CET44349740142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:57.581343889 CET44349740142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:57.581933022 CET49741443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.582045078 CET44349741142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:57.582240105 CET49741443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.582667112 CET49741443192.168.2.5142.250.185.132
      Mar 14, 2025 01:30:57.582722902 CET44349741142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:57.781948090 CET44349741142.250.185.132192.168.2.5
      Mar 14, 2025 01:30:58.896624088 CET49744443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.896680117 CET44349744172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:58.896758080 CET49744443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.896785975 CET49745443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.896821976 CET44349745172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:58.896879911 CET49745443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.897212982 CET49745443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.897223949 CET44349745172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:58.897670984 CET49744443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:58.897691965 CET44349744172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.097063065 CET44349744172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.097632885 CET49746443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.097700119 CET44349746172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.097778082 CET49746443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.097995996 CET44349745172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.098195076 CET49746443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.098206043 CET44349746172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.098562956 CET49747443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.098676920 CET44349747172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.098790884 CET49747443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.099072933 CET49747443192.168.2.5172.64.151.8
      Mar 14, 2025 01:30:59.099114895 CET44349747172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.297090054 CET44349746172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.297318935 CET44349747172.64.151.8192.168.2.5
      Mar 14, 2025 01:30:59.862195015 CET49750443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.862260103 CET4434975023.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.866235971 CET49750443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.866584063 CET49751443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.866627932 CET4434975123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.866708040 CET49751443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.866707087 CET49750443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.866724968 CET4434975023.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.866957903 CET49751443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.866964102 CET4434975123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.867403030 CET4434975023.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.867702961 CET4434975123.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.867841959 CET49752443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.867880106 CET4434975223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.868144989 CET49753443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.868185997 CET4434975323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.868215084 CET49752443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.868544102 CET49753443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.868628025 CET49752443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.868640900 CET4434975223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.868659019 CET49753443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.868665934 CET4434975323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869123936 CET4434975223.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869270086 CET4434975323.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869550943 CET49754443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.869581938 CET4434975423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869693041 CET49754443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.869693995 CET49755443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.869728088 CET4434975523.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869743109 CET49754443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.869764090 CET4434975423.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.869786024 CET49755443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.869872093 CET49754443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.870058060 CET49755443192.168.2.523.15.178.200
      Mar 14, 2025 01:30:59.870086908 CET4434975523.15.178.200192.168.2.5
      Mar 14, 2025 01:30:59.871700048 CET49755443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:00.386384964 CET49757443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.386441946 CET44349757172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.386533976 CET49757443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.388077021 CET49758443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.388139009 CET44349758172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.388704062 CET49758443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.389086008 CET49757443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.389101982 CET44349757172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.389372110 CET49758443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.389384985 CET44349758172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.589171886 CET44349758172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.589685917 CET49759443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.589728117 CET44349759172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.589798927 CET49759443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.589879990 CET44349757172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.590131044 CET49759443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.590145111 CET44349759172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.590462923 CET49760443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.590471983 CET44349760172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.590518951 CET49760443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.590822935 CET49760443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:00.590835094 CET44349760172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.789700985 CET44349760172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.789849997 CET44349759172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:00.907937050 CET49761443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.907991886 CET4434976120.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.908102036 CET49761443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.909080982 CET49761443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.909096003 CET4434976120.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.909761906 CET4434976120.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.912764072 CET49762443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.912813902 CET4434976220.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.912875891 CET49762443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.913183928 CET49762443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.913197041 CET4434976220.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.913582087 CET4434976220.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.971333027 CET49763443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.971368074 CET4434976320.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.971451998 CET49763443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.972327948 CET49763443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.972335100 CET4434976320.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.972795010 CET4434976320.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.983411074 CET49764443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.983458996 CET4434976420.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.983583927 CET49764443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.983921051 CET49764443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:00.983932018 CET4434976420.109.210.53192.168.2.5
      Mar 14, 2025 01:31:00.984316111 CET4434976420.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.022834063 CET49765443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.022891045 CET4434976520.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.022964001 CET49765443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.023293972 CET49765443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.023313046 CET4434976520.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.023977041 CET4434976520.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.052536011 CET49766443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.052587032 CET4434976620.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.052661896 CET49766443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.053107023 CET49766443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.053119898 CET4434976620.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.053993940 CET4434976620.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.113457918 CET49767443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.113502026 CET4434976720.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.113604069 CET49767443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.113924980 CET49767443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.113934040 CET4434976720.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.114815950 CET4434976720.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.133042097 CET49768443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.133095026 CET4434976820.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.133253098 CET49768443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.133668900 CET49768443192.168.2.520.109.210.53
      Mar 14, 2025 01:31:01.133686066 CET4434976820.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.134386063 CET4434976820.109.210.53192.168.2.5
      Mar 14, 2025 01:31:01.460901022 CET49769443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.460961103 CET4434976923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.461185932 CET49769443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.476212025 CET49769443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.476228952 CET4434976923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.477003098 CET4434976923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.478135109 CET49770443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.478194952 CET4434977023.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.478291035 CET49770443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.478569031 CET49771443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.478615046 CET4434977123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.478660107 CET49771443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.479038954 CET49771443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.479053020 CET4434977123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.479739904 CET4434977123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.485364914 CET49770443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.485383034 CET4434977023.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.485801935 CET49772443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.485831976 CET4434977223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.485929012 CET4434977023.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.485949039 CET49772443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487023115 CET49773443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487034082 CET4434977323.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.487102985 CET49772443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487118959 CET4434977223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.487137079 CET49773443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487198114 CET49773443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487231016 CET4434977323.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.487360001 CET49773443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.487577915 CET4434977223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.488660097 CET49774443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.488673925 CET4434977423.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.488734007 CET49774443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.488833904 CET49774443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.488876104 CET4434977423.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.488924980 CET49774443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.618669033 CET49775443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.618717909 CET4434977523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.618786097 CET49775443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.619555950 CET49775443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.619571924 CET4434977523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.620223045 CET4434977523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.622852087 CET49776443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.622885942 CET4434977623.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.622986078 CET49776443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.623326063 CET49776443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.623337984 CET4434977623.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.623732090 CET4434977623.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.624660015 CET49777443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.624701977 CET4434977723.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.624787092 CET49777443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.624883890 CET49777443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.624923944 CET4434977723.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.624969006 CET49777443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.628371000 CET49778443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.628424883 CET4434977823.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.628501892 CET49778443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.628925085 CET49778443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.628947973 CET4434977823.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.629324913 CET4434977823.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.629754066 CET49779443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.629780054 CET4434977923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.630012989 CET49779443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.630430937 CET49779443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.630443096 CET4434977923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.630788088 CET4434977923.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.631284952 CET49780443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.631298065 CET4434978023.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.631380081 CET49780443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.631414890 CET49780443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.631460905 CET4434978023.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.631504059 CET49780443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.751210928 CET49781443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.751271963 CET4434978123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.751364946 CET49781443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.751954079 CET49781443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.751966000 CET4434978123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.752625942 CET4434978123.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.754861116 CET49782443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.754914045 CET4434978223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.754983902 CET49782443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.755363941 CET49782443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.755377054 CET4434978223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.755736113 CET4434978223.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.756500006 CET49783443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.756531000 CET4434978323.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.756705046 CET49783443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.756989002 CET49783443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.757010937 CET4434978323.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.757169962 CET49783443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.758927107 CET49784443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.758963108 CET4434978423.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.759066105 CET49784443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.759380102 CET49784443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.759394884 CET4434978423.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.759738922 CET4434978423.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.760135889 CET49785443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.760162115 CET4434978523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.760313034 CET49785443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.760607958 CET49785443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.760617018 CET4434978523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.760936022 CET4434978523.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.761606932 CET49786443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.761632919 CET4434978623.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.761763096 CET49786443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.761893988 CET49786443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:01.761909962 CET4434978623.15.178.200192.168.2.5
      Mar 14, 2025 01:31:01.761950016 CET49786443192.168.2.523.15.178.200
      Mar 14, 2025 01:31:02.529659986 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:31:05.862550974 CET49787443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.862601042 CET44349787172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:05.862714052 CET49787443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.863193035 CET49788443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.863226891 CET44349788172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:05.863671064 CET49788443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.869926929 CET49788443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.869944096 CET44349788172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:05.870023966 CET49787443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:05.870038986 CET44349787172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.069117069 CET44349787172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.069221020 CET44349788172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.069811106 CET49789443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.069853067 CET44349789172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.069926023 CET49789443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.070226908 CET49790443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.070266962 CET44349790172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.070326090 CET49790443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.070606947 CET49789443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.070626020 CET44349789172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.070920944 CET49790443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:06.070935011 CET44349790172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.269499063 CET44349790172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:06.269530058 CET44349789172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:08.942678928 CET49796443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.942713022 CET49795443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.942723989 CET44349796172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:08.942749977 CET44349795172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:08.942832947 CET49796443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.942838907 CET49795443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.943161011 CET49795443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.943176985 CET44349795172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:08.944099903 CET49796443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:08.944128036 CET44349796172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.141231060 CET44349795172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.141879082 CET49797443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.141921997 CET44349797172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.142108917 CET49797443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.145164967 CET44349796172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.145206928 CET49797443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.145219088 CET44349797172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.145822048 CET49798443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.145863056 CET44349798172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.148292065 CET49798443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.148646116 CET49798443192.168.2.5172.64.151.8
      Mar 14, 2025 01:31:09.148672104 CET44349798172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.345463991 CET44349797172.64.151.8192.168.2.5
      Mar 14, 2025 01:31:09.349154949 CET44349798172.64.151.8192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:30:53.220698118 CET53598181.1.1.1192.168.2.5
      Mar 14, 2025 01:30:53.429660082 CET53643021.1.1.1192.168.2.5
      Mar 14, 2025 01:30:57.374419928 CET5493753192.168.2.51.1.1.1
      Mar 14, 2025 01:30:57.374651909 CET6329653192.168.2.51.1.1.1
      Mar 14, 2025 01:30:57.381422043 CET53549371.1.1.1192.168.2.5
      Mar 14, 2025 01:30:57.381464958 CET53632961.1.1.1192.168.2.5
      Mar 14, 2025 01:30:58.885588884 CET5227653192.168.2.51.1.1.1
      Mar 14, 2025 01:30:58.885765076 CET5032553192.168.2.51.1.1.1
      Mar 14, 2025 01:30:58.895596027 CET53522761.1.1.1192.168.2.5
      Mar 14, 2025 01:30:58.895618916 CET53503251.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Mar 14, 2025 01:30:57.374419928 CET192.168.2.51.1.1.10xa5c5Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Mar 14, 2025 01:30:57.374651909 CET192.168.2.51.1.1.10x3c31Standard query (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:30:58.885588884 CET192.168.2.51.1.1.10x30c2Standard query (0)metamaaskloogin.webflow.ioA (IP address)IN (0x0001)false
      Mar 14, 2025 01:30:58.885765076 CET192.168.2.51.1.1.10xdff4Standard query (0)metamaaskloogin.webflow.io65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Mar 14, 2025 01:30:57.381422043 CET1.1.1.1192.168.2.50xa5c5No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
      Mar 14, 2025 01:30:57.381464958 CET1.1.1.1192.168.2.50x3c31No error (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:30:58.895596027 CET1.1.1.1192.168.2.50x30c2No error (0)metamaaskloogin.webflow.io172.64.151.8A (IP address)IN (0x0001)false
      Mar 14, 2025 01:30:58.895596027 CET1.1.1.1192.168.2.50x30c2No error (0)metamaaskloogin.webflow.io104.18.36.248A (IP address)IN (0x0001)false
      Mar 14, 2025 01:30:58.895618916 CET1.1.1.1192.168.2.50xdff4No error (0)metamaaskloogin.webflow.io65IN (0x0001)false
      0510152025s020406080100

      Click to jump to process

      0510152025s0.0050100MB

      Click to jump to process

      Target ID:2
      Start time:20:30:46
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff697e50000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:5
      Start time:20:30:51
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=1552 /prefetch:3
      Imagebase:0x7ff697e50000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:9
      Start time:20:30:54
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1980,i,3220628845632107283,18224929301032935228,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5040 /prefetch:8
      Imagebase:0x7ff697e50000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:12
      Start time:20:30:57
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://metamaaskloogin.webflow.io/"
      Imagebase:0x7ff697e50000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

      No disassembly