Edit tour

Windows Analysis Report
https://mttamaskextsin.webflow.io/

Overview

General Information

Sample URL:https://mttamaskextsin.webflow.io/
Analysis ID:1637954
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 7052 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6676 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2200 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4368 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7760 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mttamaskextsin.webflow.io/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://mttamaskextsin.webflow.io/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.184.227
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.184.227
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.185.191
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.58
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: mttamaskextsin.webflow.io
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: classification engineClassification label: mal48.win@23/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2200 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4368 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mttamaskextsin.webflow.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2200 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4368 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1637954 URL: https://mttamaskextsin.webf... Startdate: 14/03/2025 Architecture: WINDOWS Score: 48 22 Antivirus / Scanner detection for submitted sample 2->22 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.5, 443, 49708, 49715 unknown unknown 6->16 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 18 www.google.com 142.250.186.132, 443, 49746, 49747 GOOGLEUS United States 11->18 20 mttamaskextsin.webflow.io 104.18.36.248, 443, 49750, 49751 CLOUDFLARENETUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mttamaskextsin.webflow.io/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
mttamaskextsin.webflow.io
104.18.36.248
truefalse
    unknown
    www.google.com
    142.250.186.132
    truefalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      104.18.36.248
      mttamaskextsin.webflow.ioUnited States
      13335CLOUDFLARENETUSfalse
      142.250.186.132
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.5
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1637954
      Start date and time:2025-03-14 01:31:55 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 1m 54s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://mttamaskextsin.webflow.io/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:14
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal48.win@23/0@4/3
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 199.232.210.172, 142.250.185.238, 142.250.185.67, 142.250.184.206, 142.251.168.84
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtOpenFile calls found.
      • VT rate limit hit for: https://mttamaskextsin.webflow.io/
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info

      Download Network PCAP: filteredfull

      • Total Packets: 191
      • 443 (HTTPS)
      • 80 (HTTP)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:32:38.017385960 CET49715443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.017438889 CET443497152.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.017530918 CET49715443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.018019915 CET49715443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.018035889 CET443497152.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.018642902 CET443497152.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.019035101 CET49716443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019069910 CET443497162.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.019154072 CET49716443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019453049 CET49716443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019469976 CET443497162.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.019531965 CET49717443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019572020 CET443497172.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.019637108 CET49717443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019840002 CET49717443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.019856930 CET443497172.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.019913912 CET443497162.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.020185947 CET49718443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.020209074 CET443497182.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.020272017 CET49718443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.020302057 CET49718443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.020343065 CET443497182.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.020385981 CET49718443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.020391941 CET443497172.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.022340059 CET49719443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.022356033 CET443497192.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.022408962 CET49719443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.023230076 CET49719443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.023242950 CET443497192.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.023668051 CET443497192.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.023982048 CET49720443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.024025917 CET443497202.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.024090052 CET49720443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.024132013 CET49720443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.024158955 CET443497202.19.122.58192.168.2.5
      Mar 14, 2025 01:32:38.024208069 CET49720443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:38.174830914 CET8049708142.250.184.227192.168.2.5
      Mar 14, 2025 01:32:38.179186106 CET4970880192.168.2.5142.250.184.227
      Mar 14, 2025 01:32:38.183983088 CET8049708142.250.184.227192.168.2.5
      Mar 14, 2025 01:32:38.283195972 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:32:38.360898018 CET8049708142.250.184.227192.168.2.5
      Mar 14, 2025 01:32:38.408200979 CET4970880192.168.2.5142.250.184.227
      Mar 14, 2025 01:32:40.689493895 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:32:42.265264988 CET49724443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.265321016 CET443497242.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.265563965 CET49724443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.266587019 CET49724443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.266599894 CET443497242.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.267293930 CET443497242.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.452337980 CET49725443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.452416897 CET443497252.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.452493906 CET49725443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.468318939 CET49725443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.468384981 CET443497252.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.468995094 CET443497252.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.469386101 CET49726443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.469435930 CET443497262.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.469489098 CET49726443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.470513105 CET49726443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:42.470556021 CET443497262.16.185.191192.168.2.5
      Mar 14, 2025 01:32:42.470604897 CET49726443192.168.2.52.16.185.191
      Mar 14, 2025 01:32:45.517610073 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:32:47.274620056 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:47.595705986 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:47.607834101 CET49727443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.607873917 CET443497272.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.607928038 CET49727443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.609414101 CET49727443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.609431028 CET443497272.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.610075951 CET443497272.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.611182928 CET49728443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.611211061 CET443497282.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.611320972 CET49728443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.613517046 CET49728443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.613533974 CET443497282.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.613922119 CET443497282.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.619389057 CET49729443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.619411945 CET443497292.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.619458914 CET49729443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.619532108 CET49729443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.619559050 CET443497292.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.619602919 CET49729443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.645656109 CET49730443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.645693064 CET443497302.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.645761013 CET49730443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.646608114 CET49730443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.646620989 CET443497302.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.647037029 CET443497302.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.647636890 CET49731443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.647703886 CET443497312.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.647774935 CET49731443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.648483038 CET49731443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.648499012 CET443497312.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.649008036 CET443497312.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.649609089 CET49732443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.649625063 CET443497322.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.649678946 CET49732443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.649903059 CET49732443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:47.649936914 CET443497322.19.122.58192.168.2.5
      Mar 14, 2025 01:32:47.649980068 CET49732443192.168.2.52.19.122.58
      Mar 14, 2025 01:32:48.298820019 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:49.595587015 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:52.003160954 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:53.151206017 CET49746443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.151238918 CET44349746142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:53.151304960 CET49746443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.151613951 CET49746443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.151627064 CET44349746142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:53.349809885 CET44349746142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:53.350354910 CET49747443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.350388050 CET44349747142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:53.350455046 CET49747443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.350790977 CET49747443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:53.350806952 CET44349747142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:53.548835039 CET44349747142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:54.335613012 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.335653067 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.335741043 CET49751443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.335767031 CET44349751104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.335772038 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.335815907 CET49751443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.336321115 CET49751443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.336333036 CET44349751104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.336661100 CET49750443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.336674929 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.537206888 CET44349750104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.537765980 CET44349751104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.537875891 CET49752443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.537918091 CET44349752104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.537982941 CET49752443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.538074970 CET49753443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.538098097 CET44349753104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.538176060 CET49753443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.538311005 CET49752443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.538326979 CET44349752104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.538527966 CET49753443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:54.538541079 CET44349753104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.737837076 CET44349753104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:54.737889051 CET44349752104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.128019094 CET49672443192.168.2.5204.79.197.203
      Mar 14, 2025 01:32:55.777374029 CET49758443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.777416945 CET44349758104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.777488947 CET49758443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.777718067 CET49759443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.777770042 CET44349759104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.777885914 CET49759443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.778815985 CET49758443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.778831959 CET44349758104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.779160976 CET49759443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.779174089 CET44349759104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.977318048 CET44349758104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.977361917 CET44349759104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.977948904 CET49760443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.977998972 CET44349760104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.978056908 CET49760443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.978359938 CET49761443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.978379965 CET44349761104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.978429079 CET49761443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.978971004 CET49760443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.978984118 CET44349760104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:55.979232073 CET49761443192.168.2.5104.18.36.248
      Mar 14, 2025 01:32:55.979243040 CET44349761104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:56.177146912 CET44349761104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:56.177598000 CET44349760104.18.36.248192.168.2.5
      Mar 14, 2025 01:32:56.814187050 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:32:57.914468050 CET49762443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:57.914513111 CET44349762142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:57.918800116 CET49762443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:57.918800116 CET49762443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:57.918832064 CET44349762142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:58.117682934 CET44349762142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:58.118175030 CET49763443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:58.118226051 CET44349763142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:58.118328094 CET49763443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:58.120127916 CET49763443192.168.2.5142.250.186.132
      Mar 14, 2025 01:32:58.120142937 CET44349763142.250.186.132192.168.2.5
      Mar 14, 2025 01:32:58.317574978 CET44349763142.250.186.132192.168.2.5
      Mar 14, 2025 01:33:00.806986094 CET49764443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.807014942 CET443497644.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.807205915 CET49764443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.815805912 CET49764443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.815820932 CET443497644.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.816457987 CET443497644.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.841897011 CET49765443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.841936111 CET443497654.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.842010021 CET49765443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.842325926 CET49765443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.842346907 CET443497654.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.842772961 CET443497654.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.886877060 CET49766443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.886915922 CET443497664.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.886981964 CET49766443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.887363911 CET49766443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.887378931 CET443497664.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.887799025 CET443497664.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.891438007 CET49767443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.891480923 CET443497674.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.891541958 CET49767443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.891825914 CET49767443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.891840935 CET443497674.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.892194033 CET443497674.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.915484905 CET49768443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.915574074 CET443497684.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.915705919 CET49768443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.916008949 CET49768443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.916042089 CET443497684.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.916418076 CET443497684.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.919295073 CET49769443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.919331074 CET443497694.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.919414997 CET49769443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.919692993 CET49769443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.919706106 CET443497694.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.920000076 CET443497694.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.938046932 CET49770443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.938071012 CET443497704.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.938142061 CET49770443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.940200090 CET49770443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.940210104 CET443497704.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.941018105 CET443497704.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.949218035 CET49771443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.949255943 CET443497714.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.950373888 CET49771443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.950683117 CET49771443192.168.2.54.245.163.56
      Mar 14, 2025 01:33:00.950695992 CET443497714.245.163.56192.168.2.5
      Mar 14, 2025 01:33:00.951051950 CET443497714.245.163.56192.168.2.5
      Mar 14, 2025 01:33:01.215626955 CET49772443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.215673923 CET44349772104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.215790033 CET49772443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.216115952 CET49773443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.216156960 CET44349773104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.216242075 CET49773443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.216941118 CET49772443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.216955900 CET44349772104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.217436075 CET49773443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.217451096 CET44349773104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.417464018 CET44349772104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.417949915 CET44349773104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.418375015 CET49774443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.418431044 CET44349774104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.418484926 CET49774443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.419013023 CET49775443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.419065952 CET44349775104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.419126034 CET49775443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.419610023 CET49774443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.419626951 CET44349774104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.420146942 CET49775443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:01.420175076 CET44349775104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.481086969 CET49776443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.481153011 CET443497762.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.481213093 CET49776443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.482651949 CET49776443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.482676029 CET443497762.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.483303070 CET443497762.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.483977079 CET49777443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.484030008 CET443497772.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.484091043 CET49777443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.486927032 CET49777443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.486942053 CET443497772.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.487283945 CET443497772.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.497013092 CET49778443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.497051954 CET443497782.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.497123003 CET49778443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.497644901 CET49778443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.497677088 CET443497782.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.497730970 CET49778443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.505371094 CET49779443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.505443096 CET443497792.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.505505085 CET49779443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.505842924 CET49779443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.505860090 CET443497792.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.506256104 CET443497792.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.507707119 CET49780443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.507733107 CET443497802.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.507781029 CET49780443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.508313894 CET49780443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.508321047 CET443497802.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.508665085 CET443497802.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.509134054 CET49781443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.509147882 CET443497812.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.509196997 CET49781443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.509299994 CET49781443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.509325981 CET443497812.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.509367943 CET49781443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.617708921 CET44349775104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.617752075 CET44349774104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:01.632139921 CET49782443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.632169008 CET443497822.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.632225037 CET49782443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.633956909 CET49782443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.633970976 CET443497822.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.634391069 CET443497822.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.635519028 CET49783443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.635545015 CET443497832.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.635601044 CET49783443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.638111115 CET49783443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.638120890 CET443497832.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.638442039 CET443497832.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.640703917 CET49784443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.640773058 CET443497842.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.640842915 CET49784443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.641201019 CET49784443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.641235113 CET443497842.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.641275883 CET49784443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.657737970 CET49785443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.657769918 CET443497852.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.658066988 CET49785443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.659765959 CET49785443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.659779072 CET443497852.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.660128117 CET443497852.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.661123991 CET49786443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.661151886 CET443497862.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.661205053 CET49786443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.661792040 CET49786443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.661806107 CET443497862.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.662101030 CET443497862.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.663197994 CET49787443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.663227081 CET443497872.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.663297892 CET49787443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.665955067 CET49787443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:01.665983915 CET443497872.19.122.58192.168.2.5
      Mar 14, 2025 01:33:01.666027069 CET49787443192.168.2.52.19.122.58
      Mar 14, 2025 01:33:06.424571037 CET49676443192.168.2.520.189.173.14
      Mar 14, 2025 01:33:09.837358952 CET49792443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.837362051 CET49793443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.837403059 CET44349792104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:09.837409019 CET44349793104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:09.837500095 CET49793443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.837501049 CET49792443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.837990046 CET49793443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.838007927 CET44349793104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:09.838320971 CET49792443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:09.838346958 CET44349792104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.037383080 CET44349793104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.037925005 CET44349792104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.038198948 CET49794443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.038244009 CET44349794104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.038461924 CET49795443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.038508892 CET44349795104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.038537979 CET49794443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.038645029 CET49795443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.038866997 CET49794443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.038902998 CET44349794104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.039271116 CET49795443192.168.2.5104.18.36.248
      Mar 14, 2025 01:33:10.039288044 CET44349795104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.237104893 CET44349795104.18.36.248192.168.2.5
      Mar 14, 2025 01:33:10.237689972 CET44349794104.18.36.248192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Mar 14, 2025 01:32:48.716408014 CET53528991.1.1.1192.168.2.5
      Mar 14, 2025 01:32:48.747823000 CET53635461.1.1.1192.168.2.5
      Mar 14, 2025 01:32:53.143471003 CET6412253192.168.2.51.1.1.1
      Mar 14, 2025 01:32:53.143630028 CET6494953192.168.2.51.1.1.1
      Mar 14, 2025 01:32:53.150134087 CET53641221.1.1.1192.168.2.5
      Mar 14, 2025 01:32:53.150325060 CET53649491.1.1.1192.168.2.5
      Mar 14, 2025 01:32:54.322449923 CET5718853192.168.2.51.1.1.1
      Mar 14, 2025 01:32:54.322700024 CET6232253192.168.2.51.1.1.1
      Mar 14, 2025 01:32:54.331640005 CET53571881.1.1.1192.168.2.5
      Mar 14, 2025 01:32:54.331926107 CET53623221.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Mar 14, 2025 01:32:53.143471003 CET192.168.2.51.1.1.10xd287Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Mar 14, 2025 01:32:53.143630028 CET192.168.2.51.1.1.10x331Standard query (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:32:54.322449923 CET192.168.2.51.1.1.10xb78fStandard query (0)mttamaskextsin.webflow.ioA (IP address)IN (0x0001)false
      Mar 14, 2025 01:32:54.322700024 CET192.168.2.51.1.1.10xaa3dStandard query (0)mttamaskextsin.webflow.io65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Mar 14, 2025 01:32:53.150134087 CET1.1.1.1192.168.2.50xd287No error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
      Mar 14, 2025 01:32:53.150325060 CET1.1.1.1192.168.2.50x331No error (0)www.google.com65IN (0x0001)false
      Mar 14, 2025 01:32:54.331640005 CET1.1.1.1192.168.2.50xb78fNo error (0)mttamaskextsin.webflow.io104.18.36.248A (IP address)IN (0x0001)false
      Mar 14, 2025 01:32:54.331640005 CET1.1.1.1192.168.2.50xb78fNo error (0)mttamaskextsin.webflow.io172.64.151.8A (IP address)IN (0x0001)false
      Mar 14, 2025 01:32:54.331926107 CET1.1.1.1192.168.2.50xaa3dNo error (0)mttamaskextsin.webflow.io65IN (0x0001)false
      • c.pki.goog
      Session IDSource IPSource PortDestination IPDestination Port
      0192.168.2.549708142.250.184.22780
      TimestampBytes transferredDirectionData
      Mar 14, 2025 01:32:38.174830914 CET223INHTTP/1.1 304 Not Modified
      Date: Fri, 14 Mar 2025 00:06:03 GMT
      Expires: Fri, 14 Mar 2025 00:56:03 GMT
      Last-Modified: Tue, 07 Jan 2025 07:28:00 GMT
      Cache-Control: public, max-age=3000
      Vary: Accept-Encoding
      Age: 1595
      Mar 14, 2025 01:32:38.179186106 CET200OUTGET /r/r4.crl HTTP/1.1
      Cache-Control: max-age = 3000
      Connection: Keep-Alive
      Accept: */*
      If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
      User-Agent: Microsoft-CryptoAPI/10.0
      Host: c.pki.goog
      Mar 14, 2025 01:32:38.360898018 CET223INHTTP/1.1 304 Not Modified
      Date: Fri, 14 Mar 2025 00:05:53 GMT
      Expires: Fri, 14 Mar 2025 00:55:53 GMT
      Last-Modified: Thu, 25 Jul 2024 14:48:00 GMT
      Cache-Control: public, max-age=3000
      Vary: Accept-Encoding
      Age: 1605


      01020s020406080100

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:20:32:42
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff6834a0000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:20:32:47
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2200 /prefetch:3
      Imagebase:0x7ff6834a0000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:8
      Start time:20:32:50
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2172,i,10161938508426344168,16679010280242023607,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4368 /prefetch:8
      Imagebase:0x7ff6834a0000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:11
      Start time:20:32:53
      Start date:13/03/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mttamaskextsin.webflow.io/"
      Imagebase:0x7ff6834a0000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

      No disassembly