Edit tour

Windows Analysis Report
https://gyuemineilogin.webflow.io/

Overview

General Information

Sample URL:https://gyuemineilogin.webflow.io/
Analysis ID:1637956
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6788 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2080 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3008 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7732 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gyuemineilogin.webflow.io/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://gyuemineilogin.webflow.io/Avira URL Cloud: detection malicious, Label: phishing
Source: global trafficTCP traffic: 192.168.2.5:52946 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.35.26
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.35.26
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.35.26
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.77.188
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.16
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: gyuemineilogin.webflow.io
Source: global trafficDNS traffic detected: DNS query: 206.23.85.13.in-addr.arpa
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: classification engineClassification label: mal48.win@23/0@5/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3008 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gyuemineilogin.webflow.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3008 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1637956 URL: https://gyuemineilogin.webf... Startdate: 14/03/2025 Architecture: WINDOWS Score: 48 17 206.23.85.13.in-addr.arpa 2->17 25 Antivirus / Scanner detection for submitted sample 2->25 7 chrome.exe 2->7         started        10 chrome.exe 2->10         started        signatures3 process4 dnsIp5 19 192.168.2.5, 443, 49399, 49717 unknown unknown 7->19 12 chrome.exe 7->12         started        15 chrome.exe 7->15         started        process6 dnsIp7 21 www.google.com 142.250.203.132, 443, 49746, 49747 GOOGLEUS United States 12->21 23 gyuemineilogin.webflow.io 104.18.36.248, 443, 49750, 49751 CLOUDFLARENETUS United States 12->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://gyuemineilogin.webflow.io/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
gyuemineilogin.webflow.io
104.18.36.248
truefalse
    unknown
    www.google.com
    142.250.203.132
    truefalse
      high
      206.23.85.13.in-addr.arpa
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        104.18.36.248
        gyuemineilogin.webflow.ioUnited States
        13335CLOUDFLARENETUSfalse
        142.250.203.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1637956
        Start date and time:2025-03-14 01:33:55 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 1m 57s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://gyuemineilogin.webflow.io/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:10
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@23/0@5/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, backgroundTaskHost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 23.60.203.209, 74.125.206.84, 142.250.186.174, 142.250.186.131, 142.250.184.206
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://gyuemineilogin.webflow.io/
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 168
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Mar 14, 2025 01:34:42.994678020 CET49700443192.168.2.520.223.35.26
        Mar 14, 2025 01:34:42.994679928 CET49698443192.168.2.520.223.35.26
        Mar 14, 2025 01:34:42.994682074 CET49699443192.168.2.520.223.35.26
        Mar 14, 2025 01:34:42.994770050 CET4970480192.168.2.5199.232.214.172
        Mar 14, 2025 01:34:42.994896889 CET4970580192.168.2.5199.232.214.172
        Mar 14, 2025 01:34:42.994990110 CET4970680192.168.2.52.23.77.188
        Mar 14, 2025 01:34:43.096040010 CET49717443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.096081972 CET443497172.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.096194983 CET49717443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.096517086 CET49717443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.096532106 CET443497172.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.097240925 CET443497172.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.097656965 CET49718443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.097701073 CET443497182.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.097774029 CET49718443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.097980022 CET49718443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.097996950 CET443497182.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.098452091 CET443497182.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.098822117 CET49719443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.098882914 CET443497192.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.098958015 CET49719443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.099016905 CET49719443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.099045038 CET443497192.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.099096060 CET49719443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.112399101 CET49720443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.112431049 CET443497202.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.112545967 CET49720443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.112840891 CET49720443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.112852097 CET443497202.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.113501072 CET443497202.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.113873959 CET49721443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.113925934 CET443497212.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.113985062 CET49721443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.114176035 CET49721443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.114187002 CET443497212.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.114661932 CET443497212.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.114972115 CET49722443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.115005970 CET443497222.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.115063906 CET49722443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.115115881 CET49722443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:43.115140915 CET443497222.19.122.16192.168.2.5
        Mar 14, 2025 01:34:43.115185976 CET49722443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:45.913568020 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:46.225085974 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:46.850100994 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:46.881304979 CET49672443192.168.2.5204.79.197.203
        Mar 14, 2025 01:34:48.053186893 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:50.459470987 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:52.982506990 CET49730443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.982559919 CET443497302.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.982671976 CET49730443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.989938974 CET49730443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.989954948 CET443497302.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.990643024 CET443497302.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.990672112 CET49731443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.990705967 CET443497312.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.991693974 CET49731443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.996025085 CET49732443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.996063948 CET443497322.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.996268988 CET49732443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.997028112 CET49732443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.997029066 CET49731443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:52.997041941 CET443497322.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.997056007 CET443497312.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.997545004 CET443497312.19.122.16192.168.2.5
        Mar 14, 2025 01:34:52.997824907 CET443497322.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.016556978 CET49734443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.016607046 CET443497342.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.016809940 CET49734443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.017071962 CET49734443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.017112017 CET443497342.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.017435074 CET49734443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.019809961 CET49736443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.019860983 CET443497362.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.020201921 CET49736443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.020201921 CET49736443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.020246029 CET443497362.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.020906925 CET443497362.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.021284103 CET49737443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.021318913 CET443497372.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.021542072 CET49737443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.021542072 CET49737443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:53.021619081 CET443497372.19.122.16192.168.2.5
        Mar 14, 2025 01:34:53.021739006 CET49737443192.168.2.52.19.122.16
        Mar 14, 2025 01:34:55.272839069 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:34:56.490652084 CET49672443192.168.2.5204.79.197.203
        Mar 14, 2025 01:34:57.016736031 CET49746443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.016765118 CET44349746142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:57.016896963 CET49746443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.017194033 CET49746443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.017205000 CET44349746142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:57.217530966 CET44349746142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:57.218228102 CET49747443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.218269110 CET44349747142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:57.218383074 CET49747443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.218734026 CET49747443192.168.2.5142.250.203.132
        Mar 14, 2025 01:34:57.218750954 CET44349747142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:57.417172909 CET44349747142.250.203.132192.168.2.5
        Mar 14, 2025 01:34:58.737732887 CET49750443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.737777948 CET44349750104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.737895012 CET49751443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.737941980 CET44349751104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.737950087 CET49750443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.738037109 CET49751443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.738554001 CET49750443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.738569975 CET44349750104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.738962889 CET49751443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.738981009 CET44349751104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.937731028 CET44349750104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.938277006 CET49752443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.938335896 CET44349752104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.938380957 CET44349751104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.938417912 CET49752443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.938869953 CET49753443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.938924074 CET44349753104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.938982010 CET49753443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.939299107 CET49752443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.939327002 CET44349752104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:58.939511061 CET49753443192.168.2.5104.18.36.248
        Mar 14, 2025 01:34:58.939532042 CET44349753104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:59.137850046 CET44349752104.18.36.248192.168.2.5
        Mar 14, 2025 01:34:59.138830900 CET44349753104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.204008102 CET49757443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.204108000 CET44349757104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.204222918 CET49757443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.205301046 CET49757443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.205338001 CET44349757104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.206532001 CET49758443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.206568956 CET44349758104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.206656933 CET49758443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.207551003 CET49758443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.207566023 CET44349758104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.405230999 CET44349757104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.405344009 CET44349758104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.407207966 CET49759443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.407253027 CET44349759104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.407322884 CET49759443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.407521963 CET49760443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.407529116 CET44349760104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.407569885 CET49760443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.407887936 CET49759443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.407901049 CET44349759104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.408163071 CET49760443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:00.408169031 CET44349760104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.605572939 CET44349759104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:00.605995893 CET44349760104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:01.533013105 CET49761443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.533066988 CET44349761142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:01.533165932 CET49761443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.533783913 CET49761443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.533801079 CET44349761142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:01.737725973 CET44349761142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:01.738301039 CET49762443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.738348007 CET44349762142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:01.738483906 CET49762443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.738862038 CET49762443192.168.2.5142.250.203.132
        Mar 14, 2025 01:35:01.738874912 CET44349762142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:01.937803030 CET44349762142.250.203.132192.168.2.5
        Mar 14, 2025 01:35:04.884226084 CET49676443192.168.2.520.189.173.14
        Mar 14, 2025 01:35:05.174232960 CET49763443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.174273968 CET44349763172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.174526930 CET49763443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.177458048 CET49763443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.177470922 CET44349763172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.178047895 CET44349763172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.234391928 CET49764443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.234431982 CET44349764172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.234519005 CET49764443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.235277891 CET49764443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.235299110 CET44349764172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.235836983 CET44349764172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.507006884 CET49765443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.507052898 CET44349765172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.507180929 CET49765443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.507814884 CET49765443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.507826090 CET44349765172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.508440018 CET44349765172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.569866896 CET49766443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.569906950 CET44349766172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.570041895 CET49766443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.570535898 CET49766443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.570552111 CET44349766172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.571160078 CET44349766172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.692374945 CET49768443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.692424059 CET44349768104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.692656040 CET49768443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.693583965 CET49769443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.693584919 CET49768443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.693602085 CET44349768104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.693624973 CET44349769104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.693727970 CET49769443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.694164991 CET49769443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.694183111 CET44349769104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.781992912 CET49770443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.782048941 CET44349770172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.782116890 CET49770443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.782644987 CET49770443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.782660961 CET44349770172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.783572912 CET44349770172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.812545061 CET49771443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.812588930 CET443497712.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.812675953 CET49771443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.817677021 CET49772443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.817728996 CET44349772172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.817804098 CET49772443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.818216085 CET49772443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.818229914 CET44349772172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.818492889 CET49771443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.818516970 CET443497712.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.818825006 CET44349772172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.819154978 CET443497712.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.823756933 CET49773443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.823784113 CET443497732.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.823843956 CET49773443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.830935955 CET49773443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.830951929 CET443497732.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.831686974 CET443497732.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.833905935 CET49774443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.833931923 CET443497742.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.833997965 CET49774443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.834512949 CET49774443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.834554911 CET443497742.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.834608078 CET49774443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.872200966 CET49775443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.872242928 CET443497752.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.872315884 CET49775443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.873433113 CET49776443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.873452902 CET44349776172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.873511076 CET49776443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.873924971 CET49776443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.873936892 CET44349776172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.874566078 CET44349776172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.874731064 CET49775443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.874758005 CET443497752.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.875488997 CET443497752.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.876096010 CET49777443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.876123905 CET443497772.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.876190901 CET49777443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.879225969 CET49777443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.879239082 CET443497772.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.879789114 CET443497772.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.880692959 CET49778443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.880724907 CET443497782.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.880788088 CET49778443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.884380102 CET49778443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.884426117 CET443497782.19.122.16192.168.2.5
        Mar 14, 2025 01:35:05.884480000 CET49778443192.168.2.52.19.122.16
        Mar 14, 2025 01:35:05.893064022 CET44349769104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.893768072 CET44349768104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.896028042 CET49779443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.896063089 CET44349779104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.896130085 CET49779443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.896651030 CET49781443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.896682978 CET44349781104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.896739960 CET49781443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.897053003 CET49779443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.897066116 CET44349779104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.899322033 CET49781443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:05.899348021 CET44349781104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:05.934217930 CET49782443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.934253931 CET44349782172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.934322119 CET49782443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.934719086 CET49782443192.168.2.5172.202.163.200
        Mar 14, 2025 01:35:05.934734106 CET44349782172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:05.935520887 CET44349782172.202.163.200192.168.2.5
        Mar 14, 2025 01:35:06.097563028 CET44349781104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:06.097580910 CET44349779104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.482932091 CET49785443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.482940912 CET49786443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.482976913 CET44349786104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.482976913 CET44349785104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.483071089 CET49785443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.483081102 CET49786443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.483637094 CET49785443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.483639956 CET49786443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.483656883 CET44349786104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.483660936 CET44349785104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.681540966 CET44349785104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.681668997 CET44349786104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.682158947 CET49787443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.682203054 CET44349787104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.682435989 CET49787443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.682714939 CET49788443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.682748079 CET44349788104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.682957888 CET49787443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.682972908 CET44349787104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.683000088 CET49788443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.683239937 CET49788443192.168.2.5104.18.36.248
        Mar 14, 2025 01:35:13.683254957 CET44349788104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.881359100 CET44349788104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:13.882462025 CET44349787104.18.36.248192.168.2.5
        Mar 14, 2025 01:35:19.014550924 CET5294653192.168.2.5162.159.36.2
        Mar 14, 2025 01:35:19.019267082 CET5352946162.159.36.2192.168.2.5
        Mar 14, 2025 01:35:19.019365072 CET5294653192.168.2.5162.159.36.2
        Mar 14, 2025 01:35:19.024091959 CET5352946162.159.36.2192.168.2.5
        Mar 14, 2025 01:35:19.468241930 CET5294653192.168.2.5162.159.36.2
        Mar 14, 2025 01:35:19.473078966 CET5352946162.159.36.2192.168.2.5
        Mar 14, 2025 01:35:19.473130941 CET5294653192.168.2.5162.159.36.2
        TimestampSource PortDest PortSource IPDest IP
        Mar 14, 2025 01:34:52.763139963 CET53493991.1.1.1192.168.2.5
        Mar 14, 2025 01:34:52.770698071 CET53563211.1.1.1192.168.2.5
        Mar 14, 2025 01:34:57.009001017 CET5388753192.168.2.51.1.1.1
        Mar 14, 2025 01:34:57.009212017 CET5253253192.168.2.51.1.1.1
        Mar 14, 2025 01:34:57.015722990 CET53538871.1.1.1192.168.2.5
        Mar 14, 2025 01:34:57.015739918 CET53525321.1.1.1192.168.2.5
        Mar 14, 2025 01:34:58.725212097 CET5712953192.168.2.51.1.1.1
        Mar 14, 2025 01:34:58.725451946 CET5842153192.168.2.51.1.1.1
        Mar 14, 2025 01:34:58.734419107 CET53571291.1.1.1192.168.2.5
        Mar 14, 2025 01:34:58.735449076 CET53584211.1.1.1192.168.2.5
        Mar 14, 2025 01:35:19.014141083 CET5354250162.159.36.2192.168.2.5
        Mar 14, 2025 01:35:19.469753981 CET5988253192.168.2.51.1.1.1
        Mar 14, 2025 01:35:19.477880955 CET53598821.1.1.1192.168.2.5
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 14, 2025 01:34:57.009001017 CET192.168.2.51.1.1.10x139bStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 14, 2025 01:34:57.009212017 CET192.168.2.51.1.1.10xd592Standard query (0)www.google.com65IN (0x0001)false
        Mar 14, 2025 01:34:58.725212097 CET192.168.2.51.1.1.10xfb57Standard query (0)gyuemineilogin.webflow.ioA (IP address)IN (0x0001)false
        Mar 14, 2025 01:34:58.725451946 CET192.168.2.51.1.1.10xf8c2Standard query (0)gyuemineilogin.webflow.io65IN (0x0001)false
        Mar 14, 2025 01:35:19.469753981 CET192.168.2.51.1.1.10x57caStandard query (0)206.23.85.13.in-addr.arpaPTR (Pointer record)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 14, 2025 01:34:57.015722990 CET1.1.1.1192.168.2.50x139bNo error (0)www.google.com142.250.203.132A (IP address)IN (0x0001)false
        Mar 14, 2025 01:34:57.015739918 CET1.1.1.1192.168.2.50xd592No error (0)www.google.com65IN (0x0001)false
        Mar 14, 2025 01:34:58.734419107 CET1.1.1.1192.168.2.50xfb57No error (0)gyuemineilogin.webflow.io104.18.36.248A (IP address)IN (0x0001)false
        Mar 14, 2025 01:34:58.734419107 CET1.1.1.1192.168.2.50xfb57No error (0)gyuemineilogin.webflow.io172.64.151.8A (IP address)IN (0x0001)false
        Mar 14, 2025 01:34:58.735449076 CET1.1.1.1192.168.2.50xf8c2No error (0)gyuemineilogin.webflow.io65IN (0x0001)false
        Mar 14, 2025 01:35:19.477880955 CET1.1.1.1192.168.2.50x57caName error (3)206.23.85.13.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
        01020s020406080100

        Click to jump to process

        Click to jump to process

        Target ID:2
        Start time:20:34:47
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff69d3b0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:20:34:51
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
        Imagebase:0x7ff69d3b0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:20:34:54
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,7379194039290633691,10512156184939331069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3008 /prefetch:8
        Imagebase:0x7ff69d3b0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:7
        Start time:20:34:57
        Start date:13/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gyuemineilogin.webflow.io/"
        Imagebase:0x7ff69d3b0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly