Windows Analysis Report
https://protect.checkpoint.com/v2/r02/___https://lsems.gravityzone.bitdefender.com/xhfsdfMW5hMR*~*QDcqg1KugH/rhrqqgrWni2pyg1KugH/og75AgMRA37Cu37x!i2GzU2ZBRIJzQYOHZZqqYsmZW5OR00KOX83/48p8j0J8ZqF5gYq/X5p/4JhyRpOG1IqMhIh5WIqxR6iX1YmuV1mTfLuz38uCWp/KRqiVYoq5hZbCTIh/4MqE1rinfpmCiY0KZ8i*~*QYOHf1mO48i1RIOf

Overview

General Information

Sample URL: https://protect.checkpoint.com/v2/r02/___https://lsems.gravityzone.bitdefender.com/xhfsdfMW5hMR*~*QDcqg1KugH/rhrqqgrWni2pyg1KugH/og75AgMRA37Cu37x!i2GzU2ZBRIJzQYOHZZqqYsmZW5OR00KOX83/48p8j0J8ZqF5gYq/X5
Analysis ID: 1649540
Infos:

Detection

Score: 2
Range: 0 - 100
Confidence: 80%

Signatures

Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected suspicious crossdomain redirect
Sample execution stops while process was sleeping (likely an evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Source: unknown HTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.168.102.96:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.168.102.96:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.64:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.64:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.68:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.19:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.49:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.173.132.30:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.173.132.30:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: protect.checkpoint.com to https://lsems.gravityzone.bitdefender.com/scan/ahr0chm6ly9lbwfpbc5mcmllbmridxktbwfpbc5jb20vbhmvy2xpy2s!dxbupxuwmdeultjcuulltnhur0jmvvfjs3y5z3k3eve3ula0btl5s0k5zectmkjbwdlhcdc0rdlsm1dswthpqwhoagpuy3pxrk5fmldqtjl0cu8xodc5zhlzwmdiakhxdtvfu3d6ltjcawhjz3dwmdjaclbxeglfrwhksvnkntfsm2u1tnfjb2lqb2hxmddvufetmkj3rko1oxpnzmnos01voen4yujctljrvfvqug1sznotmkjpode3vznwmerpmvp6u1vqu0fqcgzcv09rdkv1otnyq3k5uwf2cy0yrjvivmh0ufdgegxtb3biqs0yqnzlrgw1bdhoy0tmswtddknbumplmdetmkjlrmpuawpwvjlhulnssvatmkj6qkx3bffqa3zirtm2dxpzd3bjbnmtmkjvy0p1ntdkannud1rknfpez2i3zxq5ynnkv3ptawlld1vhaw5aumfdnk5wulrctutoddhysk40akljs1llttdlcxzxntflagnmqkp5t2xpt203nxjzrwhhymi1cg5zowiztjg4dfrerkn6cfnfd2jkvzjut0tmrjitmkitmkzqvxbyztzwwul3ltjcsnbowtk1dxr4qtd0n2v4vw9pbgwtmkjpenhzu1zinupjvvvxrexfoxuxltjgtuflv1lczvrsdth3mxlyzkpjsnnomdvnltjcamvuv2xkexfwevdrndb1uhdbuzjtz1v4wlhurg9nzu9hujhbrmnot3duznltmlnmukh0dhjsz0w0ovrcq2phmuiwbxpds3jmckhkwtvzv2pqnk5ssdzjrxnxr3bxwk5fdwhtcvv0zzndak1ibmjtretyd0wtmkj3rnbabnfrbkfenzrvevvgbuwxmznksda3bjjselbfbw1rajj6ethsu0pkz0zhszzmxzrwawhiewdou0iwcjlszlcwzdq0t1bydmnbzjd6dnbjrmhkwvzjvhhsry0yqlzpdtdxd081celpswprbln5ykr1uu55sdfka2nhtks0ujitmkzybnnangppd3poq0pzu0zzblnlznrorujaclbtzu8tmkixstvomfr6ewffb3v0rek2ewnrsktoeupnmmfhvjatmkzyqi0yri0yrmlfwuy0cwntm3h3s1vazjnqsxneu3itmkjevetyrxd5c2wwvgxvnfl3bta3swvyy0dr/744f42f112f962f17ada5ee8ed50836e04d0c23a8c389560f7654fcdfe5c922f?c=1&i=1&docs=1
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: email.friendbuy-mail.com to https://394-kadoma.trakcid.com/?u=http:%2f%2femail.double.serviceautopilot.com%2fc%2fejwewdtuxcaqandtma6lz8baqzhg9waziyphxwlzlzlt553jfvlrt9wuc2nxrgqh7srezziyvat1tgwosvbaurp7aiixldsccdz5dilu3hqryyuixeysi1dbaihlkiotubgtw82eik6ucrgcrryxqiloomx05cbh5ytn0zjrxilrqkps2u0aifamkrazv4wbqdo-pdp-pvltj-xpgk_ry-3nuevp11rpe7m_mzk2c_yncu_67u38boyyzjs5ju3xuruy6bxme6_xxdt33ht-badmm8e-6lzen5n_aaaa__97vled&e=bo6ao4ijqeteqbsfkxxaarisjwux2-yy&cee=y2hyaxn0b3bozxiuywxsyw5acnbyby50zwno
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: email.friendbuy-mail.com to https://394-kadoma.trakcid.com/?u=http:%2f%2femail.double.serviceautopilot.com%2fc%2fejwewdtuxcaqandtma6lz8baqzhg9waziyphxwlzlzlt553jfvlrt9wuc2nxrgqh7srezziyvat1tgwosvbaurp7aiixldsccdz5dilu3hqryyuixeysi1dbaihlkiotubgtw82eik6ucrgcrryxqiloomx05cbh5ytn0zjrxilrqkps2u0aifamkrazv4wbqdo-pdp-pvltj-xpgk_ry-3nuevp11rpe7m_mzk2c_yncu_67u38boyyzjs5ju3xuruy6bxme6_xxdt33ht-badmm8e-6lzen5n_aaaa__97vled&e=bo6ao4ijqeteqbsfkxxaarisjwux2-yy&cee=y2hyaxn0b3bozxiuywxsyw5acnbyby50zwno
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknown TCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknown TCP traffic detected without corresponding DNS query: 23.57.90.144
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /v2/r02/___https://lsems.gravityzone.bitdefender.com/xhfsdfMW5hMR*~*QDcqg1KugH/rhrqqgrWni2pyg1KugH/og75AgMRA37Cu37x!i2GzU2ZBRIJzQYOHZZqqYsmZW5OR00KOX83/48p8j0J8ZqF5gYq/X5p/4JhyRpOG1IqMhIh5WIqxR6iX1YmuV1mTfLuz38uCWp/KRqiVYoq5hZbCTIh/4MqE1rinfpmCiY0KZ8i*~*QYOHf1mO48i1RIOfhqGCjLqKW1mPX0SpSYKxR7Z6YsKOg7qvg7m2RIiAZKJyRpO8Wpt6T2uS4rSTX560TJS93ZOHYqOw0K0vZL6x4styRpOuTIJ80ES1RJWuR0u*~*Z60vZ5KvhL4H05cwip06TYSDV8p/Z1K7hD5DWo0n0rm5ZKiLjLCyg8GNVX5DVs4QWLB6gImt35yRX1yIipSGZruqRIJyRpOQWruzf1uB0oqmZqSXX0FyRpO*~*VpC8gKKvf84NWYR7i2uEi8GogsRyRpOA35u6SYipfsSZi6WpSKuJ47N842V/3sSp08uyf1qqi60Mf1/fZrKISp/BZqWHYZytiIm3Xp95fpqOX6qqYYiqh24CSYKqfLSRVpu/Y7CUY758S2O4W1mm3rN6hL/4T1NEYol9iKWJWpS*~*hKSKi7Op0EOZY5yrWoNyRpNyRp4V02G34Y4B1Zq8QYOHXsGt1Yp6i2W9VYi5S70901cUgLByRpOUjsmEZ64nSZuO0002WJCKT2ZCQYOLYZKq06qH40WxiYm8R2q34puoXsStRI0SQYOHfr0z07Cpj2KBj0iWSIG6ZMiGZEOY46091qmZWLcS4ZcmZomGWrStY8iz4sqyRqSrZpm5iMOX45B5T0WHV7umRZNBg2uIX8ORhpmP1Y0407uVSp/XXI4OW2SCW8G21p/Ki1myh0054ESIfp6NgrOyWJyDi5ByRpO8WsGfgsKWgpKJSEW0j00LgZBCRESPXIF8goOxjqGKg16WfoO*~*jYmXZ5up454mXE4R2EWBf1mNj1iTZ5NBhoqX4qhB4IV5Y6G3irSG4oi*~*isGOWrmP104O0MmXWD5DVq4uiYi2i5b6hJqUX1uWgqS/3pW6ZZ*/2*XIKpf7SMYpx5ZoNyRp43gsSfSLuUi8utV5u4Z544gqSq4sWtWZOfhqGY4ZbyRpNCXY0tRKW*~*j1KKg805WJp7j1SwXpyTjZuSRrKm0oFyRp43Vn5DWn5DWrqK1Z35h1SyR8m8X60f4oSvX2SJZ8NyRpOJ0JyDW2i/h7BB0LC0SKq8gYF8X10335iWda99K97K667Kc*~*7K6aFIF/JJbJI/5b8*~*J59I5H78FbH8bc/*~*5Ka*~*/9KHIKJ/Hc77K?h=6&fru;n=6&fru;ithx=6___.YzJlOmdhbmdzdGVyOmM6bzozNzgzODlmOGVjOWFjMDU4ODA2YzZiNzAzODIwZWExYjo3OjE1MzU6MzgzZDA3MjA0MGU4NmVjOTQ5NjUyYWM1MTBkYzkzNzg4ODQ3Mjg0YTJlN2I1MzhlZWM4YWU1YzI1YWE5Y2UxNjpoOlQ6VA HTTP/1.1Host: protect.checkpoint.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1 HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /index.css HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://lsems.gravityzone.bitdefender.com/scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/css/main.3dfe9f5e.css HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://lsems.gravityzone.bitdefender.com/scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /static/js/main.d62e4927.js HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://lsems.gravityzone.bitdefender.com/scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://lsems.gravityzone.bitdefender.com/scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /manifest.json HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: manifestReferer: https://lsems.gravityzone.bitdefender.com/scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?c=1&i=1&docs=1Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lsems.gravityzone.bitdefender.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?i=0&docs=1&s=1 HTTP/1.1Host: api-bd.linkscan.ioConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: application/json, text/plain, */*sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"X-Original-Referer: unknownsec-ch-ua-mobile: ?0Origin: https://lsems.gravityzone.bitdefender.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://lsems.gravityzone.bitdefender.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scan/aHR0cHM6Ly9lbWFpbC5mcmllbmRidXktbWFpbC5jb20vbHMvY2xpY2s!dXBuPXUwMDEuLTJCUUllTnhUR0JMVVFJS3Y5Z3k3eVE3UlA0bTl5S0k5ZEctMkJBWDlHcDc0RDlsM1dSWThpQWhOaGpuY3pxRk5FMldQTjl0cU8xODc5ZHlzWmdiakhxdTVFU3d6LTJCaWhJZ3dWMDJaclBxeGlFRWhKSVNkNTFsM2U1TnFJb2lqb2hXMDdvUFEtMkJ3Rko1OXpNZmNOS01VOEN4YUJCTlJrVFVqUG1sZnotMkJpODE3VzNWMERpMVp6U1VqU0FqcGZCV09rdkV1OTNyQ3k5UWF2cy0yRjViVmh0UFdGeGxtb3BIQS0yQnZLRGw1bDhoY0tMSWtDdkNBUmplMDEtMkJLRmpuaWpwVjlhUlNSSVAtMkJ6Qkx3bFFqa3ZIRTM2dXpzd3BjbnMtMkJvY0p1NTdkanNUd1RkNFpEZ2I3ZXQ5YnNkV3ptaWlld1VHaW5aUmFDNk5wUlRCTUtodDhYSk40aklJS1llTTdlcXZxNTFlaGNMQkp5T2xPT203NXJZRWhhYmI1cG5ZOWIzTjg4dFRERkN6cFNFd2JkVzJUT0tmRjItMkItMkZQVXBYZTZwWUl3LTJCSnBoWTk1dXR4QTd0N2V4VW9PbGwtMkJPenhzU1ZiNUpJVVVXRExFOXUxLTJGTUFlV1lCZVRsdTh3MXlYZkpjSnNoMDVNLTJCamVuV2xkeXFweVdRNDB1UHdBUzJTZ1V4WlhURG9NZU9hUjhBRmNoT3duZnltMlNmUkh0dHJSZ0w0OVRCQ2phMUIwbXpDS3JMckhKWTVZV2pQNk5SSDZJRXNxR3BXWk5FdWhtcVV0ZzNDak1IbmJtREtyd0wtMkJ3RnBabnFRbkFENzRVeVVGbUwxMzNKSDA3bjJselBFbW1RajJ6eThSU0pkZ0ZhSzZMXzRwaWhIeWdOU0IwcjlSZlcwZDQ0T1BYdmNBZjd6dnBJRmhKWVZJVHhSRy0yQlZpdTdXd081cElPSWpRblN5YkR1UU55SDFka2NHTks0UjItMkZYbnNaNGpPd3poQ0pZU0ZZblNlZnRoRUJaclBTZU8tMkIxSTVoMFR6eWFFb3V0REk2eWNrSktOeUpNMmFhVjAtMkZYQi0yRi0yRmlFWUY0cWNtM3h3S1VaZjNqSXNEU3ItMkJEVEtyRXd5c2wwVGxVNFl3bTA3SWVYY0dR/744F42F112F962F17ADA5EE8ED50836E04D0C23A8C389560F7654FCDFE5C922F?i=0&docs=1&s=1 HTTP/1.1Host: api-bd.linkscan.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ls/click?upn=u001.-2BQIeNxTGBLUQIKv9gy7yQ7RP4m9yKI9dG-2BAX9Gp74D9l3WRY8iAhNhjnczqFNE2WPN9tqO1879dysZgbjHqu5ESwz-2BihIgwV02ZrPqxiEEhJISd51l3e5NqIoijohW07oPQ-2BwFJ59zMfcNKMU8CxaBBNRkTUjPmlfz-2Bi817W3V0Di1ZzSUjSAjpfBWOkvEu93rCy9Qavs-2F5bVhtPWFxlmopHA-2BvKDl5l8hcKLIkCvCARje01-2BKFjnijpV9aRSRIP-2BzBLwlQjkvHE36uzswpcns-2BocJu57djsTwTd4ZDgb7et9bsdWzmiiewUGinZRaC6NpRTBMKht8XJN4jIIKYeM7eqvq51ehcLBJyOlOOm75rYEhabb5pnY9b3N88tTDFCzpSEwbdW2TOKfF2-2B-2FPUpXe6pYIw-2BJphY95utxA7t7exUoOll-2BOzxsSVb5JIUUWDLE9u1-2FMAeWYBeTlu8w1yXfJcJsh05M-2BjenWldyqpyWQ40uPwAS2SgUxZXTDoMeOaR8AFchOwnfym2SfRHttrRgL49TBCja1B0mzCKrLrHJY5YWjP6NRH6IEsqGpWZNEuhmqUtg3CjMHnbmDKrwL-2BwFpZnqQnAD74UyUFmL133JH07n2lzPEmmQj2zy8RSJdgFaK6L_4pihHygNSB0r9RfW0d44OPXvcAf7zvpIFhJYVITxRG-2BViu7WwO5pIOIjQnSybDuQNyH1dkcGNK4R2-2FXnsZ4jOwzhCJYSFYnSefthEBZrPSeO-2B1I5h0TzyaEoutDI6yckJKNyJM2aaV0-2FXB-2F-2FiEYF4qcm3xwKUZf3jIsDSr-2BDTKrEwysl0TlU4Ywm07IeXcGQ HTTP/1.1Host: email.friendbuy-mail.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://lsems.gravityzone.bitdefender.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ls/click?upn=u001.-2BQIeNxTGBLUQIKv9gy7yQ7RP4m9yKI9dG-2BAX9Gp74D9l3WRY8iAhNhjnczqFNE2WPN9tqO1879dysZgbjHqu5ESwz-2BihIgwV02ZrPqxiEEhJISd51l3e5NqIoijohW07oPQ-2BwFJ59zMfcNKMU8CxaBBNRkTUjPmlfz-2Bi817W3V0Di1ZzSUjSAjpfBWOkvEu93rCy9Qavs-2F5bVhtPWFxlmopHA-2BvKDl5l8hcKLIkCvCARje01-2BKFjnijpV9aRSRIP-2BzBLwlQjkvHE36uzswpcns-2BocJu57djsTwTd4ZDgb7et9bsdWzmiiewUGinZRaC6NpRTBMKht8XJN4jIIKYeM7eqvq51ehcLBJyOlOOm75rYEhabb5pnY9b3N88tTDFCzpSEwbdW2TOKfF2-2B-2FPUpXe6pYIw-2BJphY95utxA7t7exUoOll-2BOzxsSVb5JIUUWDLE9u1-2FMAeWYBeTlu8w1yXfJcJsh05M-2BjenWldyqpyWQ40uPwAS2SgUxZXTDoMeOaR8AFchOwnfym2SfRHttrRgL49TBCja1B0mzCKrLrHJY5YWjP6NRH6IEsqGpWZNEuhmqUtg3CjMHnbmDKrwL-2BwFpZnqQnAD74UyUFmL133JH07n2lzPEmmQj2zy8RSJdgFaK6L_4pihHygNSB0r9RfW0d44OPXvcAf7zvpIFhJYVITxRG-2BViu7WwO5pIOIjQnSybDuQNyH1dkcGNK4R2-2FXnsZ4jOwzhCJYSFYnSefthEBZrPSeO-2B1I5h0TzyaEoutDI6yckJKNyJM2aaV0-2FXB-2F-2FiEYF4qcm3xwKUZf3jIsDSr-2BDTKrEwysl0TlU4Ywm07IeXcGQ HTTP/1.1Host: email.friendbuy-mail.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://lsems.gravityzone.bitdefender.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: protect.checkpoint.com
Source: global traffic DNS traffic detected: DNS query: lsems.gravityzone.bitdefender.com
Source: global traffic DNS traffic detected: DNS query: api-bd.linkscan.io
Source: global traffic DNS traffic detected: DNS query: email.friendbuy-mail.com
Source: global traffic DNS traffic detected: DNS query: 394-kadoma.trakcid.com
Source: global traffic DNS traffic detected: DNS query: google.com
Source: chromecache_64.2.dr String found in binary or memory: https://394-kadoma.trakcid.com/?u=http:%2F%2Femail.double.serviceautopilot.com%2Fc%2FeJwEwDtuxCAQAND
Source: chromecache_64.2.dr String found in binary or memory: https://email.friendbuy-mail.com/ls/click?upn=u001.-2BQIeNxTGBLUQIKv9gy7yQ7RP4m9yKI9dG-2BAX9Gp74D9l3
Source: chromecache_63.2.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Montserrat:100
Source: chromecache_63.2.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Raleway:400
Source: chromecache_63.2.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Roboto:100
Source: chromecache_59.2.dr String found in binary or memory: https://fonts.gstatic.com/s/montserrat/v29/JTUSjIg1_i6t8kCHKm459W1hyzbi.woff2)
Source: chromecache_59.2.dr String found in binary or memory: https://fonts.gstatic.com/s/montserrat/v29/JTUSjIg1_i6t8kCHKm459WRhyzbi.woff2)
Source: chromecache_59.2.dr String found in binary or memory: https://fonts.gstatic.com/s/montserrat/v29/JTUSjIg1_i6t8kCHKm459WZhyzbi.woff2)
Source: chromecache_59.2.dr String found in binary or memory: https://fonts.gstatic.com/s/montserrat/v29/JTUSjIg1_i6t8kCHKm459Wdhyzbi.woff2)
Source: chromecache_59.2.dr String found in binary or memory: https://fonts.gstatic.com/s/montserrat/v29/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2)
Source: chromecache_57.2.dr String found in binary or memory: https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyC0ITw.woff2)
Source: chromecache_57.2.dr String found in binary or memory: https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyCAIT5lu.woff2)
Source: chromecache_57.2.dr String found in binary or memory: https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyCIIT5lu.woff2)
Source: chromecache_57.2.dr String found in binary or memory: https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyCMIT5lu.woff2)
Source: chromecache_57.2.dr String found in binary or memory: https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyCkIT5lu.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3-UBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3CUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3GUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3KUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3OUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3iUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3yUBA.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMawCUBGEe.woff2)
Source: chromecache_66.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMaxKUBGEe.woff2)
Source: chromecache_64.2.dr String found in binary or memory: https://storage.googleapis.com/track.salesflare.com/provider.html?xdm_e=https%3A%2F%2F394-kadoma.tra
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49671 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown HTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.168.102.96:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.168.102.96:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.64:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.64:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.68:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.19:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.249.91.49:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.173.132.30:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.173.132.30:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Windows\SystemTemp\scoped_dir3472_1504000474 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File deleted: C:\Windows\SystemTemp\scoped_dir3472_1504000474 Jump to behavior
Source: classification engine Classification label: clean2.win@34/25@69/8
Source: C:\Windows\System32\conhost.exe Mutant created: \BaseNamedObjects\Local\SM0:5064:120:WilError_03
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2348,i,977650232591120726,18254827365428393022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2388 /prefetch:3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://protect.checkpoint.com/v2/r02/___https://lsems.gravityzone.bitdefender.com/xhfsdfMW5hMR*~*QDcqg1KugH/rhrqqgrWni2pyg1KugH/og75AgMRA37Cu37x!i2GzU2ZBRIJzQYOHZZqqYsmZW5OR00KOX83/48p8j0J8ZqF5gYq/X5p/4JhyRpOG1IqMhIh5WIqxR6iX1YmuV1mTfLuz38uCWp/KRqiVYoq5hZbCTIh/4MqE1rinfpmCiY0KZ8i*~*QYOHf1mO48i1RIOfhqGCjLqKW1mPX0SpSYKxR7Z6YsKOg7qvg7m2RIiAZKJyRpO8Wpt6T2uS4rSTX560TJS93ZOHYqOw0K0vZL6x4styRpOuTIJ80ES1RJWuR0u*~*Z60vZ5KvhL4H05cwip06TYSDV8p/Z1K7hD5DWo0n0rm5ZKiLjLCyg8GNVX5DVs4QWLB6gImt35yRX1yIipSGZruqRIJyRpOQWruzf1uB0oqmZqSXX0FyRpO*~*VpC8gKKvf84NWYR7i2uEi8GogsRyRpOA35u6SYipfsSZi6WpSKuJ47N842V/3sSp08uyf1qqi60Mf1/fZrKISp/BZqWHYZytiIm3Xp95fpqOX6qqYYiqh24CSYKqfLSRVpu/Y7CUY758S2O4W1mm3rN6hL/4T1NEYol9iKWJWpS*~*hKSKi7Op0EOZY5yrWoNyRpNyRp4V02G34Y4B1Zq8QYOHXsGt1Yp6i2W9VYi5S70901cUgLByRpOUjsmEZ64nSZuO0002WJCKT2ZCQYOLYZKq06qH40WxiYm8R2q34puoXsStRI0SQYOHfr0z07Cpj2KBj0iWSIG6ZMiGZEOY46091qmZWLcS4ZcmZomGWrStY8iz4sqyRqSrZpm5iMOX45B5T0WHV7umRZNBg2uIX8ORhpmP1Y0407uVSp/XXI4OW2SCW8G21p/Ki1myh0054ESIfp6NgrOyWJyDi5ByRpO8WsGfgsKWgpKJSEW0j00LgZBCRESPXIF8goOxjqGKg16WfoO*~*jYmXZ5up454mXE4R2EWBf1mNj1iTZ5NBhoqX4qhB4IV5Y6G3irSG4oi*~*isGOWrmP104O0MmXWD5DVq4uiYi2i5b6hJqUX1uWgqS/3pW6ZZ*/2*XIKpf7SMYpx5ZoNyRp43gsSfSLuUi8utV5u4Z544gqSq4sWtWZOfhqGY4ZbyRpNCXY0tRKW*~*j1KKg805WJp7j1SwXpyTjZuSRrKm0oFyRp43Vn5DWn5DWrqK1Z35h1SyR8m8X60f4oSvX2SJZ8NyRpOJ0JyDW2i/h7BB0LC0SKq8gYF8X10335iWda99K97K667Kc*~*7K6aFIF/JJbJI/5b8*~*J59I5H78FbH8bc/*~*5Ka*~*/9KHIKJ/Hc77K?h=6&fru;n=6&fru;ithx=6___.YzJlOmdhbmdzdGVyOmM6bzozNzgzODlmOGVjOWFjMDU4ODA2YzZiNzAzODIwZWExYjo3OjE1MzU6MzgzZDA3MjA0MGU4NmVjOTQ5NjUyYWM1MTBkYzkzNzg4ODQ3Mjg0YTJlN2I1MzhlZWM4YWU1YzI1YWE5Y2UxNjpoOlQ6VA"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2348,i,977650232591120726,18254827365428393022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2388 /prefetch:3 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: mpclient.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: wscapi.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: slc.dll Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Section loaded: sppc.dll Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Windows Defender\MpCmdRun.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files\Windows Defender\MpCmdRun.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
Source: C:\Program Files\Windows Defender\MpCmdRun.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs