Edit tour

Windows Analysis Report
https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp

Overview

General Information

Sample URL:https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp
Analysis ID:1649548
Infos:

Detection

Score:1
Range:0 - 100
Confidence:80%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3712 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1396 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2356,i,5406969455431525545,3592045430826831812,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2396 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 5568 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webpHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.41.58:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.41.58:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 23.203.176.221
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp HTTP/1.1Host: imageservice.pyur.opentv.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: imageservice.pyur.opentv.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webpAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: imageservice.pyur.opentv.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 26 Mar 2025 21:10:27 GMTContent-Type: application/jsonContent-Length: 23Connection: closeapigw-requestid: IDYChiEwjoEEMqw=x-cache: Error from cloudfrontvia: 1.1 09a970c514541c01d3b3e83903632062.cloudfront.net (CloudFront)x-amz-cf-pop: JFK52-P6x-amz-cf-id: oe2pMqafbdJleZmmx1Fx6o5lGLUjV2Xw4KW2idK_cWGezs2z8g_y1g==CF-Cache-Status: MISSExpires: Thu, 27 Mar 2025 01:10:27 GMTCache-Control: public, max-age=14400Server: cloudflareCF-RAY: 9269a2804ac28ce0-EWR
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.41.58:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.41.58:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3712_104383201Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3712_104383201Jump to behavior
Source: classification engineClassification label: clean1.win@21/2@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2356,i,5406969455431525545,3592045430826831812,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2396 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2356,i,5406969455431525545,3592045430826831812,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2396 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1649548 URL: https://imageservice.pyur.o... Startdate: 26/03/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49709 unknown unknown 5->13 15 192.168.2.5 unknown unknown 5->15 17 192.168.2.6 unknown unknown 5->17 10 chrome.exe 5->10         started        process4 dnsIp5 19 www.google.com 142.250.81.228, 443, 49729, 49742 GOOGLEUS United States 10->19 21 imageservice.pyur.opentv.com 104.18.41.58, 443, 49732, 49733 CLOUDFLARENETUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://imageservice.pyur.opentv.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.81.228
truefalse
    high
    imageservice.pyur.opentv.com
    104.18.41.58
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://imageservice.pyur.opentv.com/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webpfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        104.18.41.58
        imageservice.pyur.opentv.comUnited States
        13335CLOUDFLARENETUSfalse
        142.250.81.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        192.168.2.6
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1649548
        Start date and time:2025-03-26 22:09:17 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 5s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:20
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean1.win@21/2@4/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.80.110, 142.251.35.163, 172.253.122.84, 142.250.65.238, 142.250.65.163, 23.204.23.20, 204.79.197.222, 4.175.87.197
        • Excluded domains from analysis (whitelisted): fp.msedge.net, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&amp;height=50&amp;imageFormat=webp
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:JSON data
        Category:downloaded
        Size (bytes):23
        Entropy (8bit):3.914866303883101
        Encrypted:false
        SSDEEP:3:YIzLKFjJ4:YI/KZJ4
        MD5:E66A7A6C91E2C26803F3F49FEB7A883F
        SHA1:4AE440FF2BD4594A3CACAEB1EDD29444B781A3ED
        SHA-256:8FD54EEE4277F1327015CC0BCAED8A878BF44D1804364CD5D93DFAB9E2D1A5AF
        SHA-512:9A00E2AA47634A1AA8B4234F7692CA71521929EE31A225A460DD5A7BD46F9196F688467B8303C5EF5D6CFF32D25B85F511BD741CE99A3FDA8D76A66591A1DC2E
        Malicious:false
        Reputation:low
        URL:https://imageservice.pyur.opentv.com/favicon.ico
        Preview:{"message":"Not Found"}
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 63
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Mar 26, 2025 22:10:10.650079966 CET4968180192.168.2.42.17.190.73
        Mar 26, 2025 22:10:15.259972095 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:15.571788073 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:16.181127071 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:17.384304047 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:19.852605104 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:20.321243048 CET4968180192.168.2.42.17.190.73
        Mar 26, 2025 22:10:23.578879118 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:23.578926086 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:23.579030037 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:23.579227924 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:23.579241037 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:23.762924910 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:23.763003111 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:23.764403105 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:23.764450073 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:23.764687061 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:23.805743933 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:24.024909973 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:24.337069035 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:24.655881882 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:24.946367979 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:25.505356073 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.505404949 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.505692005 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.505758047 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.505831957 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.505892038 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.505892038 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.505922079 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.506066084 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.506087065 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.690109015 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.690346003 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.692995071 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.693109035 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.694350004 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.694359064 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.694622040 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.695358992 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.695385933 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.695614100 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:25.695751905 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.736279964 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:25.744472980 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:26.148905993 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:26.446400881 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.446528912 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.446602106 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:26.446620941 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.446650982 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.446852922 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.446976900 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:26.451899052 CET49732443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:26.451917887 CET44349732104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:26.566437006 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:26.612309933 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:27.064366102 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:27.064477921 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:27.064570904 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:27.071105003 CET49733443192.168.2.4104.18.41.58
        Mar 26, 2025 22:10:27.071156025 CET44349733104.18.41.58192.168.2.4
        Mar 26, 2025 22:10:28.558423996 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:28.593940973 CET49709443192.168.2.4131.253.33.254
        Mar 26, 2025 22:10:28.599797010 CET49709443192.168.2.4131.253.33.254
        Mar 26, 2025 22:10:28.683995962 CET44349709131.253.33.254192.168.2.4
        Mar 26, 2025 22:10:28.689637899 CET44349709131.253.33.254192.168.2.4
        Mar 26, 2025 22:10:28.691948891 CET44349709131.253.33.254192.168.2.4
        Mar 26, 2025 22:10:28.691987038 CET44349709131.253.33.254192.168.2.4
        Mar 26, 2025 22:10:28.692061901 CET49709443192.168.2.4131.253.33.254
        Mar 26, 2025 22:10:28.692063093 CET49709443192.168.2.4131.253.33.254
        Mar 26, 2025 22:10:33.368350983 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:10:33.780658007 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:33.780812025 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:33.780996084 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:34.259350061 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 22:10:35.451167107 CET49729443192.168.2.4142.250.81.228
        Mar 26, 2025 22:10:35.451242924 CET44349729142.250.81.228192.168.2.4
        Mar 26, 2025 22:10:42.969831944 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 22:11:02.384218931 CET4971380192.168.2.4142.251.32.99
        Mar 26, 2025 22:11:02.384341002 CET4971280192.168.2.423.210.73.5
        Mar 26, 2025 22:11:02.384438038 CET4971480192.168.2.423.210.73.5
        Mar 26, 2025 22:11:02.468077898 CET8049713142.251.32.99192.168.2.4
        Mar 26, 2025 22:11:02.468228102 CET4971380192.168.2.4142.251.32.99
        Mar 26, 2025 22:11:02.468374014 CET804971223.210.73.5192.168.2.4
        Mar 26, 2025 22:11:02.468408108 CET804971423.210.73.5192.168.2.4
        Mar 26, 2025 22:11:02.468430042 CET4971280192.168.2.423.210.73.5
        Mar 26, 2025 22:11:02.468461037 CET4971480192.168.2.423.210.73.5
        Mar 26, 2025 22:11:23.557487965 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:23.557585955 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:23.557852983 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:23.557924986 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:23.557945013 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:23.746000051 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:23.746540070 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:23.746635914 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:25.579382896 CET804971123.203.176.221192.168.2.4
        Mar 26, 2025 22:11:25.579649925 CET4971180192.168.2.423.203.176.221
        Mar 26, 2025 22:11:33.745346069 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:33.745403051 CET44349742142.250.81.228192.168.2.4
        Mar 26, 2025 22:11:33.745521069 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:35.449103117 CET49742443192.168.2.4142.250.81.228
        Mar 26, 2025 22:11:35.449171066 CET44349742142.250.81.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Mar 26, 2025 22:10:19.212272882 CET53579781.1.1.1192.168.2.4
        Mar 26, 2025 22:10:19.487343073 CET53620311.1.1.1192.168.2.4
        Mar 26, 2025 22:10:20.097640991 CET53641951.1.1.1192.168.2.4
        Mar 26, 2025 22:10:20.246956110 CET53518481.1.1.1192.168.2.4
        Mar 26, 2025 22:10:23.494584084 CET5848853192.168.2.41.1.1.1
        Mar 26, 2025 22:10:23.494896889 CET5394953192.168.2.41.1.1.1
        Mar 26, 2025 22:10:23.577656031 CET53584881.1.1.1192.168.2.4
        Mar 26, 2025 22:10:23.577702045 CET53539491.1.1.1192.168.2.4
        Mar 26, 2025 22:10:25.407835007 CET6026353192.168.2.41.1.1.1
        Mar 26, 2025 22:10:25.407989979 CET5193153192.168.2.41.1.1.1
        Mar 26, 2025 22:10:25.504384995 CET53519311.1.1.1192.168.2.4
        Mar 26, 2025 22:10:25.504682064 CET53602631.1.1.1192.168.2.4
        Mar 26, 2025 22:10:37.196603060 CET53614491.1.1.1192.168.2.4
        Mar 26, 2025 22:10:56.233815908 CET53534571.1.1.1192.168.2.4
        Mar 26, 2025 22:10:56.828885078 CET5351462162.159.36.2192.168.2.4
        Mar 26, 2025 22:11:18.907483101 CET53616791.1.1.1192.168.2.4
        Mar 26, 2025 22:11:19.083182096 CET53552591.1.1.1192.168.2.4
        Mar 26, 2025 22:11:24.532186031 CET138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 26, 2025 22:10:23.494584084 CET192.168.2.41.1.1.10x2b33Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 26, 2025 22:10:23.494896889 CET192.168.2.41.1.1.10xa4ecStandard query (0)www.google.com65IN (0x0001)false
        Mar 26, 2025 22:10:25.407835007 CET192.168.2.41.1.1.10x5e80Standard query (0)imageservice.pyur.opentv.comA (IP address)IN (0x0001)false
        Mar 26, 2025 22:10:25.407989979 CET192.168.2.41.1.1.10x1f86Standard query (0)imageservice.pyur.opentv.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 26, 2025 22:10:23.577656031 CET1.1.1.1192.168.2.40x2b33No error (0)www.google.com142.250.81.228A (IP address)IN (0x0001)false
        Mar 26, 2025 22:10:23.577702045 CET1.1.1.1192.168.2.40xa4ecNo error (0)www.google.com65IN (0x0001)false
        Mar 26, 2025 22:10:25.504384995 CET1.1.1.1192.168.2.40x1f86No error (0)imageservice.pyur.opentv.com65IN (0x0001)false
        Mar 26, 2025 22:10:25.504682064 CET1.1.1.1192.168.2.40x5e80No error (0)imageservice.pyur.opentv.com104.18.41.58A (IP address)IN (0x0001)false
        Mar 26, 2025 22:10:25.504682064 CET1.1.1.1192.168.2.40x5e80No error (0)imageservice.pyur.opentv.com172.64.146.198A (IP address)IN (0x0001)false
        • imageservice.pyur.opentv.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449732104.18.41.584431396C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-03-26 21:10:25 UTC756OUTGET /images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp HTTP/1.1
        Host: imageservice.pyur.opentv.com
        Connection: keep-alive
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-03-26 21:10:26 UTC574INHTTP/1.1 200 OK
        Date: Wed, 26 Mar 2025 21:10:26 GMT
        Content-Type: image/webp
        Content-Length: 4230
        Connection: close
        image-source: Sized image found in S3
        apigw-requestid: IDYCahtEDoEEPgQ=
        x-cache: Miss from cloudfront
        via: 1.1 2d309cac2555275db9509df4973cc040.cloudfront.net (CloudFront)
        x-amz-cf-pop: JFK52-P6
        x-amz-cf-id: jx6Fd1Ga8tRLMpj0Tx6G0h6c1TOdGBWatJJwtrxfE5BdIs-f3U9-Sw==
        vary: Origin
        Last-Modified: Wed, 26 Mar 2025 21:10:26 GMT
        Cache-Control: no-store
        CF-Cache-Status: MISS
        Accept-Ranges: bytes
        Server: cloudflare
        CF-RAY: 9269a27b8b813d64-EWR
        2025-03-26 21:10:26 UTC795INData Raw: 52 49 46 46 7e 10 00 00 57 45 42 50 56 50 38 58 0a 00 00 00 10 00 00 00 70 01 00 32 00 00 41 4c 50 48 97 0b 00 00 01 f0 46 6b db b2 a7 d9 b6 ed 49 ce 24 40 1c 77 bf 91 04 a7 82 5b 05 a7 ee 86 d5 dd 3b bc 97 51 77 77 97 40 6d 94 d4 db 81 d6 05 ad 37 14 87 1a 96 12 3f d7 e5 c7 b1 1f fb 79 08 c9 dd 9f 11 31 01 26 8e 23 e6 bd f9 29 29 2e 3f ab 95 71 ed f3 01 c0 ae 93 12 c6 39 fd a0 ed 00 6b 0f 33 51 bd 66 0f 50 ff 65 a1 71 bd 6b 17 50 fd 7e 17 13 d1 dc f9 78 6f c8 32 8d fd ec fd 67 df f9 de ea 75 a9 94 bf 7a 58 b6 43 b3 53 7f f1 54 3e 5b e2 d6 e1 b6 3d 9e 6d f7 15 47 23 ed e0 b2 6a 20 b9 fe e4 6c 87 31 ef 55 01 75 df 5f 9a 1b 8d 82 33 56 58 de 19 dd d8 eb 33 77 29 5e b9 09 56 4e 77 98 b0 0a 81 e0 3f d9 2e 19 27 81 84 e0 e5 5e 51 c8 9c ba 0e 84 60 5b 6f bf b4
        Data Ascii: RIFF~WEBPVP8Xp2ALPHFkI$@w[;Qww@m7?y1&#)).?q9k3QfPeqkP~xo2guzXCST>[=mG#j l1Uu_3VX3w)^VNw?.'^Q`[o
        2025-03-26 21:10:26 UTC1369INData Raw: 5a 10 56 c1 ba b3 9b 98 7d 57 29 11 94 0b 82 73 9b 46 eb 8c 2d d8 05 6b af d9 cf 84 18 86 19 f8 6a 12 c9 82 60 cd d1 19 29 b4 ba 62 2b 08 ab 60 f3 8d 9d 4d ca 69 87 7f 05 92 07 01 f3 4b 52 19 f2 7c 2d 12 5e 09 3e 9f 95 30 fb b0 4b 5e 7b e7 ad 10 cb 56 ac 5a bf 17 90 db 4f 9d a2 75 1f 8e 2b 8e 32 a1 86 62 7a 3d bd 07 64 41 50 7e 6a be 53 e7 ff d5 21 61 15 6c bc c2 04 3a e1 b3 24 c8 83 80 e7 c7 24 5c b2 86 2d 00 61 15 e8 93 b1 26 ec 98 b5 e8 dc 25 cc ce d3 0f 3b fb 8e 57 57 ec 41 f2 41 30 35 23 4a 1d ca 90 45 94 1f 6d e2 63 12 77 ee 02 59 90 a8 b8 b0 d0 a1 cb a3 20 ec 82 b5 33 13 c1 98 ae 1f d6 80 3c 20 b1 66 62 9a c3 b4 4f 41 58 05 75 8b fe cf ec db 22 39 e8 c9 9d 20 1f e0 f1 0e 51 1a f5 09 fe 57 25 e2 64 9a 5d bc 01 64 01 51 7f 6b a1 4f 8f 77 40 58 25 92
        Data Ascii: ZV}W)sF-kj`)b+`MiKR|-^>0K^{VZOu+2bz=dAP~jS!al:$$\-a&%;WWAA05#JEmcwY 3< fbOAXu"9 QW%d]dQkOw@X%
        2025-03-26 21:10:26 UTC1369INData Raw: ae 2d 71 28 ec dc 25 e8 4e 7d 0f ff f7 b2 3d 20 7c 27 a7 c7 a8 d5 2d 7f 80 b0 8b f5 97 16 99 54 7b 3d be 17 d9 10 c9 6f 2f 4d 6d f8 6b b5 08 bb e0 eb 29 e9 26 c5 ac c9 ef 01 f2 20 a8 5d bc 7f 83 71 56 30 dd 8f 78 7c 33 c8 47 f0 40 3b 9f 36 ff 5d 50 f6 56 d0 65 1f ac de 01 08 af 60 49 47 13 9f f6 2f ec 06 e1 95 60 d5 cc 3c 93 7a c7 3b 76 21 1b 82 2d 97 64 a4 30 6d 51 1d c2 2e f8 68 94 09 70 e4 42 40 1e 04 2c 3b b8 a1 78 6d ee 05 a9 9e 77 cf c3 cf bd b3 a6 1a 09 d7 e9 09 5b 87 c7 45 b8 12 fe 75 47 65 c5 26 63 c0 63 80 f0 0a 58 7e 44 a6 09 b2 c3 35 e5 20 79 10 fc f1 9f 16 2e 59 47 7f 05 c2 2e 2a 9f 1f 61 02 1d f4 50 12 e4 41 82 cf 8f cb 69 18 2a 7e fb 3d d5 ed 58 85 bf e0 cb 8e c6 9a 7f 01 a0 50 fc 05 0b f2 4c 6c ba bd 04 08 af 80 25 a3 4c c0 4d cf fc 15 90
        Data Ascii: -q(%N}= |'-T{=o/Mmk)& ]qV0x|3G@;6]PVe`IG/`<z;v!-d0mQ.hpB@,;xmw[EuGe&ccX~D5 y.YG.*aPAi*~=XPLl%LM
        2025-03-26 21:10:26 UTC697INData Raw: e2 a6 18 e4 cc f4 ac 9e 80 91 3e 33 39 d9 d6 a3 b4 f1 34 5b b1 f7 61 52 a0 f6 9a a1 20 0a dc 6c 42 aa b1 7e 91 7f bf 1a a4 1a a8 64 60 d7 5a 22 d5 39 e7 ff e0 fe 17 2f 0f 8b f2 a6 27 21 93 00 31 64 0f 88 e9 be 42 f7 18 e5 39 e7 fa 89 cf 1a 02 3a 2b 4f f9 36 3f 47 36 d5 a5 75 f6 cf 57 53 cf fe e9 c4 11 88 64 69 43 a1 3c 71 b7 a1 c5 75 76 a0 05 28 98 77 60 0b d1 a8 aa 6c c2 cc e0 b6 62 0e 41 dc 97 ea 33 5d e3 0b eb 86 e5 d4 55 93 b4 62 72 53 e8 98 de 42 77 bf 0e 1e 49 1d 8e 91 69 25 2c a8 ae f1 67 5a 69 73 0f 06 c5 ba ae 99 97 a8 62 d4 a5 2a 14 3b ef e3 4e fc 3e 17 97 e7 9b 83 fa 8f e6 c2 5a ea 29 38 73 b9 18 fe 4a b5 6c 1c 91 8c 89 f3 a5 b2 ae 07 f8 a0 c5 43 c0 c9 b7 50 7d b6 9b b2 07 72 72 89 33 ed 1d 0a fd d1 3c d0 9f fc a0 c0 ef 2f 23 89 e0 94 27 e0 e8
        Data Ascii: >394[aR lB~d`Z"9/'!1dB9:+O6?G6uWSdiC<quv(w`lbA3]UbrSBwIi%,gZisb*;N>Z)8sJlCP}rr3</#'


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449733104.18.41.584431396C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-03-26 21:10:26 UTC697OUTGET /favicon.ico HTTP/1.1
        Host: imageservice.pyur.opentv.com
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-03-26 21:10:27 UTC518INHTTP/1.1 404 Not Found
        Date: Wed, 26 Mar 2025 21:10:27 GMT
        Content-Type: application/json
        Content-Length: 23
        Connection: close
        apigw-requestid: IDYChiEwjoEEMqw=
        x-cache: Error from cloudfront
        via: 1.1 09a970c514541c01d3b3e83903632062.cloudfront.net (CloudFront)
        x-amz-cf-pop: JFK52-P6
        x-amz-cf-id: oe2pMqafbdJleZmmx1Fx6o5lGLUjV2Xw4KW2idK_cWGezs2z8g_y1g==
        CF-Cache-Status: MISS
        Expires: Thu, 27 Mar 2025 01:10:27 GMT
        Cache-Control: public, max-age=14400
        Server: cloudflare
        CF-RAY: 9269a2804ac28ce0-EWR
        2025-03-26 21:10:27 UTC23INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 4e 6f 74 20 46 6f 75 6e 64 22 7d
        Data Ascii: {"message":"Not Found"}


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:1
        Start time:17:10:14
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:17:10:17
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2356,i,5406969455431525545,3592045430826831812,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2396 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:9
        Start time:17:10:24
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://imageservice.pyur.opentv.com/images/v1/image/channel/SimplyTV_1540/Logo?width=88&height=50&imageFormat=webp"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly