Edit tour

Windows Analysis Report
https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX4

Overview

General Information

Sample URL:https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrD
Analysis ID:1650125
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder
URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6912 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7100 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1280,i,16046024234177905616,12265871970017837379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2188 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 5732 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.comSample URL: PII: fanny@lisihomeware.com
Source: https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.comHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.228:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.52.23:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.52.23:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com HTTP/1.1Host: lx-sagittarius-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lx-sagittarius-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lx-sagittarius-star-mail.qiye.163.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=3 HTTP/1.1Host: waimao-north-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://lx-sagittarius-star-mail.qiye.163.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://lx-sagittarius-star-mail.qiye.163.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=3 HTTP/1.1Host: waimao-north-star-mail.qiye.163.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: lx-sagittarius-star-mail.qiye.163.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: waimao-north-star-mail.qiye.163.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.228:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.52.23:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.52.23:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6912_1004390926Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6912_1004390926Jump to behavior
Source: classification engineClassification label: clean1.win@22/2@10/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1280,i,16046024234177905616,12265871970017837379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2188 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1280,i,16046024234177905616,12265871970017837379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2188 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1650125 URL: https://lx-sagittarius-star... Startdate: 27/03/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.16, 138, 443, 49318 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.250.65.228, 443, 49712, 49727 GOOGLEUS United States 10->15 17 waimao-north-star-mail.qiye.163.com 8.210.52.23, 443, 49722, 49723 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 10->17 19 lx-sagittarius-star-mail.qiye.163.com 8.218.184.24, 443, 49703, 49704 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://waimao-north-star-mail.qiye.163.com/api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=30%Avira URL Cloudsafe
https://lx-sagittarius-star-mail.qiye.163.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
lx-sagittarius-star-mail.qiye.163.com
8.218.184.24
truefalse
    high
    www.google.com
    142.250.65.228
    truefalse
      high
      waimao-north-star-mail.qiye.163.com
      8.210.52.23
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://waimao-north-star-mail.qiye.163.com/api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=3false
        • Avira URL Cloud: safe
        unknown
        https://lx-sagittarius-star-mail.qiye.163.com/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.comfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.65.228
          www.google.comUnited States
          15169GOOGLEUSfalse
          8.210.52.23
          waimao-north-star-mail.qiye.163.comSingapore
          45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
          8.218.184.24
          lx-sagittarius-star-mail.qiye.163.comSingapore
          45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
          IP
          192.168.2.16
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1650125
          Start date and time:2025-03-27 13:51:20 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 17s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsinteractivecookbook.jbs
          Sample URL:https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:17
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean1.win@22/2@10/4
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.40.238, 142.251.40.227, 172.253.62.84, 142.250.65.238, 142.250.65.234, 142.250.81.234, 142.251.32.106, 142.251.35.170, 142.251.40.106, 142.251.40.138, 142.251.40.170, 142.250.64.106, 142.250.72.106, 142.250.176.202, 142.251.40.202, 142.251.40.234, 142.251.41.10, 172.217.165.138, 142.250.65.170, 142.250.65.202, 142.250.65.195, 4.175.87.197, 23.204.23.20, 20.190.151.133, 23.57.90.150
          • Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, update.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&amp;sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&amp;from=fanny@lisihomeware.com
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with no line terminators
          Category:downloaded
          Size (bytes):16
          Entropy (8bit):3.625
          Encrypted:false
          SSDEEP:3:HFn:l
          MD5:418FBC40DEEBD999D02A91F3BC9850B9
          SHA1:A04AB7C83CB2CDF175711BF34C27A0C32F801DC2
          SHA-256:E85E233CE28065F9DE8A6429A42B6BFC4752340EDB2F66AF1B79F1B805549771
          SHA-512:74599CE0567379C67882DCC387D869C2F5340D5F814789A65740C378A85949822118A4C8B842241D297087907CF646271DAB0866E3754291F729C3253185986D
          Malicious:false
          Reputation:low
          URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCbwisDGAAlFsEgUNZecJJiHrxEi0VrAAAw==?alt=proto
          Preview:CgkKBw1l5wkmGgA=
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 85
          • 443 (HTTPS)
          • 80 (HTTP)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Mar 27, 2025 13:51:50.445832968 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.445868969 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:50.445955992 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.446439028 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.446485043 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:50.446542978 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.446605921 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.446616888 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:50.446696997 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:50.446715117 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.322860956 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.323049068 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:51.324278116 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:51.324286938 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.324676037 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.325345993 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:51.355520010 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.355652094 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:51.356193066 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:51.356205940 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.356976032 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.368272066 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:51.401544094 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.004798889 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.004873037 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.004972935 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.004991055 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.005037069 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.005110025 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.005656958 CET49703443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.005675077 CET443497038.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.103070021 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.144275904 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.461046934 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.461216927 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.461383104 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.461905956 CET49704443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.461947918 CET443497048.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.553996086 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.554084063 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:52.554177999 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.554315090 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:52.554337025 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.480534077 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.480699062 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:53.481213093 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:53.481239080 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.482067108 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.482373953 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:53.524302959 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.848201990 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.848436117 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:53.848515034 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:53.849257946 CET49711443192.168.2.168.218.184.24
          Mar 27, 2025 13:51:53.849292994 CET443497118.218.184.24192.168.2.16
          Mar 27, 2025 13:51:54.189620972 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:51:54.189682961 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:51:54.189810038 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:51:54.189960957 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:51:54.189985037 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:51:54.389193058 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:51:54.389309883 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:51:54.390583992 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:51:54.390603065 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:51:54.391016006 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:51:54.431583881 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:03.229419947 CET49673443192.168.2.162.23.227.208
          Mar 27, 2025 13:52:03.229477882 CET443496732.23.227.208192.168.2.16
          Mar 27, 2025 13:52:04.410691023 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:04.410835981 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:04.411005974 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:05.524571896 CET49712443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:05.524645090 CET44349712142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:06.608072042 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:06.913801908 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:07.519838095 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:08.734695911 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:11.142740965 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:15.052216053 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:15.355789900 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:15.943839073 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:15.959628105 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:17.169800997 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:19.575912952 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:24.376925945 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:25.556905985 CET49671443192.168.2.16204.79.197.203
          Mar 27, 2025 13:52:33.986982107 CET49679443192.168.2.1652.182.143.211
          Mar 27, 2025 13:52:36.078174114 CET4969280192.168.2.16142.251.41.3
          Mar 27, 2025 13:52:36.078258038 CET4969380192.168.2.1623.210.73.5
          Mar 27, 2025 13:52:36.167175055 CET8049692142.251.41.3192.168.2.16
          Mar 27, 2025 13:52:36.167257071 CET4969280192.168.2.16142.251.41.3
          Mar 27, 2025 13:52:36.167578936 CET804969323.210.73.5192.168.2.16
          Mar 27, 2025 13:52:36.167651892 CET4969380192.168.2.1623.210.73.5
          Mar 27, 2025 13:52:37.468445063 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:37.468522072 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:37.468650103 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:37.468843937 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:37.468867064 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.356950998 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.357072115 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.361057043 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.361088037 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.361673117 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.362036943 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.404304981 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.851929903 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.852102041 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.852181911 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.853147984 CET49722443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.853183031 CET443497228.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.944825888 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.944925070 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:38.945034027 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.945184946 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:38.945207119 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:39.881089926 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:39.881210089 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:39.881702900 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:39.881733894 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:39.881953955 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:39.882241011 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:39.924288988 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:40.252849102 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:40.253026962 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:40.253117085 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:40.255155087 CET49723443192.168.2.168.210.52.23
          Mar 27, 2025 13:52:40.255196095 CET443497238.210.52.23192.168.2.16
          Mar 27, 2025 13:52:54.153444052 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:54.153539896 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:54.153661966 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:54.153836966 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:54.153872967 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:54.342205048 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:52:54.342740059 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:52:54.342824936 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:53:04.347996950 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:53:04.348051071 CET44349727142.250.65.228192.168.2.16
          Mar 27, 2025 13:53:04.348189116 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:53:05.516385078 CET49727443192.168.2.16142.250.65.228
          Mar 27, 2025 13:53:05.516446114 CET44349727142.250.65.228192.168.2.16
          TimestampSource PortDest PortSource IPDest IP
          Mar 27, 2025 13:51:49.432512045 CET53529231.1.1.1192.168.2.16
          Mar 27, 2025 13:51:49.447033882 CET53517441.1.1.1192.168.2.16
          Mar 27, 2025 13:51:50.018435955 CET6418453192.168.2.161.1.1.1
          Mar 27, 2025 13:51:50.020973921 CET5845853192.168.2.161.1.1.1
          Mar 27, 2025 13:51:50.171655893 CET53626711.1.1.1192.168.2.16
          Mar 27, 2025 13:51:50.328039885 CET53525901.1.1.1192.168.2.16
          Mar 27, 2025 13:51:50.389765978 CET53641841.1.1.1192.168.2.16
          Mar 27, 2025 13:51:50.470571995 CET53584581.1.1.1192.168.2.16
          Mar 27, 2025 13:51:52.165514946 CET53523471.1.1.1192.168.2.16
          Mar 27, 2025 13:51:52.464922905 CET6225253192.168.2.161.1.1.1
          Mar 27, 2025 13:51:52.465085983 CET5672453192.168.2.161.1.1.1
          Mar 27, 2025 13:51:52.553121090 CET53622521.1.1.1192.168.2.16
          Mar 27, 2025 13:51:52.553167105 CET53567241.1.1.1192.168.2.16
          Mar 27, 2025 13:51:54.099731922 CET5273353192.168.2.161.1.1.1
          Mar 27, 2025 13:51:54.100086927 CET5660953192.168.2.161.1.1.1
          Mar 27, 2025 13:51:54.188024998 CET53527331.1.1.1192.168.2.16
          Mar 27, 2025 13:51:54.188177109 CET53566091.1.1.1192.168.2.16
          Mar 27, 2025 13:52:07.274394989 CET53553921.1.1.1192.168.2.16
          Mar 27, 2025 13:52:25.662650108 CET5360180162.159.36.2192.168.2.16
          Mar 27, 2025 13:52:26.270138979 CET53493181.1.1.1192.168.2.16
          Mar 27, 2025 13:52:37.254220963 CET5421253192.168.2.161.1.1.1
          Mar 27, 2025 13:52:37.254362106 CET5184053192.168.2.161.1.1.1
          Mar 27, 2025 13:52:37.430146933 CET53542121.1.1.1192.168.2.16
          Mar 27, 2025 13:52:37.869633913 CET53518401.1.1.1192.168.2.16
          Mar 27, 2025 13:52:38.855988979 CET5720953192.168.2.161.1.1.1
          Mar 27, 2025 13:52:38.856138945 CET4981553192.168.2.161.1.1.1
          Mar 27, 2025 13:52:38.944087029 CET53572091.1.1.1192.168.2.16
          Mar 27, 2025 13:52:38.944149017 CET53498151.1.1.1192.168.2.16
          Mar 27, 2025 13:52:49.261348009 CET53618341.1.1.1192.168.2.16
          Mar 27, 2025 13:52:49.359231949 CET53624871.1.1.1192.168.2.16
          Mar 27, 2025 13:53:12.661035061 CET138138192.168.2.16192.168.2.255
          Mar 27, 2025 13:53:19.997567892 CET53493541.1.1.1192.168.2.16
          TimestampSource IPDest IPChecksumCodeType
          Mar 27, 2025 13:51:50.470668077 CET192.168.2.161.1.1.1c23e(Port unreachable)Destination Unreachable
          Mar 27, 2025 13:52:37.869734049 CET192.168.2.161.1.1.1c23c(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 27, 2025 13:51:50.018435955 CET192.168.2.161.1.1.10xe52fStandard query (0)lx-sagittarius-star-mail.qiye.163.comA (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:50.020973921 CET192.168.2.161.1.1.10x74d5Standard query (0)lx-sagittarius-star-mail.qiye.163.com65IN (0x0001)false
          Mar 27, 2025 13:51:52.464922905 CET192.168.2.161.1.1.10xdaf3Standard query (0)lx-sagittarius-star-mail.qiye.163.comA (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:52.465085983 CET192.168.2.161.1.1.10x7aa0Standard query (0)lx-sagittarius-star-mail.qiye.163.com65IN (0x0001)false
          Mar 27, 2025 13:51:54.099731922 CET192.168.2.161.1.1.10x81d5Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:54.100086927 CET192.168.2.161.1.1.10xb825Standard query (0)www.google.com65IN (0x0001)false
          Mar 27, 2025 13:52:37.254220963 CET192.168.2.161.1.1.10x2b6fStandard query (0)waimao-north-star-mail.qiye.163.comA (IP address)IN (0x0001)false
          Mar 27, 2025 13:52:37.254362106 CET192.168.2.161.1.1.10xb395Standard query (0)waimao-north-star-mail.qiye.163.com65IN (0x0001)false
          Mar 27, 2025 13:52:38.855988979 CET192.168.2.161.1.1.10x2ab3Standard query (0)waimao-north-star-mail.qiye.163.comA (IP address)IN (0x0001)false
          Mar 27, 2025 13:52:38.856138945 CET192.168.2.161.1.1.10x94fdStandard query (0)waimao-north-star-mail.qiye.163.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 27, 2025 13:51:50.389765978 CET1.1.1.1192.168.2.160xe52fNo error (0)lx-sagittarius-star-mail.qiye.163.com8.218.184.24A (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:52.553121090 CET1.1.1.1192.168.2.160xdaf3No error (0)lx-sagittarius-star-mail.qiye.163.com8.218.184.24A (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:54.188024998 CET1.1.1.1192.168.2.160x81d5No error (0)www.google.com142.250.65.228A (IP address)IN (0x0001)false
          Mar 27, 2025 13:51:54.188177109 CET1.1.1.1192.168.2.160xb825No error (0)www.google.com65IN (0x0001)false
          Mar 27, 2025 13:52:37.430146933 CET1.1.1.1192.168.2.160x2b6fNo error (0)waimao-north-star-mail.qiye.163.com8.210.52.23A (IP address)IN (0x0001)false
          Mar 27, 2025 13:52:38.944087029 CET1.1.1.1192.168.2.160x2ab3No error (0)waimao-north-star-mail.qiye.163.com8.210.52.23A (IP address)IN (0x0001)false
          • lx-sagittarius-star-mail.qiye.163.com
            • waimao-north-star-mail.qiye.163.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.16497038.218.184.244437100C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-27 12:51:51 UTC976OUTGET /unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com HTTP/1.1
          Host: lx-sagittarius-star-mail.qiye.163.com
          Connection: keep-alive
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-27 12:51:52 UTC493INHTTP/1.1 200 OK
          Server: nginx/1.20.1
          Date: Thu, 27 Mar 2025 12:51:51 GMT
          Content-Type: text/html
          Content-Length: 8415
          Connection: close
          Vary: Accept-Encoding
          last-modified: Wed, 26 Mar 2025 13:16:07 GMT
          accept-ranges: bytes
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block
          cache-control: no-cache, no-store, max-age=0, must-revalidate
          pragma: no-cache
          expires: 0
          x-envoy-upstream-service-time: 4
          lingxi-traceid: f89acb9f907cb17179ad8c6e033e4ea1^750873600000^0
          2025-03-27 12:51:52 UTC8415INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 61 73 65 20 46 6f 72 65 69 67 6e 20 54 72 61 64 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 68 74 6d 6c 2c 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20
          Data Ascii: <!DOCTYPE html><html><head> <meta charset="UTF-8"> <title>Ease Foreign Trade</title> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /> <style> html, body { margin: 0;


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.16497048.218.184.244437100C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-27 12:51:52 UTC926OUTGET /favicon.ico HTTP/1.1
          Host: lx-sagittarius-star-mail.qiye.163.com
          Connection: keep-alive
          sec-ch-ua-platform: "Windows"
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-27 12:51:52 UTC472INHTTP/1.1 200 OK
          Server: nginx/1.20.1
          Date: Thu, 27 Mar 2025 12:51:52 GMT
          Content-Type: image/x-icon
          Content-Length: 946
          Connection: close
          last-modified: Thu, 20 Mar 2025 11:27:09 GMT
          accept-ranges: bytes
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block
          cache-control: no-cache, no-store, max-age=0, must-revalidate
          pragma: no-cache
          expires: 0
          x-envoy-upstream-service-time: 3
          lingxi-traceid: 2bfd690904f386e72f21bd314db0b491^750873600000^0
          2025-03-27 12:51:52 UTC946INData Raw: 00 00 01 00 01 00 10 0d 00 00 01 00 20 00 9c 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 1a 00 00 00 01 00 20 00 00 00 00 00 74 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 66 a0 70 1c 46 8f 57 8c 42 ab 87 56 41 ca ba 4f 42 cd bf 62 3b cf c4 7b 36 d0 c6 92 33 d0 c5 a4 2c ce c4 a4 32 d0 c6 a0 3b d2 c8 79 48 d3 ca 2d 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 37 9a 6b 32 2f 81 42 fb 2b 7d 3a ff 2a 85 48 ff 28 94 61 ff 26 a4 7d ff 24 b9 a1 ff 23 c5 b5 ff 22 cd c3 ff 22 cd c2 ff 21 cc c1 ff 26 cd c2 ff 31 cf c5 9e 41 d2 c9 18 00 00 00 00 44 d2 c7 25 2e c1 ad cf 26 a9 85 ff 27 a5 7e fe 28 9e 73 ff 29 96 66 ff 2a 8f 58 ff 2b 85 47 ff 2a 90 5a ff 26 b0 91 ff 23 ca bd ff 22 ce c4 fe 22 cc c1 ff 22 cc c1 ff 30 cf c5 a7 00 00 00 06 34
          Data Ascii: ( tfpFWBVAOBb;{63,2;yH-7k2/B+}:*H(a&}$#""!&1AD%.&'~(s)f*X+G*Z&#"""04


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.16497118.218.184.244437100C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-27 12:51:53 UTC412OUTGET /favicon.ico HTTP/1.1
          Host: lx-sagittarius-star-mail.qiye.163.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept: */*
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: cors
          Sec-Fetch-Dest: empty
          Sec-Fetch-Storage-Access: active
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-27 12:51:53 UTC472INHTTP/1.1 200 OK
          Server: nginx/1.20.1
          Date: Thu, 27 Mar 2025 12:51:53 GMT
          Content-Type: image/x-icon
          Content-Length: 946
          Connection: close
          last-modified: Thu, 20 Mar 2025 11:27:09 GMT
          accept-ranges: bytes
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block
          cache-control: no-cache, no-store, max-age=0, must-revalidate
          pragma: no-cache
          expires: 0
          x-envoy-upstream-service-time: 4
          lingxi-traceid: d298dc82a4a986f5936ecb10b7daeef3^750873600000^0
          2025-03-27 12:51:53 UTC946INData Raw: 00 00 01 00 01 00 10 0d 00 00 01 00 20 00 9c 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 1a 00 00 00 01 00 20 00 00 00 00 00 74 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 66 a0 70 1c 46 8f 57 8c 42 ab 87 56 41 ca ba 4f 42 cd bf 62 3b cf c4 7b 36 d0 c6 92 33 d0 c5 a4 2c ce c4 a4 32 d0 c6 a0 3b d2 c8 79 48 d3 ca 2d 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 37 9a 6b 32 2f 81 42 fb 2b 7d 3a ff 2a 85 48 ff 28 94 61 ff 26 a4 7d ff 24 b9 a1 ff 23 c5 b5 ff 22 cd c3 ff 22 cd c2 ff 21 cc c1 ff 26 cd c2 ff 31 cf c5 9e 41 d2 c9 18 00 00 00 00 44 d2 c7 25 2e c1 ad cf 26 a9 85 ff 27 a5 7e fe 28 9e 73 ff 29 96 66 ff 2a 8f 58 ff 2b 85 47 ff 2a 90 5a ff 26 b0 91 ff 23 ca bd ff 22 ce c4 fe 22 cc c1 ff 22 cc c1 ff 30 cf c5 a7 00 00 00 06 34
          Data Ascii: ( tfpFWBVAOBb;{63,2;yH-7k2/B+}:*H(a&}$#""!&1AD%.&'~(s)f*X+G*Z&#"""04


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.16497228.210.52.234437100C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-27 12:52:38 UTC850OUTGET /api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=3 HTTP/1.1
          Host: waimao-north-star-mail.qiye.163.com
          Connection: keep-alive
          sec-ch-ua-platform: "Windows"
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          Accept: */*
          Origin: https://lx-sagittarius-star-mail.qiye.163.com
          Sec-Fetch-Site: same-site
          Sec-Fetch-Mode: cors
          Sec-Fetch-Dest: empty
          Referer: https://lx-sagittarius-star-mail.qiye.163.com/
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-27 12:52:38 UTC645INHTTP/1.1 200 OK
          Server: nginx/1.20.1
          Date: Thu, 27 Mar 2025 12:52:38 GMT
          Content-Type: application/json;charset=UTF-8
          Transfer-Encoding: chunked
          Connection: close
          Vary: Accept-Encoding
          vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
          access-control-allow-origin: https://lx-sagittarius-star-mail.qiye.163.com
          access-control-allow-credentials: true
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block
          cache-control: no-cache, no-store, max-age=0, must-revalidate
          pragma: no-cache
          expires: 0
          x-envoy-upstream-service-time: 145
          lingxi-traceid: abec4d39dd1574ae9cd7707e8e3cea4c^750873600000^0
          2025-03-27 12:52:38 UTC63INData Raw: 33 34 0d 0a 7b 22 64 61 74 61 22 3a 6e 75 6c 6c 2c 22 73 75 63 63 65 73 73 22 3a 74 72 75 65 2c 22 6d 65 73 73 61 67 65 22 3a 6e 75 6c 6c 2c 22 63 6f 64 65 22 3a 30 7d 0d 0a 30 0d 0a 0d 0a
          Data Ascii: 34{"data":null,"success":true,"message":null,"code":0}0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          4192.168.2.16497238.210.52.234437100C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-27 12:52:39 UTC636OUTGET /api/pub/edm/unsubscribe?sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&reasonCode=3 HTTP/1.1
          Host: waimao-north-star-mail.qiye.163.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept: */*
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: cors
          Sec-Fetch-Dest: empty
          Sec-Fetch-Storage-Access: active
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-27 12:52:40 UTC452INHTTP/1.1 200 OK
          Server: nginx/1.20.1
          Date: Thu, 27 Mar 2025 12:52:40 GMT
          Content-Type: application/json;charset=UTF-8
          Transfer-Encoding: chunked
          Connection: close
          Vary: Accept-Encoding
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block
          cache-control: no-cache, no-store, max-age=0, must-revalidate
          pragma: no-cache
          expires: 0
          x-envoy-upstream-service-time: 1
          lingxi-traceid: beb6ff24c1ba23552e95e7b45ec2298a^750873600000^0
          2025-03-27 12:52:40 UTC77INData Raw: 34 32 0d 0a 7b 22 64 61 74 61 22 3a 22 e6 93 8d e4 bd 9c e8 bf 87 e4 ba 8e e9 a2 91 e7 b9 81 22 2c 22 73 75 63 63 65 73 73 22 3a 74 72 75 65 2c 22 6d 65 73 73 61 67 65 22 3a 22 22 2c 22 63 6f 64 65 22 3a 30 7d 0d 0a 30 0d 0a 0d 0a
          Data Ascii: 42{"data":"","success":true,"message":"","code":0}0


          050100s020406080100

          Click to jump to process

          050100s0.0050100MB

          Click to jump to process

          Target ID:0
          Start time:08:51:47
          Start date:27/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff77eaf0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:08:51:48
          Start date:27/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1280,i,16046024234177905616,12265871970017837379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2188 /prefetch:3
          Imagebase:0x7ff77eaf0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:08:51:49
          Start date:27/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com"
          Imagebase:0x7ff77eaf0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

          No disassembly