Edit tour

Windows Analysis Report
http://convertix-api.xyz

Overview

General Information

Sample URL:http://convertix-api.xyz
Analysis ID:1653629
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Performs DNS queries to domains with low reputation

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 692 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4132 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2340,i,13848920191299947155,12211409323835193597,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2352 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://convertix-api.xyz" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://convertix-api.xyzAvira URL Cloud: detection malicious, Label: malware
Source: unknownHTTPS traffic detected: 142.250.176.196:443 -> 192.168.2.4:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49731 version: TLS 1.2

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: DNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: DNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: convertix-api.xyz
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.176.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.176.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.176.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.176.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.176.195
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: convertix-api.xyz
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownHTTPS traffic detected: 142.250.176.196:443 -> 192.168.2.4:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: classification engineClassification label: mal52.troj.win@22/0@20/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2340,i,13848920191299947155,12211409323835193597,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2352 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://convertix-api.xyz"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2340,i,13848920191299947155,12211409323835193597,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2352 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1653629 URL: http://convertix-api.xyz Startdate: 01/04/2025 Architecture: WINDOWS Score: 52 15 convertix-api.xyz 2->15 26 Antivirus / Scanner detection for submitted sample 2->26 7 chrome.exe 2->7         started        10 chrome.exe 2->10         started        signatures3 28 Performs DNS queries to domains with low reputation 15->28 process4 dnsIp5 17 192.168.2.4, 443, 49202, 49237 unknown unknown 7->17 12 chrome.exe 7->12         started        process6 dnsIp7 19 convertix-api.xyz 12->19 22 www.google.com 142.250.176.196, 443, 49720 GOOGLEUS United States 12->22 24 google.com 12->24 signatures8 30 Performs DNS queries to domains with low reputation 19->30

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://convertix-api.xyz100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.65.238
truefalse
    high
    www.google.com
    142.250.176.196
    truefalse
      high
      convertix-api.xyz
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://c.pki.goog/r/gsr1.crlfalse
          high
          http://c.pki.goog/r/r4.crlfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.176.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1653629
            Start date and time:2025-04-01 13:49:20 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 52s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://convertix-api.xyz
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:11
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal52.troj.win@22/0@20/2
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.251.40.195, 142.250.81.238, 142.250.72.110, 142.251.167.84, 142.251.40.206, 142.251.40.142, 142.250.80.78, 23.203.176.221, 199.232.214.172, 142.250.65.238, 142.250.65.206, 184.31.69.3, 172.202.163.200
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: http://convertix-api.xyz
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 73
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 1, 2025 13:50:18.904021025 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:19.312493086 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:19.950922966 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:21.153501034 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:21.602921963 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:21.602961063 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:21.603032112 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:21.603233099 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:21.603245974 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:21.799602032 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:21.799675941 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:21.801035881 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:21.801048040 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:21.801260948 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:21.841420889 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:23.559372902 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:27.668709040 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:27.980709076 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:28.372157097 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:28.592298031 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:29.794030905 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:30.963105917 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:31.256601095 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.256937981 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.256963968 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.264292002 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:31.353431940 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.353466988 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.355431080 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.355451107 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.355499029 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.355534077 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.357383013 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.357453108 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.357495070 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.357523918 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.357538939 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.362472057 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.453619003 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.459089994 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.461499929 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.461555004 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.461571932 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 13:50:31.461612940 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 13:50:31.464900017 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.466510057 CEST49731443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.466607094 CEST44349731204.79.197.222192.168.2.4
            Apr 1, 2025 13:50:31.466711044 CEST49731443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.466892958 CEST49731443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.466914892 CEST44349731204.79.197.222192.168.2.4
            Apr 1, 2025 13:50:31.748974085 CEST44349731204.79.197.222192.168.2.4
            Apr 1, 2025 13:50:31.749227047 CEST49731443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.764370918 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:31.796580076 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:31.796653986 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:31.796797037 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:31.871840000 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:32.152817965 CEST49720443192.168.2.4142.250.176.196
            Apr 1, 2025 13:50:32.152863026 CEST44349720142.250.176.196192.168.2.4
            Apr 1, 2025 13:50:32.201109886 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:32.380218983 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:32.704226017 CEST4973480192.168.2.4142.250.176.195
            Apr 1, 2025 13:50:32.793365955 CEST8049734142.250.176.195192.168.2.4
            Apr 1, 2025 13:50:32.793483019 CEST4973480192.168.2.4142.250.176.195
            Apr 1, 2025 13:50:32.793670893 CEST4973480192.168.2.4142.250.176.195
            Apr 1, 2025 13:50:32.883192062 CEST8049734142.250.176.195192.168.2.4
            Apr 1, 2025 13:50:32.883214951 CEST8049734142.250.176.195192.168.2.4
            Apr 1, 2025 13:50:32.891774893 CEST4973480192.168.2.4142.250.176.195
            Apr 1, 2025 13:50:32.982289076 CEST8049734142.250.176.195192.168.2.4
            Apr 1, 2025 13:50:33.028423071 CEST4973480192.168.2.4142.250.176.195
            Apr 1, 2025 13:50:33.075292110 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:33.590926886 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:35.481061935 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:35.996835947 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 13:50:37.012803078 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 13:50:37.981561899 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 13:50:40.294015884 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 13:50:40.802298069 CEST49680443192.168.2.4204.79.197.222
            TimestampSource PortDest PortSource IPDest IP
            Apr 1, 2025 13:50:18.489871979 CEST53602961.1.1.1192.168.2.4
            Apr 1, 2025 13:50:18.565867901 CEST53492371.1.1.1192.168.2.4
            Apr 1, 2025 13:50:19.306946993 CEST53550061.1.1.1192.168.2.4
            Apr 1, 2025 13:50:21.498842001 CEST6415453192.168.2.41.1.1.1
            Apr 1, 2025 13:50:21.499169111 CEST5332953192.168.2.41.1.1.1
            Apr 1, 2025 13:50:21.596755981 CEST53641541.1.1.1192.168.2.4
            Apr 1, 2025 13:50:21.597203016 CEST53533291.1.1.1192.168.2.4
            Apr 1, 2025 13:50:23.805742979 CEST5723153192.168.2.41.1.1.1
            Apr 1, 2025 13:50:23.807907104 CEST5844153192.168.2.41.1.1.1
            Apr 1, 2025 13:50:23.819696903 CEST5189153192.168.2.41.1.1.1
            Apr 1, 2025 13:50:23.820040941 CEST5896453192.168.2.41.1.1.1
            Apr 1, 2025 13:50:23.905888081 CEST53572311.1.1.1192.168.2.4
            Apr 1, 2025 13:50:23.909147978 CEST53584411.1.1.1192.168.2.4
            Apr 1, 2025 13:50:23.910151958 CEST6092653192.168.2.41.1.1.1
            Apr 1, 2025 13:50:23.929023027 CEST53518911.1.1.1192.168.2.4
            Apr 1, 2025 13:50:23.945329905 CEST53589641.1.1.1192.168.2.4
            Apr 1, 2025 13:50:24.017261028 CEST53609261.1.1.1192.168.2.4
            Apr 1, 2025 13:50:24.021893024 CEST6376053192.168.2.41.1.1.1
            Apr 1, 2025 13:50:24.022133112 CEST6032653192.168.2.41.1.1.1
            Apr 1, 2025 13:50:24.121113062 CEST53637601.1.1.1192.168.2.4
            Apr 1, 2025 13:50:24.127816916 CEST53603261.1.1.1192.168.2.4
            Apr 1, 2025 13:50:24.168716908 CEST6546453192.168.2.48.8.8.8
            Apr 1, 2025 13:50:24.169212103 CEST5473553192.168.2.41.1.1.1
            Apr 1, 2025 13:50:24.267311096 CEST53547351.1.1.1192.168.2.4
            Apr 1, 2025 13:50:24.267684937 CEST53654648.8.8.8192.168.2.4
            Apr 1, 2025 13:50:25.186615944 CEST4920253192.168.2.41.1.1.1
            Apr 1, 2025 13:50:25.186944008 CEST5383253192.168.2.41.1.1.1
            Apr 1, 2025 13:50:25.289231062 CEST53538321.1.1.1192.168.2.4
            Apr 1, 2025 13:50:25.305422068 CEST53492021.1.1.1192.168.2.4
            Apr 1, 2025 13:50:30.324337959 CEST5085553192.168.2.41.1.1.1
            Apr 1, 2025 13:50:30.324732065 CEST5515653192.168.2.41.1.1.1
            Apr 1, 2025 13:50:30.428042889 CEST53551561.1.1.1192.168.2.4
            Apr 1, 2025 13:50:30.444894075 CEST53508551.1.1.1192.168.2.4
            Apr 1, 2025 13:50:30.445789099 CEST5502053192.168.2.41.1.1.1
            Apr 1, 2025 13:50:30.553792953 CEST53550201.1.1.1192.168.2.4
            Apr 1, 2025 13:50:32.114216089 CEST6364953192.168.2.41.1.1.1
            Apr 1, 2025 13:50:32.114809036 CEST5944153192.168.2.41.1.1.1
            Apr 1, 2025 13:50:32.217312098 CEST53594411.1.1.1192.168.2.4
            Apr 1, 2025 13:50:32.221580029 CEST53636491.1.1.1192.168.2.4
            Apr 1, 2025 13:50:32.259407043 CEST5152053192.168.2.41.1.1.1
            Apr 1, 2025 13:50:32.260081053 CEST6236553192.168.2.48.8.8.8
            Apr 1, 2025 13:50:32.356677055 CEST53623658.8.8.8192.168.2.4
            Apr 1, 2025 13:50:32.357408047 CEST53515201.1.1.1192.168.2.4
            Apr 1, 2025 13:50:36.347776890 CEST53555021.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 1, 2025 13:50:21.498842001 CEST192.168.2.41.1.1.10xa395Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:21.499169111 CEST192.168.2.41.1.1.10xa9b3Standard query (0)www.google.com65IN (0x0001)false
            Apr 1, 2025 13:50:23.805742979 CEST192.168.2.41.1.1.10x7e46Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:23.807907104 CEST192.168.2.41.1.1.10xe2b2Standard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:23.819696903 CEST192.168.2.41.1.1.10x2400Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:23.820040941 CEST192.168.2.41.1.1.10x29dStandard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:23.910151958 CEST192.168.2.41.1.1.10x1604Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.021893024 CEST192.168.2.41.1.1.10xb5f9Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.022133112 CEST192.168.2.41.1.1.10x4acdStandard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:24.168716908 CEST192.168.2.48.8.8.80x4b8cStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.169212103 CEST192.168.2.41.1.1.10x658aStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:25.186615944 CEST192.168.2.41.1.1.10x43bbStandard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:25.186944008 CEST192.168.2.41.1.1.10x147eStandard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:30.324337959 CEST192.168.2.41.1.1.10x8999Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:30.324732065 CEST192.168.2.41.1.1.10xeba5Standard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:30.445789099 CEST192.168.2.41.1.1.10xe548Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.114216089 CEST192.168.2.41.1.1.10x4b04Standard query (0)convertix-api.xyzA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.114809036 CEST192.168.2.41.1.1.10x392bStandard query (0)convertix-api.xyz65IN (0x0001)false
            Apr 1, 2025 13:50:32.259407043 CEST192.168.2.41.1.1.10x6d34Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.260081053 CEST192.168.2.48.8.8.80x1df7Standard query (0)google.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 1, 2025 13:50:21.596755981 CEST1.1.1.1192.168.2.40xa395No error (0)www.google.com142.250.176.196A (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:21.597203016 CEST1.1.1.1192.168.2.40xa9b3No error (0)www.google.com65IN (0x0001)false
            Apr 1, 2025 13:50:23.905888081 CEST1.1.1.1192.168.2.40x7e46Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:23.909147978 CEST1.1.1.1192.168.2.40xe2b2Name error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:23.929023027 CEST1.1.1.1192.168.2.40x2400Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:23.945329905 CEST1.1.1.1192.168.2.40x29dName error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:24.017261028 CEST1.1.1.1192.168.2.40x1604Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.121113062 CEST1.1.1.1192.168.2.40xb5f9Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.127816916 CEST1.1.1.1192.168.2.40x4acdName error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:24.267311096 CEST1.1.1.1192.168.2.40x658aNo error (0)google.com142.250.65.238A (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:24.267684937 CEST8.8.8.8192.168.2.40x4b8cNo error (0)google.com142.250.64.78A (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:25.289231062 CEST1.1.1.1192.168.2.40x147eName error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:25.305422068 CEST1.1.1.1192.168.2.40x43bbName error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:30.428042889 CEST1.1.1.1192.168.2.40xeba5Name error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:30.444894075 CEST1.1.1.1192.168.2.40x8999Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:30.553792953 CEST1.1.1.1192.168.2.40xe548Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.217312098 CEST1.1.1.1192.168.2.40x392bName error (3)convertix-api.xyznonenone65IN (0x0001)false
            Apr 1, 2025 13:50:32.221580029 CEST1.1.1.1192.168.2.40x4b04Name error (3)convertix-api.xyznonenoneA (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.356677055 CEST8.8.8.8192.168.2.40x1df7No error (0)google.com142.250.64.78A (IP address)IN (0x0001)false
            Apr 1, 2025 13:50:32.357408047 CEST1.1.1.1192.168.2.40x6d34No error (0)google.com142.251.32.110A (IP address)IN (0x0001)false
            • c.pki.goog
            Session IDSource IPSource PortDestination IPDestination Port
            0192.168.2.449734142.250.176.19580
            TimestampBytes transferredDirectionData
            Apr 1, 2025 13:50:32.793670893 CEST202OUTGET /r/gsr1.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 1, 2025 13:50:32.883214951 CEST223INHTTP/1.1 304 Not Modified
            Date: Tue, 01 Apr 2025 11:23:36 GMT
            Expires: Tue, 01 Apr 2025 12:13:36 GMT
            Age: 1616
            Last-Modified: Tue, 07 Jan 2025 07:28:00 GMT
            Cache-Control: public, max-age=3000
            Vary: Accept-Encoding
            Apr 1, 2025 13:50:32.891774893 CEST200OUTGET /r/r4.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 1, 2025 13:50:32.982289076 CEST223INHTTP/1.1 304 Not Modified
            Date: Tue, 01 Apr 2025 11:33:30 GMT
            Expires: Tue, 01 Apr 2025 12:23:30 GMT
            Age: 1022
            Last-Modified: Thu, 25 Jul 2024 14:48:00 GMT
            Cache-Control: public, max-age=3000
            Vary: Accept-Encoding


            05101520s020406080100

            Click to jump to process

            05101520s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:07:50:14
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:07:50:16
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2340,i,13848920191299947155,12211409323835193597,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2352 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:07:50:23
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://convertix-api.xyz"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly