Edit tour

Windows Analysis Report
http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaR

Overview

General Information

Sample URL:http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc
Analysis ID:1658194
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3244 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,8563054155903528755,1253471551842718358,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2184 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6764 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3DAvira URL Cloud: detection malicious, Label: phishing
Source: https://coaufu.com/favicon.icoAvira URL Cloud: Label: phishing
Source: unknownHTTPS traffic detected: 142.251.116.106:443 -> 192.168.2.4:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.224.182.206:443 -> 192.168.2.4:49722 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D HTTP/1.1Host: coaufu.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: coaufu.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3DAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: coaufu.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownHTTPS traffic detected: 142.251.116.106:443 -> 192.168.2.4:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.224.182.206:443 -> 192.168.2.4:49722 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3244_31137730Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3244_31137730Jump to behavior
Source: classification engineClassification label: mal56.win@22/2@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,8563054155903528755,1253471551842718358,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2184 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,8563054155903528755,1253471551842718358,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2184 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1658194 URL: http://coaufu.com/xr.php?e=... Startdate: 07/04/2025 Architecture: WINDOWS Score: 56 20 Antivirus detection for URL or domain 2->20 22 Antivirus / Scanner detection for submitted sample 2->22 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49204 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 coaufu.com 103.224.182.206, 443, 49722, 49723 TRELLIAN-AS-APTrellianPtyLimitedAU Australia 11->16 18 www.google.com 142.251.116.106, 443, 49720, 49741 GOOGLEUS United States 11->18

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://coaufu.com/favicon.ico100%Avira URL Cloudphishing

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
coaufu.com
103.224.182.206
truefalse
    unknown
    www.google.com
    142.251.116.106
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://coaufu.com/favicon.icofalse
      • Avira URL Cloud: phishing
      unknown
      http://c.pki.goog/r/gsr1.crlfalse
        high
        http://c.pki.goog/r/r4.crlfalse
          high
          https://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3Dfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            103.224.182.206
            coaufu.comAustralia
            133618TRELLIAN-AS-APTrellianPtyLimitedAUfalse
            142.251.116.106
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1658194
            Start date and time:2025-04-07 12:40:02 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 54s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:20
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal56.win@22/2@6/3
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.115.84, 142.250.80.14, 172.217.165.131, 142.250.81.238, 142.251.40.238, 142.250.64.110, 142.250.80.78, 199.232.210.172, 23.203.176.221, 142.250.65.174, 142.251.40.142, 142.251.35.174, 142.250.65.238, 142.250.72.99, 142.251.40.174, 142.250.80.35, 142.250.80.110, 23.204.23.20, 20.109.210.53
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnM
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):94
            Entropy (8bit):4.648751656165808
            Encrypted:false
            SSDEEP:3:qVZqcMsMgs0UL3AE+FoJRx+QVBK3z:qzsgs0HE+2XVBmz
            MD5:E96DDCEB1C305B9AD21EAAE42522C26F
            SHA1:AD08AE39A71ED5BA992B8B5DABC450D046354696
            SHA-256:9221CFEDFC5E03790F46C7890BCA21FCC47C5788D89DAB0AA0799C492B6AE78A
            SHA-512:1CC850F76467645447E9935F4DE13EDE698727B4FB598C7BD36DE2779596D8B5A85CB94B0CF1FB2259AD1D988F1F199E3F4C310DFDC22FCDD378B8E773F0DBD5
            Malicious:false
            Reputation:low
            URL:https://coaufu.com/favicon.ico
            Preview:<html><body><h1>403 Forbidden</h1>.Request forbidden by administrative rules..</body></html>..
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 73
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 7, 2025 12:41:00.671304941 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:01.079107046 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:01.857944965 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:03.061052084 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:05.054503918 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.054557085 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:05.054771900 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.054945946 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.054964066 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:05.328006983 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:05.328099966 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.329665899 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.329679012 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:05.330003023 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:05.373467922 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:05.467223883 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:06.366545916 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.366585016 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.366657019 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.369739056 CEST4972380192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.369877100 CEST4972480192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.375312090 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.375323057 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.525954962 CEST8049723103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.526020050 CEST8049724103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.526067972 CEST4972380192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.530292988 CEST4972480192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.720755100 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.720860004 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.721414089 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.721719027 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.866985083 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.867010117 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.867466927 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:06.869129896 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:06.869165897 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.073438883 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.073570967 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.073652029 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.136776924 CEST49722443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.136807919 CEST44349722103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.194856882 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.194889069 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.195034027 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.195259094 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.195270061 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.534492970 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.534883022 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.534907103 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.535257101 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.535262108 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.862294912 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.862370968 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:07.862555027 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.865663052 CEST49725443192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:07.865699053 CEST44349725103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:09.390084982 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:09.702339888 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:10.280361891 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:10.311604977 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:11.515445948 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:11.694749117 CEST8049723103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:11.695507050 CEST8049724103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:11.695530891 CEST8049724103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:11.695621014 CEST4972480192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:11.749737978 CEST4972380192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:12.412075043 CEST8049723103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:12.414819002 CEST4972380192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:12.415086985 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:12.716928005 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:13.329066992 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:13.922250986 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:14.530225039 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:15.011409998 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:41:15.106021881 CEST8049733142.251.40.195192.168.2.4
            Apr 7, 2025 12:41:15.106110096 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:41:15.106220007 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:41:15.200856924 CEST8049733142.251.40.195192.168.2.4
            Apr 7, 2025 12:41:15.201334953 CEST8049733142.251.40.195192.168.2.4
            Apr 7, 2025 12:41:15.207676888 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:41:15.303596973 CEST8049733142.251.40.195192.168.2.4
            Apr 7, 2025 12:41:15.358326912 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:41:15.376127005 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:15.376192093 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:15.376255989 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:16.937242031 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:17.157890081 CEST49720443192.168.2.4142.251.116.106
            Apr 7, 2025 12:41:17.157926083 CEST44349720142.251.116.106192.168.2.4
            Apr 7, 2025 12:41:18.734132051 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:19.889122009 CEST49671443192.168.2.4204.79.197.203
            Apr 7, 2025 12:41:21.755745888 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:28.347107887 CEST49678443192.168.2.420.189.173.27
            Apr 7, 2025 12:41:31.366116047 CEST4968180192.168.2.42.17.190.73
            Apr 7, 2025 12:41:56.702372074 CEST4972480192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:56.857295036 CEST8049724103.224.182.206192.168.2.4
            Apr 7, 2025 12:41:57.421782970 CEST4972380192.168.2.4103.224.182.206
            Apr 7, 2025 12:41:57.578294039 CEST8049723103.224.182.206192.168.2.4
            Apr 7, 2025 12:42:05.017755985 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:05.017838001 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:05.017935038 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:05.018099070 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:05.018117905 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:05.286921024 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:05.287441969 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:05.287466049 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:15.297261953 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:15.297350883 CEST44349741142.251.116.106192.168.2.4
            Apr 7, 2025 12:42:15.297419071 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:16.796724081 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:42:16.892649889 CEST8049733142.251.40.195192.168.2.4
            Apr 7, 2025 12:42:16.892709017 CEST4973380192.168.2.4142.251.40.195
            Apr 7, 2025 12:42:17.156366110 CEST49741443192.168.2.4142.251.116.106
            Apr 7, 2025 12:42:17.156414032 CEST44349741142.251.116.106192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 7, 2025 12:41:00.892297029 CEST53501461.1.1.1192.168.2.4
            Apr 7, 2025 12:41:00.910510063 CEST53545741.1.1.1192.168.2.4
            Apr 7, 2025 12:41:01.693669081 CEST53613021.1.1.1192.168.2.4
            Apr 7, 2025 12:41:04.953074932 CEST5672153192.168.2.41.1.1.1
            Apr 7, 2025 12:41:04.953324080 CEST6173353192.168.2.41.1.1.1
            Apr 7, 2025 12:41:05.052822113 CEST53617331.1.1.1192.168.2.4
            Apr 7, 2025 12:41:05.053483963 CEST53567211.1.1.1192.168.2.4
            Apr 7, 2025 12:41:06.210540056 CEST4933453192.168.2.41.1.1.1
            Apr 7, 2025 12:41:06.210691929 CEST5958453192.168.2.41.1.1.1
            Apr 7, 2025 12:41:06.226522923 CEST6127553192.168.2.41.1.1.1
            Apr 7, 2025 12:41:06.226670980 CEST4920453192.168.2.41.1.1.1
            Apr 7, 2025 12:41:06.308803082 CEST53493341.1.1.1192.168.2.4
            Apr 7, 2025 12:41:06.328372002 CEST53612751.1.1.1192.168.2.4
            Apr 7, 2025 12:41:06.382051945 CEST53595841.1.1.1192.168.2.4
            Apr 7, 2025 12:41:06.398552895 CEST53492041.1.1.1192.168.2.4
            Apr 7, 2025 12:41:18.804855108 CEST53599761.1.1.1192.168.2.4
            Apr 7, 2025 12:41:37.771140099 CEST53638901.1.1.1192.168.2.4
            Apr 7, 2025 12:42:00.401283026 CEST53558491.1.1.1192.168.2.4
            Apr 7, 2025 12:42:00.507849932 CEST53550091.1.1.1192.168.2.4
            Apr 7, 2025 12:42:03.413620949 CEST53582281.1.1.1192.168.2.4
            Apr 7, 2025 12:42:08.821932077 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPChecksumCodeType
            Apr 7, 2025 12:41:06.382175922 CEST192.168.2.41.1.1.1c21c(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 7, 2025 12:41:04.953074932 CEST192.168.2.41.1.1.10xac0eStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:04.953324080 CEST192.168.2.41.1.1.10xc7d7Standard query (0)www.google.com65IN (0x0001)false
            Apr 7, 2025 12:41:06.210540056 CEST192.168.2.41.1.1.10x1bd1Standard query (0)coaufu.comA (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:06.210691929 CEST192.168.2.41.1.1.10x6b29Standard query (0)coaufu.com65IN (0x0001)false
            Apr 7, 2025 12:41:06.226522923 CEST192.168.2.41.1.1.10xb4e4Standard query (0)coaufu.comA (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:06.226670980 CEST192.168.2.41.1.1.10x8aeeStandard query (0)coaufu.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 7, 2025 12:41:05.052822113 CEST1.1.1.1192.168.2.40xc7d7No error (0)www.google.com65IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.106A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.105A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.103A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.99A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.104A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:05.053483963 CEST1.1.1.1192.168.2.40xac0eNo error (0)www.google.com142.251.116.147A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:06.308803082 CEST1.1.1.1192.168.2.40x1bd1No error (0)coaufu.com103.224.182.206A (IP address)IN (0x0001)false
            Apr 7, 2025 12:41:06.328372002 CEST1.1.1.1192.168.2.40xb4e4No error (0)coaufu.com103.224.182.206A (IP address)IN (0x0001)false
            • coaufu.com
            • c.pki.goog
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449723103.224.182.206801016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 7, 2025 12:41:11.694749117 CEST233INHTTP/1.1 408 Request Time-out
            Content-length: 110
            Cache-Control: no-cache
            Connection: close
            Content-Type: text/html
            Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
            Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
            Apr 7, 2025 12:41:57.421782970 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449724103.224.182.206801016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 7, 2025 12:41:11.695507050 CEST233INHTTP/1.1 408 Request Time-out
            Content-length: 110
            Cache-Control: no-cache
            Connection: close
            Content-Type: text/html
            Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
            Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
            Apr 7, 2025 12:41:56.702372074 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination Port
            2192.168.2.449733142.251.40.19580
            TimestampBytes transferredDirectionData
            Apr 7, 2025 12:41:15.106220007 CEST202OUTGET /r/gsr1.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 7, 2025 12:41:15.201334953 CEST223INHTTP/1.1 304 Not Modified
            Date: Mon, 07 Apr 2025 09:53:36 GMT
            Expires: Mon, 07 Apr 2025 10:43:36 GMT
            Age: 2859
            Last-Modified: Tue, 07 Jan 2025 07:28:00 GMT
            Cache-Control: public, max-age=3000
            Vary: Accept-Encoding
            Apr 7, 2025 12:41:15.207676888 CEST200OUTGET /r/r4.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 7, 2025 12:41:15.303596973 CEST1243INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
            Cross-Origin-Resource-Policy: cross-origin
            Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
            Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
            Content-Length: 530
            X-Content-Type-Options: nosniff
            Server: sffe
            X-XSS-Protection: 0
            Date: Mon, 07 Apr 2025 10:07:11 GMT
            Expires: Mon, 07 Apr 2025 10:57:11 GMT
            Cache-Control: public, max-age=3000
            Age: 2044
            Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
            Content-Type: application/pkix-crl
            Vary: Accept-Encoding
            Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
            Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449722103.224.182.2064431016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 10:41:06 UTC2013OUTGET /xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0 [TRUNCATED]
            Host: coaufu.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 10:41:07 UTC150INHTTP/1.1 200 OK
            date: Mon, 07 Apr 2025 10:41:06 GMT
            server: Apache
            content-length: 0
            content-type: text/html; charset=UTF-8
            connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449725103.224.182.2064431016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 10:41:07 UTC1936OUTGET /favicon.ico HTTP/1.1
            Host: coaufu.com
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9 [TRUNCATED]
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 10:41:07 UTC76INData Raw: 48 54 54 50 2f 31 2e 30 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 63 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 63 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 0d 0a 0d 0a
            Data Ascii: HTTP/1.0 403 Forbiddencache-control: no-cachecontent-type: text/html
            2025-04-07 10:41:07 UTC94INData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 52 65 71 75 65 73 74 20 66 6f 72 62 69 64 64 65 6e 20 62 79 20 61 64 6d 69 6e 69 73 74 72 61 74 69 76 65 20 72 75 6c 65 73 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0a
            Data Ascii: <html><body><h1>403 Forbidden</h1>Request forbidden by administrative rules.</body></html>


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:06:40:56
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:06:40:59
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,8563054155903528755,1253471551842718358,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2184 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:06:41:05
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php?e=10kms74ZqPpGbF6GeOnb5349fnpoVGpGa0xzT0VWM21jTUZib1VKckdGZDdyc1B1L08rRVdPYzlxRU1BV3ZyZWdBTE9zSFlrckRmbHBpZW0xZnBTbHZOeHJHeGRJZGN2NW5YTERCbDY3bWh3a0RZUWM2WHgzNHZGVTFJa2EzRHZMc05RVkdmT0M3TllTUElCTlRtd1BXaCtrZE5SaTMyZXZlMTlzdW9FdVBPemROankydFc4bkh1bi9YVWw3V1JaTW5VaHJNRzg5SWlaRFJ2bFA1MlhzQWt5UzJ2SkFlTS8wZXF1RTF2QmpQMC80NFd2a0JyWkpmSUI0eGJuUmx3dlJ6a05RaDJuMEpqRDVuQ2JlZTZ6TjRKU0dLN09scVZNREpyQ3V6TUJjdG9Lem1JZTUvc2QyNzFBVytLck9CZGVkWVFOWVVtcmtDalY2aXNZYzBJd1d0YTdCU3lhR3FYRm5QaFIxK0N1cmgrUjVoc01ZRVFRK1kzZkd0QXM0WmFxNjQrZGxUMnZyK2J6R29CYjJRSXRHRlZBNG94SGJGc1NUMWlNMEZFL1R5dG9TcmRvZFh1eTRwMUcyRXVhMHZXdG4zQm5RSlZzMVpLZkJWZjRDOExLem8vL0lXdFVKWHVPVFVLVDJsNWppWURpTnkvTm95UGcxY0xtY0ZFdnlrZXAxTDZiRjRFaTRIUUhZRVRUTmhCZjdCdDFhVE5ORDBWTkwyYmZNODg2SmxFN0paMi9melVIWUovUzlNeDJvRDZjS3Z3dGE1WTJuS0FLd2xzM3FLdThWU0RzRVBPRXdKRmpNZ1NDWDRNUHgrOC9raGJLcVFWd0puSVk3NTdyeVZzMEw3UDhCdzV6OFdkWGJ5Nm93YnVaM3l5bzJkOG9DOEM3emJ0WmxDb2N6OUw3eDJGWUVhelBHSCtRNUQ3VkF4ZmEwN3dpSDI4QS9DdFBoMFlhanBlWGZxNmNnMStrYlJsdk5qVm9OVzhSS01ua1czUElRYVRuR0RxNFovTnVzVEw1ODh5cForRGVYNklIYkk4WTIvbUIveGlzeUpJb2lrQThTTFlTdVVSbzFubEd1YWdEbENGRmk0NkYyWmtwWCs4eDQ5NWttYVRkT0FnV2JvT1JJblVtSU9GNlJ1NnptZFdaeHJWK0VDalZ3a0Y3Y0ZTQ21uL04xNnJ6TXlyTVBnQmlQR3JsMzFWN2dQRGRmUENQRk9CRXVneTBXTWovK09OSzVQd0Vrbmo3SFViQm9KNjE0ZERSQ2Fyak9iZkZaZzVsUk5vN281NzFnL1ZZQVN5ZXYvOXoxZzhEc2FscnRrYlpzR1VVU3M2cVE9PQ%3D%3D"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly