Edit tour

Windows Analysis Report
https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNz

Overview

General Information

Sample URL:https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1
Analysis ID:1658793
Infos:

Detection

Score:1
Range:0 - 100
Confidence:80%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2324 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2428,i,9608192530633808466,17440926814177086415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2456 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&saHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.251.40.196:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.176.132.253:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.176.132.253:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.227
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa HTTP/1.1Host: firstinterstat09.linkpc.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: firstinterstat09.linkpc.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&saAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: firstinterstat09.linkpc.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 07 Apr 2025 22:55:37 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 07 Apr 2025 22:55:37 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 142.251.40.196:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.176.132.253:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.176.132.253:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir2324_612852366Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir2324_612852366Jump to behavior
Source: classification engineClassification label: clean1.win@21/4@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2428,i,9608192530633808466,17440926814177086415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2456 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2428,i,9608192530633808466,17440926814177086415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2456 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1658793 URL: https://firstinterstat09.li... Startdate: 08/04/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49171 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.251.40.196, 443, 49723, 49740 GOOGLEUS United States 10->15 17 firstinterstat09.linkpc.net 54.176.132.253, 443, 49725, 49726 AMAZON-02US United States 10->17

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://firstinterstat09.linkpc.net/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.40.196
truefalse
    high
    firstinterstat09.linkpc.net
    54.176.132.253
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://c.pki.goog/r/gsr1.crlfalse
        high
        http://c.pki.goog/r/r4.crlfalse
          high
          https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&safalse
            unknown
            https://firstinterstat09.linkpc.net/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            54.176.132.253
            firstinterstat09.linkpc.netUnited States
            16509AMAZON-02USfalse
            142.251.40.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1658793
            Start date and time:2025-04-08 00:54:29 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 5s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:20
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean1.win@21/4@4/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.65.238, 142.251.163.84, 142.250.176.206, 142.251.40.99, 142.251.35.174, 142.250.81.238, 142.251.40.110, 23.210.73.6, 23.203.176.221, 208.89.73.17, 142.251.40.238, 142.250.80.14, 142.251.32.110, 142.250.65.206, 142.250.80.78, 142.250.65.195, 142.251.35.163, 184.31.69.3, 20.12.23.50
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&amp;i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&amp;p=m&amp;s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&amp;t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&amp;u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&amp;sa
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):315
            Entropy (8bit):5.0572271090563765
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
            MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
            SHA1:A82190FC530C265AA40A045C21770D967F4767B8
            SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
            SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
            Malicious:false
            Reputation:low
            URL:https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):315
            Entropy (8bit):5.0572271090563765
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
            MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
            SHA1:A82190FC530C265AA40A045C21770D967F4767B8
            SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
            SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
            Malicious:false
            Reputation:low
            URL:https://firstinterstat09.linkpc.net/favicon.ico
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 73
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 8, 2025 00:55:23.226994038 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:30.212774038 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:30.553872108 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:31.239521980 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:32.460531950 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:32.835649014 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:34.530745029 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.530786037 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:34.530910015 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.531179905 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.531193018 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:34.747967958 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:34.748043060 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.749272108 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.749279976 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:34.749670029 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:34.804651022 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:34.867161989 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:36.778363943 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.778405905 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:36.778476954 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.778860092 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.778901100 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:36.778956890 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.779063940 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.779078007 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:36.779175043 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:36.779184103 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.118526936 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.118604898 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.121819019 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.121825933 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.122035027 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.122323990 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.126873016 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.126950026 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.127854109 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.127861977 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.128189087 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.164299965 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.174381971 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.435281038 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.435420990 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.435475111 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.436250925 CEST49725443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.436269045 CEST4434972554.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.533766031 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.576316118 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.698349953 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.698447943 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:37.698502064 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.699409008 CEST49726443192.168.2.454.176.132.253
            Apr 8, 2025 00:55:37.699425936 CEST4434972654.176.132.253192.168.2.4
            Apr 8, 2025 00:55:38.519167900 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:38.826214075 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:39.435585976 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:39.683773994 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:40.638736010 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:42.476408005 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:42.783219099 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.783838987 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.783864975 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.788070917 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:42.876322985 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.877110958 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.877188921 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.877866983 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.877928972 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.877991915 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.878598928 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.879918098 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.879956007 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:42.879985094 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.880004883 CEST49710443192.168.2.4204.79.197.222
            Apr 8, 2025 00:55:42.973114967 CEST44349710204.79.197.222192.168.2.4
            Apr 8, 2025 00:55:43.039174080 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:43.240098000 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:43.335499048 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:55:43.335577011 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:43.335674047 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:43.398380041 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:43.430721045 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:55:43.430946112 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:55:43.430988073 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:55:43.431045055 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:43.436264992 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:43.531239033 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:55:43.585840940 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:55:44.603116989 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:44.751185894 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:44.751313925 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:44.751499891 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:45.009759903 CEST49723443192.168.2.4142.251.40.196
            Apr 8, 2025 00:55:45.009787083 CEST44349723142.251.40.196192.168.2.4
            Apr 8, 2025 00:55:47.007777929 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:47.851383924 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:55:49.293628931 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 00:55:51.809463024 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:55:57.455737114 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 00:56:01.414479017 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 00:56:34.493228912 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:34.493294954 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:34.493408918 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:34.493567944 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:34.493582010 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:34.696358919 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:34.696875095 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:34.696922064 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:43.836314917 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:56:43.931126118 CEST8049733142.251.40.227192.168.2.4
            Apr 8, 2025 00:56:43.931561947 CEST4973380192.168.2.4142.251.40.227
            Apr 8, 2025 00:56:44.692430019 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:44.692548990 CEST44349740142.251.40.196192.168.2.4
            Apr 8, 2025 00:56:44.692637920 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:45.009985924 CEST49740443192.168.2.4142.251.40.196
            Apr 8, 2025 00:56:45.010010004 CEST44349740142.251.40.196192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 8, 2025 00:55:30.796659946 CEST53621721.1.1.1192.168.2.4
            Apr 8, 2025 00:55:30.944226980 CEST53508861.1.1.1192.168.2.4
            Apr 8, 2025 00:55:31.773458958 CEST53593761.1.1.1192.168.2.4
            Apr 8, 2025 00:55:31.891952991 CEST53595951.1.1.1192.168.2.4
            Apr 8, 2025 00:55:34.430536985 CEST6149953192.168.2.41.1.1.1
            Apr 8, 2025 00:55:34.430670023 CEST4956753192.168.2.41.1.1.1
            Apr 8, 2025 00:55:34.528752089 CEST53495671.1.1.1192.168.2.4
            Apr 8, 2025 00:55:34.529648066 CEST53614991.1.1.1192.168.2.4
            Apr 8, 2025 00:55:36.640233040 CEST5727753192.168.2.41.1.1.1
            Apr 8, 2025 00:55:36.640501976 CEST5946653192.168.2.41.1.1.1
            Apr 8, 2025 00:55:36.769999027 CEST53594661.1.1.1192.168.2.4
            Apr 8, 2025 00:55:36.775983095 CEST53572771.1.1.1192.168.2.4
            Apr 8, 2025 00:55:48.984692097 CEST53620121.1.1.1192.168.2.4
            Apr 8, 2025 00:56:07.968905926 CEST53502881.1.1.1192.168.2.4
            Apr 8, 2025 00:56:30.375215054 CEST53549511.1.1.1192.168.2.4
            Apr 8, 2025 00:56:30.469319105 CEST53491711.1.1.1192.168.2.4
            Apr 8, 2025 00:56:33.043684959 CEST53611951.1.1.1192.168.2.4
            Apr 8, 2025 00:56:37.905972958 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 8, 2025 00:55:34.430536985 CEST192.168.2.41.1.1.10x30e3Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 8, 2025 00:55:34.430670023 CEST192.168.2.41.1.1.10xa475Standard query (0)www.google.com65IN (0x0001)false
            Apr 8, 2025 00:55:36.640233040 CEST192.168.2.41.1.1.10x1bbeStandard query (0)firstinterstat09.linkpc.netA (IP address)IN (0x0001)false
            Apr 8, 2025 00:55:36.640501976 CEST192.168.2.41.1.1.10x2655Standard query (0)firstinterstat09.linkpc.net65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 8, 2025 00:55:34.528752089 CEST1.1.1.1192.168.2.40xa475No error (0)www.google.com65IN (0x0001)false
            Apr 8, 2025 00:55:34.529648066 CEST1.1.1.1192.168.2.40x30e3No error (0)www.google.com142.251.40.196A (IP address)IN (0x0001)false
            Apr 8, 2025 00:55:36.775983095 CEST1.1.1.1192.168.2.40x1bbeNo error (0)firstinterstat09.linkpc.net54.176.132.253A (IP address)IN (0x0001)false
            • firstinterstat09.linkpc.net
            • c.pki.goog
            Session IDSource IPSource PortDestination IPDestination Port
            0192.168.2.449733142.251.40.22780
            TimestampBytes transferredDirectionData
            Apr 8, 2025 00:55:43.335674047 CEST202OUTGET /r/gsr1.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 8, 2025 00:55:43.430946112 CEST1254INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
            Cross-Origin-Resource-Policy: cross-origin
            Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
            Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
            Content-Length: 1739
            X-Content-Type-Options: nosniff
            Server: sffe
            X-XSS-Protection: 0
            Date: Mon, 07 Apr 2025 22:44:49 GMT
            Expires: Mon, 07 Apr 2025 23:34:49 GMT
            Cache-Control: public, max-age=3000
            Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
            Content-Type: application/pkix-crl
            Vary: Accept-Encoding
            Age: 654
            Data Raw: 30 82 06 c7 30 82 05 af 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69 67 6e 20 6e 76 2d 73 61 31 10 30 0e 06 03 55 04 0b 13 07 52 6f 6f 74 20 43 41 31 1b 30 19 06 03 55 04 03 13 12 47 6c 6f 62 61 6c 53 69 67 6e 20 52 6f 6f 74 20 43 41 17 0d 32 35 30 34 30 37 30 30 30 30 30 30 5a 17 0d 32 35 30 37 31 35 30 30 30 30 30 30 5a 30 82 04 f1 30 2a 02 0b 04 00 00 00 00 01 1e 44 a5 e4 04 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 29 45 c3 a8 0f 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 20 19 c1 8d 68 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2c 5e 7f 1a 88 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 15 4b 5a [TRUNCATED]
            Data Ascii: 000*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA250407000000Z250715000000Z00*D141125000000Z00U0*)E141125000000Z00U0* h141125000000Z00U0*,^141125000000Z00U0*KZ160107000000Z00U0*/NIR170419000000Z00U0*/NG170419000000Z00U0*/N9191120000000Z00U0*/N=k191204000000Z00U
            Apr 8, 2025 00:55:43.430988073 CEST1198INData Raw: 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2f 4e e1 3b 58 17 0d 31 39 31 32 30 34 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2d 02 0e 47 c3 0f ff 8a 61 9a 37 f5 a8 2e f0 b5 75 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30
            Data Ascii: 0*/N;X191204000000Z00U0-Ga7.u200630000000Z00U0-GA>ThA200630000000Z00U0-GK&TA+200630000000Z00U0*6::200711160000Z00U0/vSBS
            Apr 8, 2025 00:55:43.436264992 CEST200OUTGET /r/r4.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 8, 2025 00:55:43.531239033 CEST1243INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
            Cross-Origin-Resource-Policy: cross-origin
            Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
            Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
            Content-Length: 530
            X-Content-Type-Options: nosniff
            Server: sffe
            X-XSS-Protection: 0
            Date: Mon, 07 Apr 2025 22:37:11 GMT
            Expires: Mon, 07 Apr 2025 23:27:11 GMT
            Cache-Control: public, max-age=3000
            Age: 1112
            Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
            Content-Type: application/pkix-crl
            Vary: Accept-Encoding
            Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
            Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44972554.176.132.253443420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 22:55:37 UTC1146OUTGET /v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa HTTP/1.1
            Host: firstinterstat09.linkpc.net
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 22:55:37 UTC164INHTTP/1.1 404 Not Found
            Date: Mon, 07 Apr 2025 22:55:37 GMT
            Server: Apache
            Content-Length: 315
            Connection: close
            Content-Type: text/html; charset=iso-8859-1
            2025-04-07 22:55:37 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44972654.176.132.253443420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 22:55:37 UTC1086OUTGET /favicon.ico HTTP/1.1
            Host: firstinterstat09.linkpc.net
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 22:55:37 UTC164INHTTP/1.1 404 Not Found
            Date: Mon, 07 Apr 2025 22:55:37 GMT
            Server: Apache
            Content-Length: 315
            Connection: close
            Content-Type: text/html; charset=iso-8859-1
            2025-04-07 22:55:37 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:0
            Start time:18:55:25
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:1
            Start time:18:55:28
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2428,i,9608192530633808466,17440926814177086415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2456 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:18:55:35
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://firstinterstat09.linkpc.net/v/n/login1?next=https://www.google.com/YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498&i=NjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3&p=m&s=AVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A&t=M3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0=&u=aHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly