Edit tour

Windows Analysis Report
https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni

Overview

General Information

Sample URL:https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni
Analysis ID:1665629
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected suspicious crossdomain redirect

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2788 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1940,i,6075087294735186206,16067551633918766053,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1972 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6948 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://sendgrid.production-us12.com/favicon.icoAvira URL Cloud: Label: phishing
Source: https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3DHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 173.194.219.99:443 -> 192.168.2.6:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.203.31:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.203.31:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.172.83.250:443 -> 192.168.2.6:49700 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: mindlabs.topleads.co to https://sendgrid.production-us12.com?email=yifzjikj5ujtefdhdscrylwb9gvfg8q%2bvcqgaktl3bpgz3yd%2fs5yif7sra%2fve1186mwgkvz2z2i5vkvsqx2ofnhljmfbke6dfi74%2fycgiz4fuk1xu5imzhvzzmvuxovji8y7ouh4l3ppbqzt9mmsf5bo%2fgtdklv15vky6gwmskacuoezyvd2wloxetig92uff0oyh4m1sgd9yocwwrvexc86wig5llpbawa7r7ssk%2f9imdmzkiwxeyvy4tmpn38p2eugq%2bwf%2b9yppfmylzxh%2fdzwthfkmrfds8jf3odbc8nbkbzygjgwr4mnz3s7txmbgw7k8lfnu6yntl4mngmt6g%3d%3d
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.9.94
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni HTTP/1.1Host: mindlabs.topleads.coConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D HTTP/1.1Host: sendgrid.production-us12.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sendgrid.production-us12.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3DAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: mindlabs.topleads.co
Source: global trafficDNS traffic detected: DNS query: sendgrid.production-us12.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Tue, 15 Apr 2025 15:50:30 GMTContent-Type: text/htmlContent-Length: 564Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 173.194.219.99:443 -> 192.168.2.6:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.203.31:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.203.31:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.172.83.250:443 -> 192.168.2.6:49700 version: TLS 1.2
Source: classification engineClassification label: mal48.win@24/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1940,i,6075087294735186206,16067551633918766053,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1972 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1940,i,6075087294735186206,16067551633918766053,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1972 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1665629 URL: https://mindlabs.topleads.c... Startdate: 15/04/2025 Architecture: WINDOWS Score: 48 24 Antivirus detection for URL or domain 2->24 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.16 unknown unknown 6->14 16 192.168.2.6, 138, 443, 49681 unknown unknown 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 173.194.219.99, 443, 49697, 49712 GOOGLEUS United States 11->18 20 sendgrid.production-us12.com 31.172.83.250, 443, 49700, 49701 DE-FIRSTCOLOwwwfirst-colonetDE Germany 11->20 22 2 other IPs or domains 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://sendgrid.production-us12.com/favicon.ico100%Avira URL Cloudphishing

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
173.194.219.99
truefalse
    high
    sendgrid.production-us12.com
    31.172.83.250
    truefalse
      unknown
      mindlabs.activehosted.com
      104.17.203.31
      truefalse
        unknown
        mindlabs.topleads.co
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://c.pki.goog/r/r4.crlfalse
            high
            https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3Dfalse
              unknown
              https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKnifalse
                unknown
                https://sendgrid.production-us12.com/favicon.icofalse
                • Avira URL Cloud: phishing
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                104.17.203.31
                mindlabs.activehosted.comUnited States
                13335CLOUDFLARENETUSfalse
                173.194.219.99
                www.google.comUnited States
                15169GOOGLEUSfalse
                31.172.83.250
                sendgrid.production-us12.comGermany
                44066DE-FIRSTCOLOwwwfirst-colonetDEfalse
                IP
                192.168.2.16
                192.168.2.6
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1665629
                Start date and time:2025-04-15 17:49:19 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 7s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@24/4@6/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 108.177.122.113, 108.177.122.100, 108.177.122.102, 108.177.122.101, 108.177.122.138, 108.177.122.139, 172.217.215.94, 172.217.215.138, 172.217.215.100, 172.217.215.102, 172.217.215.113, 172.217.215.139, 172.217.215.101, 74.125.21.84, 74.125.21.101, 74.125.21.113, 74.125.21.102, 74.125.21.138, 74.125.21.100, 74.125.21.139, 74.125.138.138, 74.125.138.101, 74.125.138.100, 74.125.138.139, 74.125.138.113, 74.125.138.102, 173.194.219.139, 173.194.219.101, 173.194.219.138, 173.194.219.100, 173.194.219.102, 173.194.219.113, 23.218.145.76, 64.233.185.100, 64.233.185.113, 64.233.185.138, 64.233.185.139, 64.233.185.102, 64.233.185.101, 74.125.136.94, 142.250.9.101, 142.250.9.100, 142.250.9.139, 142.250.9.113, 142.250.9.138, 142.250.9.102, 142.251.15.94, 23.79.17.61, 4.245.163.56
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):564
                Entropy (8bit):4.775290370533887
                Encrypted:false
                SSDEEP:12:TjeRHVIdtklI5rRCNGlTF5TF5TF5TF5TF5TFK:neRH688lTPTPTPTPTPTc
                MD5:5DA4C1420F84EC727D1B6BDD0D46E62E
                SHA1:280D08D142F7386283F420444EC48E1CDBFD61BB
                SHA-256:3C8CC37A98346BD0123B35E5CCD87BD07D69914DAE04F8B49F61C150D96E9D1F
                SHA-512:7C51A628831D0236E8D314C71732B8A62E06334431D10F7C293C49B23665B2A6A1DDBC4772009010955B5228EA4A5CD97FB93581CE391EE1792E8A198B76111A
                Malicious:false
                Reputation:low
                URL:https://sendgrid.production-us12.com/favicon.ico
                Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.18.0 (Ubuntu)</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):588
                Entropy (8bit):4.727576914852944
                Encrypted:false
                SSDEEP:12:TiUDW5VIFUDWOlI5rRCNGlTF5TF5TF5TF5TF5TFK:eUDW5aUDWY8lTPTPTPTPTPTc
                MD5:1AFAC349CEA899675DE7D9F7F29EABA0
                SHA1:F924BE061A24E2E275E25193D4EB6FDAC4EEC9D6
                SHA-256:C48B71948160F9CC2AE1E8C93498E2C3EC4C3544D8FE7A4D2F85147444F862EC
                SHA-512:CD3B7875AD23CF017CE25D49E7588B4BC4BB2E4A4D909CF2084CB0496E9378F00327EC4A55B93637E389AF66B8A3F9FB4133B868C505C8A4B0BAAA2E193C790E
                Malicious:false
                Reputation:low
                URL:https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D
                Preview:<html>..<head><title>500 Internal Server Error</title></head>..<body>..<center><h1>500 Internal Server Error</h1></center>..<hr><center>nginx/1.18.0 (Ubuntu)</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 72
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Apr 15, 2025 17:50:13.438204050 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:13.750277996 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:14.359585047 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:15.562845945 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:17.969014883 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:22.016918898 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:22.351763964 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:22.797606945 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:23.016180992 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:24.314064980 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:25.970483065 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:25.970530033 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:25.970611095 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:25.970817089 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:25.970834017 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:26.190947056 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:26.191080093 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:26.192420959 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:26.192429066 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:26.192617893 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:26.235220909 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:26.719549894 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:27.125461102 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.125500917 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.125932932 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.130057096 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.130083084 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.130230904 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.130603075 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.130619049 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.130765915 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.130784988 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.367285013 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.367425919 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.368360043 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.368560076 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.411461115 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.411469936 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.411684036 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.411782026 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.411806107 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.411966085 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:27.412055969 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.456273079 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:27.459259033 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:28.435064077 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:28.435185909 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:28.435234070 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:28.437992096 CEST49699443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:28.438000917 CEST44349699104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:28.567990065 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:28.568079948 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:28.568173885 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:28.568429947 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:28.568466902 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:28.998305082 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:28.998421907 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:28.999763012 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:28.999793053 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.000025988 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.001539946 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.044301987 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.413908958 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.413969040 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.414038897 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.414891005 CEST49700443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.414932966 CEST4434970031.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.569874048 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.569924116 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.569992065 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.570296049 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:29.570312023 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:29.995178938 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:30.006212950 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:30.006253958 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:30.007961035 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:30.007972002 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:30.414458036 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:30.414537907 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:30.414647102 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:30.415508986 CEST49701443192.168.2.631.172.83.250
                Apr 15, 2025 17:50:30.415528059 CEST4434970131.172.83.250192.168.2.6
                Apr 15, 2025 17:50:31.532373905 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:32.407346010 CEST49672443192.168.2.6204.79.197.203
                Apr 15, 2025 17:50:34.173113108 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:50:34.279966116 CEST8049705142.250.9.94192.168.2.6
                Apr 15, 2025 17:50:34.280067921 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:50:34.280260086 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:50:34.388299942 CEST8049705142.250.9.94192.168.2.6
                Apr 15, 2025 17:50:34.388828039 CEST8049705142.250.9.94192.168.2.6
                Apr 15, 2025 17:50:34.437997103 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:50:36.196408987 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:36.196485996 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:36.196569920 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:36.691071033 CEST49697443192.168.2.6173.194.219.99
                Apr 15, 2025 17:50:36.691095114 CEST44349697173.194.219.99192.168.2.6
                Apr 15, 2025 17:50:41.141829014 CEST49678443192.168.2.620.42.65.91
                Apr 15, 2025 17:50:42.346218109 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:42.346422911 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:50:42.346559048 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:42.691010952 CEST49698443192.168.2.6104.17.203.31
                Apr 15, 2025 17:50:42.691025972 CEST44349698104.17.203.31192.168.2.6
                Apr 15, 2025 17:51:25.924350977 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:25.924407959 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:25.924513102 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:25.924854994 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:25.924864054 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:26.143320084 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:26.143832922 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:26.143848896 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:32.415795088 CEST443496812.23.227.215192.168.2.6
                Apr 15, 2025 17:51:32.415821075 CEST443496812.23.227.215192.168.2.6
                Apr 15, 2025 17:51:32.416063070 CEST49681443192.168.2.62.23.227.215
                Apr 15, 2025 17:51:34.610897064 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:51:34.717360973 CEST8049705142.250.9.94192.168.2.6
                Apr 15, 2025 17:51:34.717430115 CEST4970580192.168.2.6142.250.9.94
                Apr 15, 2025 17:51:36.147458076 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:36.147500038 CEST44349712173.194.219.99192.168.2.6
                Apr 15, 2025 17:51:36.147550106 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:36.691802025 CEST49712443192.168.2.6173.194.219.99
                Apr 15, 2025 17:51:36.691838980 CEST44349712173.194.219.99192.168.2.6
                TimestampSource PortDest PortSource IPDest IP
                Apr 15, 2025 17:50:21.496104002 CEST53627721.1.1.1192.168.2.6
                Apr 15, 2025 17:50:21.499875069 CEST53580921.1.1.1192.168.2.6
                Apr 15, 2025 17:50:22.384179115 CEST53551721.1.1.1192.168.2.6
                Apr 15, 2025 17:50:22.537586927 CEST53556891.1.1.1192.168.2.6
                Apr 15, 2025 17:50:25.861537933 CEST5114753192.168.2.61.1.1.1
                Apr 15, 2025 17:50:25.861989975 CEST5651653192.168.2.61.1.1.1
                Apr 15, 2025 17:50:25.968899965 CEST53511471.1.1.1192.168.2.6
                Apr 15, 2025 17:50:25.968974113 CEST53565161.1.1.1192.168.2.6
                Apr 15, 2025 17:50:26.960580111 CEST5277553192.168.2.61.1.1.1
                Apr 15, 2025 17:50:26.960855007 CEST6062253192.168.2.61.1.1.1
                Apr 15, 2025 17:50:27.105015039 CEST53527751.1.1.1192.168.2.6
                Apr 15, 2025 17:50:27.117839098 CEST53606221.1.1.1192.168.2.6
                Apr 15, 2025 17:50:28.439471006 CEST5886153192.168.2.61.1.1.1
                Apr 15, 2025 17:50:28.439652920 CEST5432153192.168.2.61.1.1.1
                Apr 15, 2025 17:50:28.564438105 CEST53588611.1.1.1192.168.2.6
                Apr 15, 2025 17:50:28.566102982 CEST53543211.1.1.1192.168.2.6
                Apr 15, 2025 17:50:39.564522982 CEST53603361.1.1.1192.168.2.6
                Apr 15, 2025 17:50:58.345491886 CEST53518471.1.1.1192.168.2.6
                Apr 15, 2025 17:51:20.102312088 CEST138138192.168.2.6192.168.2.255
                Apr 15, 2025 17:51:21.143721104 CEST53612631.1.1.1192.168.2.6
                Apr 15, 2025 17:51:21.317380905 CEST53634441.1.1.1192.168.2.6
                Apr 15, 2025 17:51:24.188086987 CEST53615321.1.1.1192.168.2.6
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 15, 2025 17:50:25.861537933 CEST192.168.2.61.1.1.10x7a0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.861989975 CEST192.168.2.61.1.1.10x17f7Standard query (0)www.google.com65IN (0x0001)false
                Apr 15, 2025 17:50:26.960580111 CEST192.168.2.61.1.1.10xd27Standard query (0)mindlabs.topleads.coA (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:26.960855007 CEST192.168.2.61.1.1.10x29fStandard query (0)mindlabs.topleads.co65IN (0x0001)false
                Apr 15, 2025 17:50:28.439471006 CEST192.168.2.61.1.1.10x17feStandard query (0)sendgrid.production-us12.comA (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:28.439652920 CEST192.168.2.61.1.1.10xa295Standard query (0)sendgrid.production-us12.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.99A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.105A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.104A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.103A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.147A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968899965 CEST1.1.1.1192.168.2.60x7a0No error (0)www.google.com173.194.219.106A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:25.968974113 CEST1.1.1.1192.168.2.60x17f7No error (0)www.google.com65IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.topleads.comindlabs.activehosted.comCNAME (Canonical name)IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.activehosted.com104.17.203.31A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.activehosted.com104.17.206.31A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.activehosted.com104.17.204.31A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.activehosted.com104.17.205.31A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:27.105015039 CEST1.1.1.1192.168.2.60xd27No error (0)mindlabs.activehosted.com104.17.202.31A (IP address)IN (0x0001)false
                Apr 15, 2025 17:50:27.117839098 CEST1.1.1.1192.168.2.60x29fNo error (0)mindlabs.topleads.comindlabs.activehosted.comCNAME (Canonical name)IN (0x0001)false
                Apr 15, 2025 17:50:27.117839098 CEST1.1.1.1192.168.2.60x29fNo error (0)mindlabs.activehosted.com65IN (0x0001)false
                Apr 15, 2025 17:50:28.564438105 CEST1.1.1.1192.168.2.60x17feNo error (0)sendgrid.production-us12.com31.172.83.250A (IP address)IN (0x0001)false
                • mindlabs.topleads.co
                • sendgrid.production-us12.com
                • c.pki.goog
                Session IDSource IPSource PortDestination IPDestination Port
                0192.168.2.649705142.250.9.9480
                TimestampBytes transferredDirectionData
                Apr 15, 2025 17:50:34.280260086 CEST200OUTGET /r/r4.crl HTTP/1.1
                Cache-Control: max-age = 3000
                Connection: Keep-Alive
                Accept: */*
                If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                User-Agent: Microsoft-CryptoAPI/10.0
                Host: c.pki.goog
                Apr 15, 2025 17:50:34.388828039 CEST1243INHTTP/1.1 200 OK
                Accept-Ranges: bytes
                Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                Cross-Origin-Resource-Policy: cross-origin
                Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                Content-Length: 530
                X-Content-Type-Options: nosniff
                Server: sffe
                X-XSS-Protection: 0
                Date: Tue, 15 Apr 2025 15:17:58 GMT
                Expires: Tue, 15 Apr 2025 16:07:58 GMT
                Cache-Control: public, max-age=3000
                Age: 1956
                Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                Content-Type: application/pkix-crl
                Vary: Accept-Encoding
                Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.649699104.17.203.314432788C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-15 15:50:27 UTC754OUTGET /lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni HTTP/1.1
                Host: mindlabs.topleads.co
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-15 15:50:28 UTC1169INHTTP/1.1 302 Found
                Date: Tue, 15 Apr 2025 15:50:28 GMT
                Content-Type: text/html; charset=UTF-8
                Content-Length: 0
                Connection: close
                location: https://sendgrid.production-us12.com?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D
                Cache-Control: no-store, no-cache, must-revalidate
                expires: Thu, 19 Nov 1981 08:52:00 GMT
                pragma: no-cache
                Set-Cookie: PHPSESSID=27cd68a3bc7ddb2b7df0c79ccb359792; path=/; HttpOnly; SameSite=Lax
                x-content-type-options: nosniff
                x-privacy-policy: You can find our privacy policy here: https://www.activecampaign.com/help/privacy-policy/
                x-request-id: c64e6a30749f22064ccf9d1ab9de2951
                x-robots-tag: noindex
                cf-cache-status: DYNAMIC
                Set-Cookie: cmp1000154298=506ea9f57a17ea89bb45011edfc2f431; expires=Thu, 15-May-2025 15:50:28 GMT; Max-Age=2592000; path=/; domain=.mindlabs.topleads.co; secure; SameSite=Lax
                2025-04-15 15:50:28 UTC425INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 5f 5f 63 66 5f 62 6d 3d 64 67 65 4b 31 5a 55 36 77 74 35 71 51 4c 35 57 67 33 6b 73 72 4e 78 32 6e 49 35 36 6c 55 34 37 66 34 58 4a 49 37 41 43 42 6e 55 2d 31 37 34 34 37 33 32 32 32 38 2d 31 2e 30 2e 31 2e 31 2d 4f 59 6c 39 6c 43 56 6e 32 46 36 6d 7a 30 35 4d 43 4b 68 5f 34 44 73 62 73 4a 69 4b 77 59 47 34 7a 62 58 34 6d 41 4f 65 69 4e 65 6a 30 62 55 36 59 52 49 4f 6d 2e 46 4e 41 39 5a 5f 4b 51 64 74 37 67 66 46 30 6b 77 6a 6d 48 35 69 75 75 6c 36 46 57 5a 4a 78 64 35 52 50 34 39 38 74 4c 7a 48 47 39 6a 6e 63 35 42 45 41 43 6b 3b 20 70 61 74 68 3d 2f 3b 20 65 78 70 69 72 65 73 3d 54 75 65 2c 20 31 35 2d 41 70 72 2d 32 35 20 31 36 3a 32 30 3a 32 38 20 47 4d 54 3b 20 64 6f 6d 61 69 6e 3d 2e 6d 69 6e 64 6c 61 62 73 2e 74
                Data Ascii: Set-Cookie: __cf_bm=dgeK1ZU6wt5qQL5Wg3ksrNx2nI56lU47f4XJI7ACBnU-1744732228-1.0.1.1-OYl9lCVn2F6mz05MCKh_4DsbsJiKwYG4zbX4mAOeiNej0bU6YRIOm.FNA9Z_KQdt7gfF0kwjmH5iuul6FWZJxd5RP498tLzHG9jnc5BEACk; path=/; expires=Tue, 15-Apr-25 16:20:28 GMT; domain=.mindlabs.t


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.64970031.172.83.2504432788C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-15 15:50:28 UTC1051OUTGET /?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D HTTP/1.1
                Host: sendgrid.production-us12.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-15 15:50:29 UTC171INHTTP/1.1 500 Internal Server Error
                Server: nginx/1.18.0 (Ubuntu)
                Date: Tue, 15 Apr 2025 15:50:29 GMT
                Content-Type: text/html
                Content-Length: 588
                Connection: close
                2025-04-15 15:50:29 UTC588INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21
                Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>... a padding to disable MSIE and Chrome friendly error page --><!


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.64970131.172.83.2504432788C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-15 15:50:30 UTC992OUTGET /favicon.ico HTTP/1.1
                Host: sendgrid.production-us12.com
                Connection: keep-alive
                sec-ch-ua-platform: "Windows"
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-15 15:50:30 UTC159INHTTP/1.1 404 Not Found
                Server: nginx/1.18.0 (Ubuntu)
                Date: Tue, 15 Apr 2025 15:50:30 GMT
                Content-Type: text/html
                Content-Length: 564
                Connection: close
                2025-04-15 15:50:30 UTC564INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20
                Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:2
                Start time:11:50:15
                Start date:15/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:11:50:20
                Start date:15/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1940,i,6075087294735186206,16067551633918766053,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1972 /prefetch:3
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:11
                Start time:11:50:26
                Start date:15/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni"
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly