Edit tour

Windows Analysis Report
http://dasmalwerk.eu/

Overview

General Information

Sample URL:http://dasmalwerk.eu/
Analysis ID:1668629
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5916 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2020,i,11901637287193123405,16153164578512413847,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1740 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6964 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dasmalwerk.eu/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://dasmalwerk.eu/Avira URL Cloud: detection malicious, Label: malware
Source: http://dasmalwerk.eu/favicon.icoAvira URL Cloud: Label: malware
Source: http://dasmalwerk.eu/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 108.177.122.105:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 46.137.15.86:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.230.31.32:443 -> 192.168.2.6:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 143.204.29.6:443 -> 192.168.2.6:49710 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: das-malwerk.herokuapp.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: frameSec-Fetch-Storage-Access: activeReferer: http://dasmalwerk.eu/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /error-pages/no-such-app.html HTTP/1.1Host: www.herokucdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://das-malwerk.herokuapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dasmalwerk.euConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dasmalwerk.euConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://dasmalwerk.eu/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: dasmalwerk.eu
Source: global trafficDNS traffic detected: DNS query: das-malwerk.herokuapp.com
Source: global trafficDNS traffic detected: DNS query: www.herokucdn.com
Source: global trafficDNS traffic detected: DNS query: www.heroku.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Length: 548Cache-Control: no-cache, no-storeContent-Type: text/html; charset=utf-8Date: 2025-04-18 17:10:31.450635641 +0000 UTCServer: heroku-router
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: awselb/2.0Date: Fri, 18 Apr 2025 17:10:32 GMTContent-Length: 0Connection: keep-aliveWAFRule: 5
Source: chromecache_57.2.drString found in binary or memory: https://das-malwerk.herokuapp.com
Source: chromecache_56.2.drString found in binary or memory: https://www.herokucdn.com/favicon.ico
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49680
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 108.177.122.105:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 46.137.15.86:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 54.230.31.32:443 -> 192.168.2.6:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 143.204.29.6:443 -> 192.168.2.6:49710 version: TLS 1.2
Source: classification engineClassification label: mal56.win@25/4@12/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2020,i,11901637287193123405,16153164578512413847,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1740 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dasmalwerk.eu/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2020,i,11901637287193123405,16153164578512413847,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1740 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1668629 URL: http://dasmalwerk.eu/ Startdate: 18/04/2025 Architecture: WINDOWS Score: 56 22 Antivirus detection for URL or domain 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.6, 138, 443, 49152 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 dasmalwerk.eu 15.197.142.173, 443, 49699, 49700 TANDEMUS United States 11->16 18 www.google.com 108.177.122.105, 443, 49698, 49715 GOOGLEUS United States 11->18 20 6 other IPs or domains 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://dasmalwerk.eu/100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://dasmalwerk.eu/favicon.ico100%Avira URL Cloudmalware
https://das-malwerk.herokuapp.com0%Avira URL Cloudsafe
https://das-malwerk.herokuapp.com/0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
ie02.ingress.herokuapp.com
46.137.15.86
truefalse
    high
    d3v17f49c4gdd3.cloudfront.net
    54.230.31.32
    truefalse
      unknown
      dasmalwerk.eu
      15.197.142.173
      truefalse
        unknown
        d1iy6che4tyjhe.cloudfront.net
        143.204.29.6
        truefalse
          unknown
          www.google.com
          108.177.122.105
          truefalse
            high
            das-malwerk.herokuapp.com
            unknown
            unknownfalse
              unknown
              www.herokucdn.com
              unknown
              unknownfalse
                high
                www.heroku.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://www.herokucdn.com/error-pages/no-such-app.htmlfalse
                    high
                    http://dasmalwerk.eu/favicon.icotrue
                    • Avira URL Cloud: malware
                    unknown
                    http://dasmalwerk.eu/true
                      unknown
                      https://das-malwerk.herokuapp.com/false
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://das-malwerk.herokuapp.comchromecache_57.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.herokucdn.com/favicon.icochromecache_56.2.drfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        143.204.29.6
                        d1iy6che4tyjhe.cloudfront.netUnited States
                        16509AMAZON-02USfalse
                        54.230.31.32
                        d3v17f49c4gdd3.cloudfront.netUnited States
                        16509AMAZON-02USfalse
                        15.197.142.173
                        dasmalwerk.euUnited States
                        7430TANDEMUSfalse
                        46.137.15.86
                        ie02.ingress.herokuapp.comIreland
                        16509AMAZON-02USfalse
                        108.177.122.105
                        www.google.comUnited States
                        15169GOOGLEUSfalse
                        IP
                        192.168.2.6
                        Joe Sandbox version:42.0.0 Malachite
                        Analysis ID:1668629
                        Start date and time:2025-04-18 19:09:09 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 3m 10s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:browseurl.jbs
                        Sample URL:http://dasmalwerk.eu/
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:10
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Detection:MAL
                        Classification:mal56.win@25/4@12/6
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe, TextInputHost.exe
                        • Excluded IPs from analysis (whitelisted): 23.76.34.6, 173.194.219.84, 108.177.122.139, 108.177.122.138, 108.177.122.101, 108.177.122.100, 108.177.122.113, 108.177.122.102, 64.233.185.94, 64.233.177.113, 64.233.177.101, 64.233.177.100, 64.233.177.139, 64.233.177.138, 64.233.177.102, 74.125.21.101, 74.125.21.139, 74.125.21.100, 74.125.21.113, 74.125.21.138, 74.125.21.102, 142.250.9.138, 142.250.9.101, 142.250.9.102, 142.250.9.113, 142.250.9.100, 142.250.9.139, 199.232.210.172, 64.233.185.139, 64.233.185.102, 64.233.185.138, 64.233.185.113, 64.233.185.100, 64.233.185.101, 172.253.124.138, 172.253.124.101, 172.253.124.139, 172.253.124.100, 172.253.124.113, 172.253.124.102, 74.125.138.102, 74.125.138.113, 74.125.138.138, 74.125.138.139, 74.125.138.100, 74.125.138.101, 172.253.124.94, 142.251.15.94, 4.175.87.197
                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, c.pki.goog
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtOpenFile calls found.
                        • VT rate limit hit for: http://dasmalwerk.eu/
                        No simulations
                        No context
                        No context
                        No context
                        No context
                        No context
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (2897)
                        Category:downloaded
                        Size (bytes):4810
                        Entropy (8bit):5.244178467368151
                        Encrypted:false
                        SSDEEP:96:Gr7FCUCEFCBSbBVpdtWFj774q1+kk+O5wrBh0eQZVGtO:Gr74bE4k/tWF7hWEDsgO
                        MD5:3604480F330BA55A1FB300A55319F907
                        SHA1:01CF4F79AF4ACA2C0C7DD0727A73BA5799D37868
                        SHA-256:5485A924900FCEE105A2A32EA75BF01F6107CCE493EAC7066C4301F86B99C691
                        SHA-512:92D3967BA226B5F0E0CE09F06984327B9C00C9B700C3BBC4A2F3D8DFF72681D7424746DFBE817AF57E3AAE8BE0F93FA749DAE4C870653B2C41BFC82F202C65E5
                        Malicious:false
                        Reputation:low
                        URL:https://www.herokucdn.com/error-pages/no-such-app.html
                        Preview:<!doctype html> <html> <head> <meta charset=utf-8> <meta content="width=device-width,initial-scale=1.0,minimum-scale=1.0,maximum-scale=1.0,user-scalable=no" name=viewport> <title>No such app | Heroku </title> <link rel="shortcut icon" type="image/x-icon" href="https://www.herokucdn.com/favicon.ico"> <style>html, body {. font-family: sans-serif;. -ms-text-size-adjust: 100%;. -webkit-text-size-adjust: 100%;. background-color: #F7F8FB;. height: 100%;. -webkit-font-smoothing: antialiased; }..body {. margin: 0;. padding: 0;. display: flex;. flex-direction: column;. align-items: center;. justify-content: center; }...message {. text-align: center;. align-self: center;. display: flex;. flex-direction: column;. align-items: center;. padding: 0px 20px;. max-width: 450px; }...message__title {. font-size: 22px;. font-weight: 100;. margin-top: 15px;. color: #47494E;. margin-bottom: 8px; }..p {. -webkit-margin-after: 0px;. -webkit-margin-before: 0px;. font-size: 15px;. co
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text
                        Category:downloaded
                        Size (bytes):363
                        Entropy (8bit):5.041211080760603
                        Encrypted:false
                        SSDEEP:6:B8FQtJCc4svmo9cL/sGcmSRgkhdwZ3TXCwFWAEdkx0smHqd5/05YmWALxL:BMQtJOo99ISRujXHWAEdkx0smHC5/ORx
                        MD5:55F58B66B63EEDE1D0BDFDFF29D7C008
                        SHA1:B9B6B18892CD45880F924ACB49F13C7F1B917DB3
                        SHA-256:BA45ED11664D18E506D180050D0A3940C1D0AF12A6C22DF158A0861A97825903
                        SHA-512:E1540EE596941B4DAA2B87868523B95470E085491B4BBC5AF670CC5FCE6C7EADDC2CAC9389654F834278D763B83DC0036F58AA91F0F991AA5B5A64140AE73597
                        Malicious:false
                        Reputation:low
                        URL:http://dasmalwerk.eu/
                        Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">.<html>. <head>. <title>dasmalwerk.eu</title>. <meta name="description" content="" />. <meta name="keywords" content="" />. </head>. <frameset rows="100%,*" border="0">. <frame src="https://das-malwerk.herokuapp.com" frameborder="0" />. </frameset>.</html>.
                        No static file info

                        Download Network PCAP: filteredfull

                        • Total Packets: 82
                        • 443 (HTTPS)
                        • 80 (HTTP)
                        • 53 (DNS)
                        TimestampSource PortDest PortSource IPDest IP
                        Apr 18, 2025 19:10:12.256642103 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:12.568865061 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:13.006308079 CEST49672443192.168.2.6204.79.197.203
                        Apr 18, 2025 19:10:13.178153992 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:14.381329060 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:16.787561893 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:21.756598949 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:22.694082975 CEST49672443192.168.2.6204.79.197.203
                        Apr 18, 2025 19:10:25.737387896 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:25.737438917 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:25.737503052 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:25.737622976 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:25.737642050 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:25.950316906 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:25.950406075 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:25.952029943 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:25.952042103 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:25.952248096 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:25.991733074 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:27.962022066 CEST49699443192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:27.962055922 CEST4434969915.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:27.962219954 CEST49699443192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:27.962451935 CEST49699443192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:27.962467909 CEST4434969915.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:28.041641951 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:28.042076111 CEST4970180192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:28.143214941 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:28.143320084 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:28.143821955 CEST804970115.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:28.143887043 CEST4970180192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:30.363369942 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:30.465130091 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:30.485903978 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:30.526518106 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:30.668721914 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:30.668804884 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:30.668872118 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:30.669019938 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:30.669034958 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.326257944 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.326338053 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:31.329230070 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:31.329251051 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.329540014 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.348083973 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:31.366167068 CEST49678443192.168.2.620.42.65.91
                        Apr 18, 2025 19:10:31.388268948 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.566042900 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.566127062 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.566179037 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:31.582669020 CEST49703443192.168.2.646.137.15.86
                        Apr 18, 2025 19:10:31.582704067 CEST4434970346.137.15.86192.168.2.6
                        Apr 18, 2025 19:10:31.781126022 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:31.781176090 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:31.781250000 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:31.781425953 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:31.781440973 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:31.995670080 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:31.995951891 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.059357882 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.059390068 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.059776068 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.062340021 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.104276896 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.195518970 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.195789099 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.195825100 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.195895910 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.195925951 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.195944071 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.196631908 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.196690083 CEST4434970654.230.31.32192.168.2.6
                        Apr 18, 2025 19:10:32.196743011 CEST49706443192.168.2.654.230.31.32
                        Apr 18, 2025 19:10:32.317076921 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:32.436577082 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:10:32.479151964 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:35.943403006 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:35.943476915 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:35.943538904 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:36.689024925 CEST49698443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:10:36.689054012 CEST44349698108.177.122.105192.168.2.6
                        Apr 18, 2025 19:10:39.682425022 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:39.682533026 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:10:39.682637930 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:39.682796001 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:39.682813883 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:10:39.900055885 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:10:39.900217056 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:39.901293993 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:39.901307106 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:10:39.901654005 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:10:39.944605112 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:10:57.975991964 CEST49699443192.168.2.615.197.142.173
                        Apr 18, 2025 19:10:58.020277023 CEST4434969915.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:09.888048887 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:11:09.888118982 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:11:09.888175011 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:11:10.698926926 CEST49710443192.168.2.6143.204.29.6
                        Apr 18, 2025 19:11:10.698956013 CEST44349710143.204.29.6192.168.2.6
                        Apr 18, 2025 19:11:13.148534060 CEST4970180192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:13.250498056 CEST804970115.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:17.444514036 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:17.548690081 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:23.253695965 CEST443496802.23.227.215192.168.2.6
                        Apr 18, 2025 19:11:23.253721952 CEST443496802.23.227.215192.168.2.6
                        Apr 18, 2025 19:11:23.253845930 CEST49680443192.168.2.62.23.227.215
                        Apr 18, 2025 19:11:23.253890038 CEST49680443192.168.2.62.23.227.215
                        Apr 18, 2025 19:11:25.696422100 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:25.696481943 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:25.696607113 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:25.696837902 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:25.696852922 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:25.905734062 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:25.906243086 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:25.906270027 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:28.276681900 CEST804970115.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:28.276758909 CEST4970180192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:28.696858883 CEST4970180192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:28.798871994 CEST804970115.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:32.437457085 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:32.437575102 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:32.696650982 CEST4970080192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:32.798587084 CEST804970015.197.142.173192.168.2.6
                        Apr 18, 2025 19:11:35.971450090 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:35.971539974 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:35.971669912 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:36.696727037 CEST49715443192.168.2.6108.177.122.105
                        Apr 18, 2025 19:11:36.696749926 CEST44349715108.177.122.105192.168.2.6
                        Apr 18, 2025 19:11:43.022825003 CEST49699443192.168.2.615.197.142.173
                        Apr 18, 2025 19:11:43.022851944 CEST4434969915.197.142.173192.168.2.6
                        TimestampSource PortDest PortSource IPDest IP
                        Apr 18, 2025 19:10:21.555093050 CEST53541781.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:21.556617975 CEST53562761.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:22.380804062 CEST53582101.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:22.510232925 CEST53609701.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:25.633502007 CEST6110153192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:25.633640051 CEST6457953192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:25.736504078 CEST53645791.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:25.736717939 CEST53611011.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:27.353586912 CEST5160353192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:27.353852034 CEST5012953192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:27.381266117 CEST4976353192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:27.381511927 CEST5878053192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:27.741533995 CEST53587801.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:27.961281061 CEST53497631.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:27.976136923 CEST53516031.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:28.350392103 CEST53501291.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:30.546869993 CEST5371953192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:30.547282934 CEST5722653192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:30.655211926 CEST53537191.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:30.655962944 CEST53572261.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:31.671468019 CEST5530653192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:31.671808958 CEST6120953192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:31.775500059 CEST53553061.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:31.777760029 CEST53612091.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:39.452903032 CEST53558361.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:39.549310923 CEST6107153192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:39.549514055 CEST4915253192.168.2.61.1.1.1
                        Apr 18, 2025 19:10:39.656200886 CEST53491521.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:39.681427002 CEST53610711.1.1.1192.168.2.6
                        Apr 18, 2025 19:10:58.253138065 CEST53650491.1.1.1192.168.2.6
                        Apr 18, 2025 19:11:10.326261997 CEST138138192.168.2.6192.168.2.255
                        Apr 18, 2025 19:11:20.878514051 CEST53554081.1.1.1192.168.2.6
                        Apr 18, 2025 19:11:21.194302082 CEST53568961.1.1.1192.168.2.6
                        Apr 18, 2025 19:11:24.002618074 CEST53615321.1.1.1192.168.2.6
                        TimestampSource IPDest IPChecksumCodeType
                        Apr 18, 2025 19:10:28.350487947 CEST192.168.2.61.1.1.1c22c(Port unreachable)Destination Unreachable
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Apr 18, 2025 19:10:25.633502007 CEST192.168.2.61.1.1.10xf3e8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.633640051 CEST192.168.2.61.1.1.10xc302Standard query (0)www.google.com65IN (0x0001)false
                        Apr 18, 2025 19:10:27.353586912 CEST192.168.2.61.1.1.10x5c64Standard query (0)dasmalwerk.euA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.353852034 CEST192.168.2.61.1.1.10x10bbStandard query (0)dasmalwerk.eu65IN (0x0001)false
                        Apr 18, 2025 19:10:27.381266117 CEST192.168.2.61.1.1.10xcbc6Standard query (0)dasmalwerk.euA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.381511927 CEST192.168.2.61.1.1.10xb6e1Standard query (0)dasmalwerk.eu65IN (0x0001)false
                        Apr 18, 2025 19:10:30.546869993 CEST192.168.2.61.1.1.10xf5d1Standard query (0)das-malwerk.herokuapp.comA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:30.547282934 CEST192.168.2.61.1.1.10x3657Standard query (0)das-malwerk.herokuapp.com65IN (0x0001)false
                        Apr 18, 2025 19:10:31.671468019 CEST192.168.2.61.1.1.10xe5b4Standard query (0)www.herokucdn.comA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:31.671808958 CEST192.168.2.61.1.1.10x94dcStandard query (0)www.herokucdn.com65IN (0x0001)false
                        Apr 18, 2025 19:10:39.549310923 CEST192.168.2.61.1.1.10xdd40Standard query (0)www.heroku.comA (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:39.549514055 CEST192.168.2.61.1.1.10xb2fStandard query (0)www.heroku.com65IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Apr 18, 2025 19:10:25.736504078 CEST1.1.1.1192.168.2.60xc302No error (0)www.google.com65IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.105A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.103A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.104A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.106A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.99A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:25.736717939 CEST1.1.1.1192.168.2.60xf3e8No error (0)www.google.com108.177.122.147A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.961281061 CEST1.1.1.1192.168.2.60xcbc6No error (0)dasmalwerk.eu15.197.142.173A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.961281061 CEST1.1.1.1192.168.2.60xcbc6No error (0)dasmalwerk.eu3.33.152.147A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.976136923 CEST1.1.1.1192.168.2.60x5c64No error (0)dasmalwerk.eu15.197.142.173A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:27.976136923 CEST1.1.1.1192.168.2.60x5c64No error (0)dasmalwerk.eu3.33.152.147A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:30.655211926 CEST1.1.1.1192.168.2.60xf5d1No error (0)das-malwerk.herokuapp.comie02.ingress.herokuapp.comCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:30.655211926 CEST1.1.1.1192.168.2.60xf5d1No error (0)ie02.ingress.herokuapp.com46.137.15.86A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:30.655211926 CEST1.1.1.1192.168.2.60xf5d1No error (0)ie02.ingress.herokuapp.com54.73.53.134A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:30.655211926 CEST1.1.1.1192.168.2.60xf5d1No error (0)ie02.ingress.herokuapp.com54.220.192.176A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:30.655962944 CEST1.1.1.1192.168.2.60x3657No error (0)das-malwerk.herokuapp.comva03.ingress.herokuapp.comCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:31.775500059 CEST1.1.1.1192.168.2.60xe5b4No error (0)www.herokucdn.comd3v17f49c4gdd3.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:31.775500059 CEST1.1.1.1192.168.2.60xe5b4No error (0)d3v17f49c4gdd3.cloudfront.net54.230.31.32A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:31.775500059 CEST1.1.1.1192.168.2.60xe5b4No error (0)d3v17f49c4gdd3.cloudfront.net54.230.31.113A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:31.775500059 CEST1.1.1.1192.168.2.60xe5b4No error (0)d3v17f49c4gdd3.cloudfront.net54.230.31.23A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:31.775500059 CEST1.1.1.1192.168.2.60xe5b4No error (0)d3v17f49c4gdd3.cloudfront.net54.230.31.53A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:31.777760029 CEST1.1.1.1192.168.2.60x94dcNo error (0)www.herokucdn.comd3v17f49c4gdd3.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:39.656200886 CEST1.1.1.1192.168.2.60xb2fNo error (0)www.heroku.comd1iy6che4tyjhe.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:39.681427002 CEST1.1.1.1192.168.2.60xdd40No error (0)www.heroku.comd1iy6che4tyjhe.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2025 19:10:39.681427002 CEST1.1.1.1192.168.2.60xdd40No error (0)d1iy6che4tyjhe.cloudfront.net143.204.29.6A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:39.681427002 CEST1.1.1.1192.168.2.60xdd40No error (0)d1iy6che4tyjhe.cloudfront.net143.204.29.119A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:39.681427002 CEST1.1.1.1192.168.2.60xdd40No error (0)d1iy6che4tyjhe.cloudfront.net143.204.29.82A (IP address)IN (0x0001)false
                        Apr 18, 2025 19:10:39.681427002 CEST1.1.1.1192.168.2.60xdd40No error (0)d1iy6che4tyjhe.cloudfront.net143.204.29.55A (IP address)IN (0x0001)false
                        • dasmalwerk.eu
                          • das-malwerk.herokuapp.com
                            • www.herokucdn.com
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.64970015.197.142.173804328C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        Apr 18, 2025 19:10:30.363369942 CEST428OUTGET / HTTP/1.1
                        Host: dasmalwerk.eu
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Accept-Encoding: gzip, deflate
                        Accept-Language: en-US,en;q=0.9
                        Apr 18, 2025 19:10:30.485903978 CEST619INHTTP/1.1 200 OK
                        Date: Fri, 18 Apr 2025 17:10:30 GMT
                        Content-Type: text/html; charset=utf-8
                        Content-Length: 363
                        Connection: keep-alive
                        Server: ip-10-123-124-114.ec2.internal
                        Vary: Accept-Encoding
                        X-Request-Id: a15dd5ef-6a35-414b-bf18-5c1c4981d052
                        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 64 61 73 6d 61 6c 77 65 72 6b 2e 65 75 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 22 20 2f 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 6b 65 79 77 6f 72 64 73 22 20 63 6f 6e 74 65 6e 74 3d 22 22 20 2f 3e 0a 20 20 3c 2f 68 65 61 64 3e 0a 20 20 3c 66 72 61 6d 65 73 65 74 20 72 6f 77 73 3d 22 31 30 30 25 2c 2a 22 20 62 6f 72 64 65 72 3d 22 30 22 3e 0a 20 20 20 20 3c 66 72 61 6d 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 64 61 73 2d 6d 61 6c 77 65 72 6b 2e 68 65 72 6f 6b 75 61 70 70 2e 63 6f 6d 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 [TRUNCATED]
                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html> <head> <title>dasmalwerk.eu</title> <meta name="description" content="" /> <meta name="keywords" content="" /> </head> <frameset rows="100%,*" border="0"> <frame src="https://das-malwerk.herokuapp.com" frameborder="0" /> </frameset></html>
                        Apr 18, 2025 19:10:32.317076921 CEST370OUTGET /favicon.ico HTTP/1.1
                        Host: dasmalwerk.eu
                        Connection: keep-alive
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Referer: http://dasmalwerk.eu/
                        Accept-Encoding: gzip, deflate
                        Accept-Language: en-US,en;q=0.9
                        Apr 18, 2025 19:10:32.436577082 CEST138INHTTP/1.1 404 Not Found
                        Server: awselb/2.0
                        Date: Fri, 18 Apr 2025 17:10:32 GMT
                        Content-Length: 0
                        Connection: keep-alive
                        WAFRule: 5
                        Apr 18, 2025 19:11:17.444514036 CEST6OUTData Raw: 00
                        Data Ascii:


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.64970115.197.142.173804328C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        Apr 18, 2025 19:11:13.148534060 CEST6OUTData Raw: 00
                        Data Ascii:


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.64970346.137.15.864434328C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2025-04-18 17:10:31 UTC724OUTGET / HTTP/1.1
                        Host: das-malwerk.herokuapp.com
                        Connection: keep-alive
                        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Sec-Fetch-Site: cross-site
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-Dest: frame
                        Sec-Fetch-Storage-Access: active
                        Referer: http://dasmalwerk.eu/
                        Accept-Encoding: gzip, deflate, br, zstd
                        Accept-Language: en-US,en;q=0.9
                        2025-04-18 17:10:31 UTC192INHTTP/1.1 404 Not Found
                        Content-Length: 548
                        Cache-Control: no-cache, no-store
                        Content-Type: text/html; charset=utf-8
                        Date: 2025-04-18 17:10:31.450635641 +0000 UTC
                        Server: heroku-router
                        2025-04-18 17:10:31 UTC548INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 4e 6f 20 73 75 63 68 20 61 70 70 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 20 6d 65 64 69 61 3d 22 73 63 72 65 65 6e 22 3e 0a 20 20 20 20 20 20 68 74 6d 6c 2c 62 6f 64 79 2c 69 66 72 61 6d 65 20 7b 0a 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 3b 0a 20
                        Data Ascii: <!DOCTYPE html><html> <head> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta charset="utf-8"> <title>No such app</title> <style media="screen"> html,body,iframe { margin: 0; padding: 0;


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.64970654.230.31.324434328C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2025-04-18 17:10:32 UTC758OUTGET /error-pages/no-such-app.html HTTP/1.1
                        Host: www.herokucdn.com
                        Connection: keep-alive
                        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Sec-Fetch-Site: cross-site
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-Dest: iframe
                        Sec-Fetch-Storage-Access: active
                        Referer: https://das-malwerk.herokuapp.com/
                        Accept-Encoding: gzip, deflate, br, zstd
                        Accept-Language: en-US,en;q=0.9
                        2025-04-18 17:10:32 UTC574INHTTP/1.1 200 OK
                        Content-Type: text/html
                        Content-Length: 4810
                        Connection: close
                        Last-Modified: Fri, 21 Mar 2025 18:18:48 GMT
                        x-amz-server-side-encryption: AES256
                        Accept-Ranges: bytes
                        Server: AmazonS3
                        Date: Fri, 18 Apr 2025 09:52:00 GMT
                        Cache-Control: max-age=86400, public
                        Expires: Mon, 31 Dec 2029 18:00:00 GMT
                        ETag: "3604480f330ba55a1fb300a55319f907"
                        X-Cache: Hit from cloudfront
                        Via: 1.1 a33c43ec5f596f8992d13ecf79c120a4.cloudfront.net (CloudFront)
                        X-Amz-Cf-Pop: ATL56-C3
                        X-Amz-Cf-Id: UdYbZXqsGKjfytehiSB2le0Fm6dYNEDK8UtPAh7RpKE6U4rIFE_0bw==
                        Age: 26313
                        2025-04-18 17:10:32 UTC3198INData Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 20 3c 68 74 6d 6c 3e 20 3c 68 65 61 64 3e 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 20 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 2c 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2e 30 2c 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 3e 20 3c 74 69 74 6c 65 3e 4e 6f 20 73 75 63 68 20 61 70 70 20 7c 20 48 65 72 6f 6b 75 20 3c 2f 74 69 74 6c 65 3e 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 78 2d 69 63 6f 6e 22 20
                        Data Ascii: <!doctype html> <html> <head> <meta charset=utf-8> <meta content="width=device-width,initial-scale=1.0,minimum-scale=1.0,maximum-scale=1.0,user-scalable=no" name=viewport> <title>No such app | Heroku </title> <link rel="shortcut icon" type="image/x-icon"
                        2025-04-18 17:10:32 UTC1612INData Raw: 31 2e 38 32 38 32 68 2d 32 2e 37 37 36 35 76 2d 31 2e 34 30 36 32 68 33 2e 38 39 31 38 56 38 2e 31 36 34 68 2d 36 2e 32 36 35 76 38 2e 36 37 32 7a 6d 38 2e 38 33 39 36 20 30 68 32 2e 33 32 35 36 56 31 33 2e 38 32 34 68 2e 36 35 32 36 4c 35 31 2e 38 39 20 31 36 2e 38 33 36 68 32 2e 35 31 35 34 6c 2d 31 2e 38 36 33 2d 33 2e 33 31 36 35 63 31 2e 31 35 31 2d 2e 33 38 36 37 20 31 2e 37 33 32 35 2d 31 2e 31 37 31 38 20 31 2e 37 33 32 35 2d 32 2e 35 33 31 32 20 30 2d 32 2e 30 38 36 2d 31 2e 33 37 36 35 2d 32 2e 38 32 34 32 2d 33 2e 36 33 31 2d 32 2e 38 32 34 32 68 2d 33 2e 34 32 39 76 38 2e 36 37 32 7a 6d 32 2e 33 32 35 36 2d 34 2e 37 39 33 76 2d 31 2e 39 38 30 35 68 31 2e 30 32 30 34 63 2e 39 37 33 20 30 20 31 2e 34 2e 32 35 37 38 20 31 2e 34 2e 39 38 34 34 20
                        Data Ascii: 1.8282h-2.7765v-1.4062h3.8918V8.164h-6.265v8.672zm8.8396 0h2.3256V13.824h.6526L51.89 16.836h2.5154l-1.863-3.3165c1.151-.3867 1.7325-1.1718 1.7325-2.5312 0-2.086-1.3765-2.8242-3.631-2.8242h-3.429v8.672zm2.3256-4.793v-1.9805h1.0204c.973 0 1.4.2578 1.4.9844


                        020406080s020406080100

                        Click to jump to process

                        020406080s0.0050100MB

                        Click to jump to process

                        Target ID:1
                        Start time:13:10:13
                        Start date:18/04/2025
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                        Imagebase:0x7ff63b000000
                        File size:3'388'000 bytes
                        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:2
                        Start time:13:10:19
                        Start date:18/04/2025
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2020,i,11901637287193123405,16153164578512413847,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1740 /prefetch:3
                        Imagebase:0x7ff63b000000
                        File size:3'388'000 bytes
                        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:6
                        Start time:13:10:26
                        Start date:18/04/2025
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dasmalwerk.eu/"
                        Imagebase:0x7ff63b000000
                        File size:3'388'000 bytes
                        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:true

                        No disassembly