Edit tour

Windows Analysis Report
https://www.kei-toku.jp/company/

Overview

General Information

Sample URL:https://www.kei-toku.jp/company/
Analysis ID:1670074
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,588035873760530470,11222625014705057356,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2088 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7012 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.kei-toku.jp/company/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.kei-toku.jp/company/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 153.122.205.41:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 153.122.205.41:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /company/ HTTP/1.1Host: www.kei-toku.jpConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.kei-toku.jpConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.kei-toku.jp/company/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.kei-toku.jp
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 21 Apr 2025 02:33:11 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 21 Apr 2025 02:33:11 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 153.122.205.41:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 153.122.205.41:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/4@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,588035873760530470,11222625014705057356,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2088 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.kei-toku.jp/company/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,588035873760530470,11222625014705057356,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2088 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1670074 URL: https://www.kei-toku.jp/company/ Startdate: 21/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49239 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.250.69.4, 443, 49724, 49738 GOOGLEUS United States 10->15 17 www.kei-toku.jp 153.122.205.41, 443, 49726, 49727 GMOCLGMOCLOUDKKJP Japan 10->17

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.kei-toku.jp/company/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.kei-toku.jp/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.kei-toku.jp
153.122.205.41
truefalse
    unknown
    www.google.com
    142.250.69.4
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://www.kei-toku.jp/company/false
        unknown
        https://www.kei-toku.jp/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.69.4
        www.google.comUnited States
        15169GOOGLEUSfalse
        153.122.205.41
        www.kei-toku.jpJapan131921GMOCLGMOCLOUDKKJPfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1670074
        Start date and time:2025-04-21 04:32:02 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 7s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://www.kei-toku.jp/company/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:20
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@21/4@4/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 192.178.49.163, 192.178.49.174, 142.251.2.84, 23.55.219.177, 23.55.241.177, 142.250.68.227, 192.178.49.195, 184.29.183.29, 172.202.163.200
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://www.kei-toku.jp/company/
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):199
        Entropy (8bit):5.112530855532291
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwIgsozEr6VyF02xxdGzsQWr+KqD:J0+oxBgsozR4F0+dgsQo+T
        MD5:BB8F534FBFF5EE61A95AF9C4740AE043
        SHA1:832E403D42AAC1FEC93E4F602338544D3FD2E4F1
        SHA-256:5B13FB5957B84EF7BB9D0B6CD509C947FF6A37D67EFDAC2B896DDD3B908AAD10
        SHA-512:EB423CA8E0F3E026A367130044B1857A1368097F9AC3C8FCAA523FA5E2785437FBC328397B5C6582FB0C872CFF44E70CF0120D874D825472806ADC46ACDBFFDD
        Malicious:false
        Reputation:low
        URL:https://www.kei-toku.jp/company/
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access this resource.</p>.</body></html>.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):199
        Entropy (8bit):5.112530855532291
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwIgsozEr6VyF02xxdGzsQWr+KqD:J0+oxBgsozR4F0+dgsQo+T
        MD5:BB8F534FBFF5EE61A95AF9C4740AE043
        SHA1:832E403D42AAC1FEC93E4F602338544D3FD2E4F1
        SHA-256:5B13FB5957B84EF7BB9D0B6CD509C947FF6A37D67EFDAC2B896DDD3B908AAD10
        SHA-512:EB423CA8E0F3E026A367130044B1857A1368097F9AC3C8FCAA523FA5E2785437FBC328397B5C6582FB0C872CFF44E70CF0120D874D825472806ADC46ACDBFFDD
        Malicious:false
        Reputation:low
        URL:https://www.kei-toku.jp/favicon.ico
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access this resource.</p>.</body></html>.
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 64
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 21, 2025 04:33:01.121246099 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:01.430726051 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:02.040079117 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:03.255295992 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:05.759025097 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:08.901247978 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:08.901284933 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:08.902007103 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:08.902177095 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:08.902189970 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:09.133625984 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:09.301563025 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:09.301693916 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:09.309374094 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:09.309386969 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:09.309849977 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:09.352046967 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:09.445796967 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:09.989254951 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.989351988 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:09.989439964 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.989790916 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.989823103 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:09.989932060 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.989993095 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.990032911 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:09.990124941 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:09.990139008 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.046391010 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:10.572099924 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:10.970942974 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.971014977 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:10.975656986 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:10.975668907 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.975878000 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.976278067 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:10.977040052 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.977111101 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:10.977463961 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:10.977478027 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:10.977768898 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.020281076 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.026012897 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.247423887 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:11.329375982 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.329447031 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.329535961 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.330667973 CEST49727443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.330684900 CEST44349727153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.455976009 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.496284008 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.788593054 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.788697958 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:11.788784027 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.816612005 CEST49726443192.168.2.4153.122.205.41
        Apr 21, 2025 04:33:11.816663027 CEST44349726153.122.205.41192.168.2.4
        Apr 21, 2025 04:33:13.649502039 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:14.739976883 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:15.040013075 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:15.210159063 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.211029053 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.211062908 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.350157022 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.350784063 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.350795031 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.351813078 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.351824999 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.351871967 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.352632046 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.354500055 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.354511023 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.354561090 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.358398914 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.492494106 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.498246908 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.500921011 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.500938892 CEST4434970852.113.196.254192.168.2.4
        Apr 21, 2025 04:33:15.500992060 CEST49708443192.168.2.452.113.196.254
        Apr 21, 2025 04:33:15.648767948 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:16.852103949 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:18.454348087 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:19.260354042 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:19.283232927 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:19.283282995 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:19.283376932 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:19.625843048 CEST49724443192.168.2.4142.250.69.4
        Apr 21, 2025 04:33:19.625864029 CEST44349724142.250.69.4192.168.2.4
        Apr 21, 2025 04:33:20.180278063 CEST49671443192.168.2.4204.79.197.203
        Apr 21, 2025 04:33:24.075594902 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:33:28.055494070 CEST49678443192.168.2.420.189.173.27
        Apr 21, 2025 04:33:33.680232048 CEST4968180192.168.2.42.17.190.73
        Apr 21, 2025 04:34:08.823014021 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:08.823052883 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:08.823121071 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:08.823290110 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:08.823302031 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:09.210598946 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:09.210973978 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:09.211003065 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:19.198715925 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:19.198767900 CEST44349738142.250.69.4192.168.2.4
        Apr 21, 2025 04:34:19.198832989 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:19.619678020 CEST49738443192.168.2.4142.250.69.4
        Apr 21, 2025 04:34:19.619712114 CEST44349738142.250.69.4192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 21, 2025 04:33:04.701605082 CEST53527751.1.1.1192.168.2.4
        Apr 21, 2025 04:33:04.720443964 CEST53560401.1.1.1192.168.2.4
        Apr 21, 2025 04:33:06.145494938 CEST53629911.1.1.1192.168.2.4
        Apr 21, 2025 04:33:06.506303072 CEST53524021.1.1.1192.168.2.4
        Apr 21, 2025 04:33:08.759322882 CEST4923953192.168.2.41.1.1.1
        Apr 21, 2025 04:33:08.759871006 CEST5619353192.168.2.41.1.1.1
        Apr 21, 2025 04:33:08.899712086 CEST53492391.1.1.1192.168.2.4
        Apr 21, 2025 04:33:08.900183916 CEST53561931.1.1.1192.168.2.4
        Apr 21, 2025 04:33:09.710036993 CEST5535153192.168.2.41.1.1.1
        Apr 21, 2025 04:33:09.710207939 CEST4977153192.168.2.41.1.1.1
        Apr 21, 2025 04:33:09.983197927 CEST53553511.1.1.1192.168.2.4
        Apr 21, 2025 04:33:09.988204956 CEST53497711.1.1.1192.168.2.4
        Apr 21, 2025 04:33:23.562510014 CEST53607771.1.1.1192.168.2.4
        Apr 21, 2025 04:33:42.612400055 CEST53520611.1.1.1192.168.2.4
        Apr 21, 2025 04:34:04.168458939 CEST53622911.1.1.1192.168.2.4
        Apr 21, 2025 04:34:05.037018061 CEST53596631.1.1.1192.168.2.4
        Apr 21, 2025 04:34:07.604800940 CEST53539061.1.1.1192.168.2.4
        Apr 21, 2025 04:34:08.546320915 CEST138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 21, 2025 04:33:08.759322882 CEST192.168.2.41.1.1.10xd199Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 21, 2025 04:33:08.759871006 CEST192.168.2.41.1.1.10xe275Standard query (0)www.google.com65IN (0x0001)false
        Apr 21, 2025 04:33:09.710036993 CEST192.168.2.41.1.1.10x7610Standard query (0)www.kei-toku.jpA (IP address)IN (0x0001)false
        Apr 21, 2025 04:33:09.710207939 CEST192.168.2.41.1.1.10x7487Standard query (0)www.kei-toku.jp65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 21, 2025 04:33:08.899712086 CEST1.1.1.1192.168.2.40xd199No error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
        Apr 21, 2025 04:33:08.900183916 CEST1.1.1.1192.168.2.40xe275No error (0)www.google.com65IN (0x0001)false
        Apr 21, 2025 04:33:09.983197927 CEST1.1.1.1192.168.2.40x7610No error (0)www.kei-toku.jp153.122.205.41A (IP address)IN (0x0001)false
        • www.kei-toku.jp
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449727153.122.205.41443320C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-21 02:33:10 UTC673OUTGET /company/ HTTP/1.1
        Host: www.kei-toku.jp
        Connection: keep-alive
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-21 02:33:11 UTC164INHTTP/1.1 403 Forbidden
        Date: Mon, 21 Apr 2025 02:33:11 GMT
        Server: Apache
        Content-Length: 199
        Content-Type: text/html; charset=iso-8859-1
        Connection: close
        2025-04-21 02:33:11 UTC199INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449726153.122.205.41443320C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-21 02:33:11 UTC601OUTGET /favicon.ico HTTP/1.1
        Host: www.kei-toku.jp
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://www.kei-toku.jp/company/
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-21 02:33:11 UTC164INHTTP/1.1 403 Forbidden
        Date: Mon, 21 Apr 2025 02:33:11 GMT
        Server: Apache
        Content-Length: 199
        Content-Type: text/html; charset=iso-8859-1
        Connection: close
        2025-04-21 02:33:11 UTC199INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:1
        Start time:22:32:59
        Start date:20/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:22:33:03
        Start date:20/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,588035873760530470,11222625014705057356,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2088 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:8
        Start time:22:33:09
        Start date:20/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.kei-toku.jp/company/"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly