Edit tour

Windows Analysis Report
https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt

Overview

General Information

Sample URL:https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt
Analysis ID:1671112
Infos:

Detection

Score:21
Range:0 - 100
Confidence:80%

Signatures

Detected use of open redirect vulnerability
Detected suspicious crossdomain redirect
URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3704 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6132 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,14388118772384941128,232339286414297275,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2052 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6308 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Proxy from: r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt to https://zapfibras.com.br/nu/dgev@oeiras.pt
Source: https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.ptSample URL: PII: dgev@oeiras.pt
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.7:49686 version: TLS 1.2
Source: unknownHTTPS traffic detected: 206.189.245.37:443 -> 192.168.2.7:49689 version: TLS 1.2
Source: unknownHTTPS traffic detected: 206.189.245.37:443 -> 192.168.2.7:49688 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.241.203.111:443 -> 192.168.2.7:49690 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.148.161:443 -> 192.168.2.7:49691 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: r.clickwise.net to https://zapfibras.com.br/nu/dgev@oeiras.pt
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.215.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.98.62
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.215.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.98.62
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt HTTP/1.1Host: r.clickwise.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /nu/dgev@oeiras.pt HTTP/1.1Host: zapfibras.com.brConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1Host: application.extensoin.worldConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1Host: application.extensoin.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm
Source: global trafficHTTP traffic detected: GET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1Host: application.extensoin.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: r.clickwise.net
Source: global trafficDNS traffic detected: DNS query: zapfibras.com.br
Source: global trafficDNS traffic detected: DNS query: application.extensoin.world
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Apr 2025 14:47:58 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeServer: cloudflareExpires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidatePragma: no-cacheCf-Cache-Status: DYNAMICSet-Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm; Path=/CF-RAY: 9345eb5a2cd4091e-LAXalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Apr 2025 14:48:10 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeServer: cloudflareExpires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidatePragma: no-cacheCf-Cache-Status: DYNAMICCF-RAY: 9345ebaaba4df7e5-LAXalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Apr 2025 14:49:06 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeServer: cloudflareExpires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidatePragma: no-cacheCf-Cache-Status: DYNAMICCF-RAY: 9345ed0579d6f7df-LAXalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49686
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.7:49686 version: TLS 1.2
Source: unknownHTTPS traffic detected: 206.189.245.37:443 -> 192.168.2.7:49689 version: TLS 1.2
Source: unknownHTTPS traffic detected: 206.189.245.37:443 -> 192.168.2.7:49688 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.241.203.111:443 -> 192.168.2.7:49690 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.148.161:443 -> 192.168.2.7:49691 version: TLS 1.2
Source: classification engineClassification label: sus21.phis.win@25/0@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,14388118772384941128,232339286414297275,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2052 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,14388118772384941128,232339286414297275,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2052 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Web Protocols
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture4
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeylogging3
Ingress Tool Transfer
Scheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1671112 URL: https://r.clickwise.net/pap... Startdate: 22/04/2025 Architecture: WINDOWS Score: 21 22 Detected use of open redirect vulnerability 2->22 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.7, 443, 49672, 49686 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 zapfibras.com.br 162.241.203.111, 443, 49690 OIS1US United States 11->16 18 r.clickwise.net 206.189.245.37, 443, 49688, 49689 DIGITALOCEAN-ASNUS United States 11->18 20 2 other IPs or domains 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://zapfibras.com.br/nu/dgev@oeiras.pt0%Avira URL Cloudsafe
https://application.extensoin.world/messaging.shtml?mode=dgev@oeiras.pt0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
r.clickwise.net
206.189.245.37
truetrue
    unknown
    application.extensoin.world
    172.67.148.161
    truefalse
      unknown
      www.google.com
      142.250.69.4
      truefalse
        high
        zapfibras.com.br
        162.241.203.111
        truetrue
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://zapfibras.com.br/nu/dgev@oeiras.pttrue
          • Avira URL Cloud: safe
          unknown
          https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.ptfalse
            unknown
            https://application.extensoin.world/messaging.shtml?mode=dgev@oeiras.ptfalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.69.4
            www.google.comUnited States
            15169GOOGLEUSfalse
            206.189.245.37
            r.clickwise.netUnited States
            14061DIGITALOCEAN-ASNUStrue
            162.241.203.111
            zapfibras.com.brUnited States
            26337OIS1UStrue
            172.67.148.161
            application.extensoin.worldUnited States
            13335CLOUDFLARENETUSfalse
            IP
            192.168.2.7
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1671112
            Start date and time:2025-04-22 16:46:53 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 51s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:14
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:SUS
            Classification:sus21.phis.win@25/0@8/5
            • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, TextInputHost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.68.238, 142.250.69.3, 142.250.141.84, 142.250.69.14, 23.220.73.6, 192.178.49.195, 142.250.68.227, 52.149.20.212, 184.29.183.29
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://r.clickwise.net/pap?k=1608105173.576&amp;b=&amp;a=59c203522ac2d&amp;u=https://zapfibras.com.br/nu/dgev@oeiras.pt
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 101
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 16:47:43.878945112 CEST4967680192.168.2.723.199.215.203
            Apr 22, 2025 16:47:43.878962040 CEST49677443192.168.2.72.18.98.62
            Apr 22, 2025 16:47:45.972656965 CEST49674443192.168.2.72.23.227.208
            Apr 22, 2025 16:47:52.943763018 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:52.943806887 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:47:52.943873882 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:52.944032907 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:52.944055080 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:47:53.263242960 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:47:53.263312101 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:53.264633894 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:53.264643908 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:47:53.264889956 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:47:53.316499949 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:47:53.481945992 CEST4967680192.168.2.723.199.215.203
            Apr 22, 2025 16:47:53.481959105 CEST49677443192.168.2.72.18.98.62
            Apr 22, 2025 16:47:54.319519043 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.319574118 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:54.319972038 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.320022106 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:54.320059061 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.320132017 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.320678949 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.320693970 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:54.320698023 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:54.320714951 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.124953032 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.125035048 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.126111984 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.126121044 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.126360893 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.126656055 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.132858038 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.132956982 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.133832932 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.133841991 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.134094954 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.172264099 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.184545994 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.393098116 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.393521070 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.393558979 CEST44349689206.189.245.37192.168.2.7
            Apr 22, 2025 16:47:55.393635035 CEST49689443192.168.2.7206.189.245.37
            Apr 22, 2025 16:47:55.586385012 CEST49674443192.168.2.72.23.227.208
            Apr 22, 2025 16:47:55.677624941 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:55.677678108 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:55.677747011 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:55.678035975 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:55.678047895 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:56.043548107 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:56.043677092 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:56.164539099 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:56.164576054 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:56.164894104 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:56.167685986 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:56.208276033 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:57.021260977 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:57.021337032 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:57.021703005 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:57.021742105 CEST44349690162.241.203.111192.168.2.7
            Apr 22, 2025 16:47:57.021750927 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:57.023098946 CEST49690443192.168.2.7162.241.203.111
            Apr 22, 2025 16:47:57.209865093 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.209913969 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:57.210074902 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.210268974 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.210279942 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:57.522897959 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:57.523032904 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.524101019 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.524111986 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:57.524353027 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:57.524646997 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:57.572267056 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:58.119343042 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:58.119396925 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:47:58.119549990 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:58.120174885 CEST49691443192.168.2.7172.67.148.161
            Apr 22, 2025 16:47:58.120191097 CEST44349691172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:03.295016050 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:03.295083046 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:03.295145035 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:03.459373951 CEST49686443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:03.459400892 CEST44349686142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:06.824197054 CEST49672443192.168.2.72.23.227.208
            Apr 22, 2025 16:48:06.824244022 CEST443496722.23.227.208192.168.2.7
            Apr 22, 2025 16:48:10.104072094 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.104137897 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.104228020 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.104273081 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.104310036 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.104404926 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.104614019 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.104626894 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.105187893 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.105200052 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.410340071 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.410604000 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.410641909 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.411187887 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.411207914 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.411675930 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.412117958 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.412147045 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.812779903 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.812841892 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:10.812927008 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.813436985 CEST49701443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:10.813462973 CEST44349701172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:20.708548069 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:21.020570993 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:21.629221916 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:22.832320929 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:25.239401102 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:25.405215025 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:25.405298948 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:25.405448914 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:25.481282949 CEST49702443192.168.2.7172.67.148.161
            Apr 22, 2025 16:48:25.481311083 CEST44349702172.67.148.161192.168.2.7
            Apr 22, 2025 16:48:29.286127090 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:29.591653109 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:30.050975084 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:30.207257986 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:31.410914898 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:33.817218065 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:38.618907928 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:39.660914898 CEST49671443192.168.2.7204.79.197.203
            Apr 22, 2025 16:48:40.160739899 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:48:40.160763979 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:48:48.223903894 CEST49678443192.168.2.720.189.173.15
            Apr 22, 2025 16:48:52.865439892 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:52.865498066 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:52.865561008 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:52.865808964 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:52.865822077 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:53.180365086 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:53.180692911 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:48:53.180726051 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:48:54.853374004 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:48:54.853463888 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:48:54.853519917 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:48:55.459405899 CEST49688443192.168.2.7206.189.245.37
            Apr 22, 2025 16:48:55.459436893 CEST44349688206.189.245.37192.168.2.7
            Apr 22, 2025 16:49:03.165816069 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:49:03.165870905 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:49:03.165939093 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:49:03.459323883 CEST49712443192.168.2.7142.250.69.4
            Apr 22, 2025 16:49:03.459356070 CEST44349712142.250.69.4192.168.2.7
            Apr 22, 2025 16:49:05.585005045 CEST49716443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585095882 CEST44349716172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.585153103 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585197926 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.585197926 CEST49716443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585262060 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585592031 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585604906 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.585678101 CEST49716443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.585714102 CEST44349716172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.891463041 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.891798019 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.891833067 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.892038107 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.892045021 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.894655943 CEST44349716172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:05.894876003 CEST49716443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:05.894906044 CEST44349716172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:06.299046993 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:06.299109936 CEST44349717172.67.148.161192.168.2.7
            Apr 22, 2025 16:49:06.299190044 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:06.299627066 CEST49717443192.168.2.7172.67.148.161
            Apr 22, 2025 16:49:06.299640894 CEST44349717172.67.148.161192.168.2.7
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 16:47:48.315372944 CEST53626811.1.1.1192.168.2.7
            Apr 22, 2025 16:47:48.318790913 CEST53651091.1.1.1192.168.2.7
            Apr 22, 2025 16:47:49.319874048 CEST53611411.1.1.1192.168.2.7
            Apr 22, 2025 16:47:49.532541037 CEST53513561.1.1.1192.168.2.7
            Apr 22, 2025 16:47:52.802442074 CEST5794953192.168.2.71.1.1.1
            Apr 22, 2025 16:47:52.802587986 CEST5037553192.168.2.71.1.1.1
            Apr 22, 2025 16:47:52.942624092 CEST53579491.1.1.1192.168.2.7
            Apr 22, 2025 16:47:52.942879915 CEST53503751.1.1.1192.168.2.7
            Apr 22, 2025 16:47:53.984385967 CEST6113153192.168.2.71.1.1.1
            Apr 22, 2025 16:47:53.993047953 CEST5565553192.168.2.71.1.1.1
            Apr 22, 2025 16:47:54.316054106 CEST53556551.1.1.1192.168.2.7
            Apr 22, 2025 16:47:54.318051100 CEST53611311.1.1.1192.168.2.7
            Apr 22, 2025 16:47:55.396028996 CEST6209853192.168.2.71.1.1.1
            Apr 22, 2025 16:47:55.396215916 CEST5277753192.168.2.71.1.1.1
            Apr 22, 2025 16:47:55.671868086 CEST53527771.1.1.1192.168.2.7
            Apr 22, 2025 16:47:55.677145004 CEST53620981.1.1.1192.168.2.7
            Apr 22, 2025 16:47:57.023595095 CEST5136853192.168.2.71.1.1.1
            Apr 22, 2025 16:47:57.023745060 CEST5322953192.168.2.71.1.1.1
            Apr 22, 2025 16:47:57.187045097 CEST53513681.1.1.1192.168.2.7
            Apr 22, 2025 16:47:57.209220886 CEST53532291.1.1.1192.168.2.7
            Apr 22, 2025 16:48:06.443005085 CEST53606131.1.1.1192.168.2.7
            Apr 22, 2025 16:48:25.537352085 CEST53630501.1.1.1192.168.2.7
            Apr 22, 2025 16:48:48.149935007 CEST53545061.1.1.1192.168.2.7
            Apr 22, 2025 16:48:48.524121046 CEST53619751.1.1.1192.168.2.7
            Apr 22, 2025 16:48:51.552392960 CEST53589421.1.1.1192.168.2.7
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 22, 2025 16:47:52.802442074 CEST192.168.2.71.1.1.10xd16bStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:52.802587986 CEST192.168.2.71.1.1.10xa9b9Standard query (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 16:47:53.984385967 CEST192.168.2.71.1.1.10x454bStandard query (0)r.clickwise.netA (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:53.993047953 CEST192.168.2.71.1.1.10x42c5Standard query (0)r.clickwise.net65IN (0x0001)false
            Apr 22, 2025 16:47:55.396028996 CEST192.168.2.71.1.1.10x5410Standard query (0)zapfibras.com.brA (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:55.396215916 CEST192.168.2.71.1.1.10xd259Standard query (0)zapfibras.com.br65IN (0x0001)false
            Apr 22, 2025 16:47:57.023595095 CEST192.168.2.71.1.1.10x4c4bStandard query (0)application.extensoin.worldA (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:57.023745060 CEST192.168.2.71.1.1.10x79cfStandard query (0)application.extensoin.world65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 22, 2025 16:47:52.942624092 CEST1.1.1.1192.168.2.70xd16bNo error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:52.942879915 CEST1.1.1.1192.168.2.70xa9b9No error (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 16:47:54.318051100 CEST1.1.1.1192.168.2.70x454bNo error (0)r.clickwise.net206.189.245.37A (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:55.677145004 CEST1.1.1.1192.168.2.70x5410No error (0)zapfibras.com.br162.241.203.111A (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:57.187045097 CEST1.1.1.1192.168.2.70x4c4bNo error (0)application.extensoin.world172.67.148.161A (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:57.187045097 CEST1.1.1.1192.168.2.70x4c4bNo error (0)application.extensoin.world104.21.29.83A (IP address)IN (0x0001)false
            Apr 22, 2025 16:47:57.209220886 CEST1.1.1.1192.168.2.70x79cfNo error (0)application.extensoin.world65IN (0x0001)false
            • r.clickwise.net
            • zapfibras.com.br
            • application.extensoin.world
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.749689206.189.245.374436132C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:47:55 UTC749OUTGET /pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt HTTP/1.1
            Host: r.clickwise.net
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 14:47:55 UTC237INHTTP/1.1 302 Found
            Server: openresty/1.17.8.2
            Date: Tue, 22 Apr 2025 14:47:55 GMT
            Content-Type: text/html; charset=utf-8
            Content-Length: 65
            Connection: close
            Location: https://zapfibras.com.br/nu/dgev@oeiras.pt
            X-Err: off time
            2025-04-22 14:47:55 UTC65INData Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 7a 61 70 66 69 62 72 61 73 2e 63 6f 6d 2e 62 72 2f 6e 75 2f 64 67 65 76 40 6f 65 69 72 61 73 2e 70 74 22 3e 46 6f 75 6e 64 3c 2f 61 3e 2e 0a 0a
            Data Ascii: <a href="https://zapfibras.com.br/nu/dgev@oeiras.pt">Found</a>.


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.749690162.241.203.1114436132C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:47:56 UTC683OUTGET /nu/dgev@oeiras.pt HTTP/1.1
            Host: zapfibras.com.br
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 14:47:57 UTC274INHTTP/1.1 302 Moved Temporarily
            Date: Tue, 22 Apr 2025 14:47:56 GMT
            Server: Apache
            Upgrade: h2,h2c
            Connection: Upgrade, close
            Location: https://application.extensoin.world/messaging.shtml?mode=dgev@oeiras.pt
            Content-Length: 0
            Content-Type: text/html; charset=UTF-8


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.749691172.67.148.1614436132C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:47:57 UTC712OUTGET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1
            Host: application.extensoin.world
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 14:47:58 UTC424INHTTP/1.1 404 Not Found
            Date: Tue, 22 Apr 2025 14:47:58 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Server: cloudflare
            Expires: Thu, 19 Nov 1981 08:52:00 GMT
            Cache-Control: no-store, no-cache, must-revalidate
            Pragma: no-cache
            Cf-Cache-Status: DYNAMIC
            Set-Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm; Path=/
            CF-RAY: 9345eb5a2cd4091e-LAX
            alt-svc: h3=":443"; ma=86400
            2025-04-22 14:47:58 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.749701172.67.148.1614436132C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:48:10 UTC790OUTGET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1
            Host: application.extensoin.world
            Connection: keep-alive
            Cache-Control: max-age=0
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: cross-site
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm
            2025-04-22 14:48:10 UTC366INHTTP/1.1 404 Not Found
            Date: Tue, 22 Apr 2025 14:48:10 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Server: cloudflare
            Expires: Thu, 19 Nov 1981 08:52:00 GMT
            Cache-Control: no-store, no-cache, must-revalidate
            Pragma: no-cache
            Cf-Cache-Status: DYNAMIC
            CF-RAY: 9345ebaaba4df7e5-LAX
            alt-svc: h3=":443"; ma=86400
            2025-04-22 14:48:10 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.749717172.67.148.1614436132C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:49:05 UTC790OUTGET /messaging.shtml?mode=dgev@oeiras.pt HTTP/1.1
            Host: application.extensoin.world
            Connection: keep-alive
            Cache-Control: max-age=0
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: cross-site
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=rn6sial4570uqchr98c21qp4lm
            2025-04-22 14:49:06 UTC366INHTTP/1.1 404 Not Found
            Date: Tue, 22 Apr 2025 14:49:06 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Server: cloudflare
            Expires: Thu, 19 Nov 1981 08:52:00 GMT
            Cache-Control: no-store, no-cache, must-revalidate
            Pragma: no-cache
            Cf-Cache-Status: DYNAMIC
            CF-RAY: 9345ed0579d6f7df-LAX
            alt-svc: h3=":443"; ma=86400
            2025-04-22 14:49:06 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:0
            Start time:10:47:46
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff778810000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:1
            Start time:10:47:46
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,14388118772384941128,232339286414297275,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2052 /prefetch:3
            Imagebase:0x7ff778810000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:5
            Start time:10:47:53
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://zapfibras.com.br/nu/dgev@oeiras.pt"
            Imagebase:0x7ff778810000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly