Create Interactive Tour

Windows Analysis Report
http://address.myairmail.com

Overview

General Information

Sample URL:http://address.myairmail.com
Analysis ID:1673878
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Confidence:60%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6948 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6372 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3672 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://address.myairmail.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: address.myairmail.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@24/0@21/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://address.myairmail.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1673878 URL: http://address.myairmail.com Startdate: 25/04/2025 Architecture: WINDOWS Score: 0 16 address.myairmail.com 2->16 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 18 192.168.2.5, 443, 49463, 49574 unknown unknown 6->18 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 20 www.google.com 192.178.49.196, 443, 49701 GOOGLEUS United States 11->20 22 google.com 11->22 24 address.myairmail.com 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://address.myairmail.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.68.238
truefalse
    high
    www.google.com
    192.178.49.196
    truefalse
      high
      address.myairmail.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://c.pki.goog/r/r4.crlfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          192.178.49.196
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.5
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1673878
          Start date and time:2025-04-25 09:02:01 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 52s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://address.myairmail.com
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:12
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown0.win@24/0@21/2
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 23.220.73.6, 142.250.68.227, 142.250.68.238, 74.125.137.84, 192.178.49.206, 184.29.183.29, 20.12.23.50
          • Excluded domains from analysis (whitelisted): c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: http://address.myairmail.com
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 37
          • 443 (HTTPS)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Apr 25, 2025 09:02:47.383738995 CEST49672443192.168.2.5204.79.197.203
          Apr 25, 2025 09:02:52.196263075 CEST49672443192.168.2.5204.79.197.203
          Apr 25, 2025 09:02:54.231189966 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:02:54.540047884 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:02:55.153613091 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:02:56.368092060 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:02:56.952672005 CEST4969680192.168.2.5192.178.49.195
          Apr 25, 2025 09:02:57.101058960 CEST8049696192.178.49.195192.168.2.5
          Apr 25, 2025 09:02:57.101465940 CEST4969680192.168.2.5192.178.49.195
          Apr 25, 2025 09:02:57.101690054 CEST4969680192.168.2.5192.178.49.195
          Apr 25, 2025 09:02:57.249397039 CEST8049696192.178.49.195192.168.2.5
          Apr 25, 2025 09:02:57.249782085 CEST8049696192.178.49.195192.168.2.5
          Apr 25, 2025 09:02:57.290607929 CEST4969680192.168.2.5192.178.49.195
          Apr 25, 2025 09:02:58.774995089 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:03:00.870356083 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:00.870400906 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:00.870501995 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:00.870630980 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:00.870637894 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:01.191842079 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:01.192120075 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:01.193200111 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:01.193218946 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:01.193475962 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:01.243326902 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:01.805839062 CEST49672443192.168.2.5204.79.197.203
          Apr 25, 2025 09:03:03.586965084 CEST49676443192.168.2.520.189.173.14
          Apr 25, 2025 09:03:09.987572908 CEST49675443192.168.2.52.23.227.208
          Apr 25, 2025 09:03:09.987632990 CEST443496752.23.227.208192.168.2.5
          Apr 25, 2025 09:03:09.987952948 CEST49675443192.168.2.52.23.227.208
          Apr 25, 2025 09:03:09.987970114 CEST443496752.23.227.208192.168.2.5
          Apr 25, 2025 09:03:10.440609932 CEST49705443192.168.2.5150.171.28.254
          Apr 25, 2025 09:03:10.440654993 CEST44349705150.171.28.254192.168.2.5
          Apr 25, 2025 09:03:10.440730095 CEST49705443192.168.2.5150.171.28.254
          Apr 25, 2025 09:03:10.441051006 CEST49705443192.168.2.5150.171.28.254
          Apr 25, 2025 09:03:10.441063881 CEST44349705150.171.28.254192.168.2.5
          Apr 25, 2025 09:03:10.883713007 CEST44349705150.171.28.254192.168.2.5
          Apr 25, 2025 09:03:10.883788109 CEST49705443192.168.2.5150.171.28.254
          Apr 25, 2025 09:03:11.216284037 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:11.216345072 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:11.216516972 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:12.058253050 CEST49701443192.168.2.5192.178.49.196
          Apr 25, 2025 09:03:12.058284044 CEST44349701192.178.49.196192.168.2.5
          Apr 25, 2025 09:03:13.197474957 CEST49676443192.168.2.520.189.173.14
          TimestampSource PortDest PortSource IPDest IP
          Apr 25, 2025 09:02:56.946491957 CEST53584401.1.1.1192.168.2.5
          Apr 25, 2025 09:02:57.954958916 CEST53612421.1.1.1192.168.2.5
          Apr 25, 2025 09:03:00.728811026 CEST4999453192.168.2.51.1.1.1
          Apr 25, 2025 09:03:00.728954077 CEST6127453192.168.2.51.1.1.1
          Apr 25, 2025 09:03:00.868923903 CEST53499941.1.1.1192.168.2.5
          Apr 25, 2025 09:03:00.869594097 CEST53612741.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.411015987 CEST6132553192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.411180019 CEST5116053192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.416616917 CEST6081853192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.416771889 CEST6429553192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.587968111 CEST53608181.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.588829041 CEST53613251.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.597481966 CEST53642951.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.598115921 CEST5052453192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.610714912 CEST53511601.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.741853952 CEST53505241.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.745100975 CEST4946353192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.745376110 CEST6004753192.168.2.51.1.1.1
          Apr 25, 2025 09:03:02.900058031 CEST53494631.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.900103092 CEST53600471.1.1.1192.168.2.5
          Apr 25, 2025 09:03:02.929765940 CEST5408353192.168.2.58.8.8.8
          Apr 25, 2025 09:03:02.934660912 CEST5032953192.168.2.51.1.1.1
          Apr 25, 2025 09:03:03.074965954 CEST53503291.1.1.1192.168.2.5
          Apr 25, 2025 09:03:03.086571932 CEST53540838.8.8.8192.168.2.5
          Apr 25, 2025 09:03:03.937206984 CEST5474853192.168.2.51.1.1.1
          Apr 25, 2025 09:03:03.937428951 CEST6092853192.168.2.51.1.1.1
          Apr 25, 2025 09:03:04.079142094 CEST53609281.1.1.1192.168.2.5
          Apr 25, 2025 09:03:04.088295937 CEST53547481.1.1.1192.168.2.5
          Apr 25, 2025 09:03:09.108766079 CEST5797753192.168.2.51.1.1.1
          Apr 25, 2025 09:03:09.108933926 CEST4957453192.168.2.51.1.1.1
          Apr 25, 2025 09:03:09.258301020 CEST53495741.1.1.1192.168.2.5
          Apr 25, 2025 09:03:09.266870022 CEST53579771.1.1.1192.168.2.5
          Apr 25, 2025 09:03:09.267554998 CEST5473653192.168.2.51.1.1.1
          Apr 25, 2025 09:03:09.409832954 CEST53547361.1.1.1192.168.2.5
          Apr 25, 2025 09:03:14.952297926 CEST53592951.1.1.1192.168.2.5
          Apr 25, 2025 09:03:15.842756987 CEST6113753192.168.2.51.1.1.1
          Apr 25, 2025 09:03:15.842973948 CEST5660753192.168.2.51.1.1.1
          Apr 25, 2025 09:03:15.989715099 CEST53566071.1.1.1192.168.2.5
          Apr 25, 2025 09:03:16.039022923 CEST53611371.1.1.1192.168.2.5
          Apr 25, 2025 09:03:16.039711952 CEST5250253192.168.2.51.1.1.1
          Apr 25, 2025 09:03:16.181535006 CEST53525021.1.1.1192.168.2.5
          Apr 25, 2025 09:03:16.192673922 CEST6367853192.168.2.51.1.1.1
          Apr 25, 2025 09:03:16.193001986 CEST5186453192.168.2.58.8.8.8
          Apr 25, 2025 09:03:16.333071947 CEST53636781.1.1.1192.168.2.5
          Apr 25, 2025 09:03:16.350214958 CEST53518648.8.8.8192.168.2.5
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 25, 2025 09:03:00.728811026 CEST192.168.2.51.1.1.10xa0acStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:00.728954077 CEST192.168.2.51.1.1.10x226bStandard query (0)www.google.com65IN (0x0001)false
          Apr 25, 2025 09:03:02.411015987 CEST192.168.2.51.1.1.10xd45bStandard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:02.411180019 CEST192.168.2.51.1.1.10x8c49Standard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:02.416616917 CEST192.168.2.51.1.1.10x257Standard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:02.416771889 CEST192.168.2.51.1.1.10x533Standard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:02.598115921 CEST192.168.2.51.1.1.10x8ed5Standard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:02.745100975 CEST192.168.2.51.1.1.10x3b54Standard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:02.745376110 CEST192.168.2.51.1.1.10xd966Standard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:02.929765940 CEST192.168.2.58.8.8.80x846bStandard query (0)google.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:02.934660912 CEST192.168.2.51.1.1.10x176eStandard query (0)google.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:03.937206984 CEST192.168.2.51.1.1.10xa0cfStandard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:03.937428951 CEST192.168.2.51.1.1.10x2c66Standard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:09.108766079 CEST192.168.2.51.1.1.10x4a4fStandard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:09.108933926 CEST192.168.2.51.1.1.10x73bStandard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:09.267554998 CEST192.168.2.51.1.1.10xd0bfStandard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:15.842756987 CEST192.168.2.51.1.1.10xee0fStandard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:15.842973948 CEST192.168.2.51.1.1.10xc1f7Standard query (0)address.myairmail.com65IN (0x0001)false
          Apr 25, 2025 09:03:16.039711952 CEST192.168.2.51.1.1.10xeb23Standard query (0)address.myairmail.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:16.192673922 CEST192.168.2.51.1.1.10x7795Standard query (0)google.comA (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:16.193001986 CEST192.168.2.58.8.8.80x1372Standard query (0)google.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 25, 2025 09:03:00.868923903 CEST1.1.1.1192.168.2.50xa0acNo error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:00.869594097 CEST1.1.1.1192.168.2.50x226bNo error (0)www.google.com65IN (0x0001)false
          Apr 25, 2025 09:03:03.074965954 CEST1.1.1.1192.168.2.50x176eNo error (0)google.com142.250.68.238A (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:03.086571932 CEST8.8.8.8192.168.2.50x846bNo error (0)google.com142.250.69.14A (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:16.333071947 CEST1.1.1.1192.168.2.50x7795No error (0)google.com192.178.49.174A (IP address)IN (0x0001)false
          Apr 25, 2025 09:03:16.350214958 CEST8.8.8.8192.168.2.50x1372No error (0)google.com142.250.69.14A (IP address)IN (0x0001)false
          • c.pki.goog
          Session IDSource IPSource PortDestination IPDestination Port
          0192.168.2.549696192.178.49.19580
          TimestampBytes transferredDirectionData
          Apr 25, 2025 09:02:57.101690054 CEST200OUTGET /r/r4.crl HTTP/1.1
          Cache-Control: max-age = 3000
          Connection: Keep-Alive
          Accept: */*
          If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
          User-Agent: Microsoft-CryptoAPI/10.0
          Host: c.pki.goog
          Apr 25, 2025 09:02:57.249782085 CEST1242INHTTP/1.1 200 OK
          Accept-Ranges: bytes
          Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
          Cross-Origin-Resource-Policy: cross-origin
          Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
          Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
          Content-Length: 530
          X-Content-Type-Options: nosniff
          Server: sffe
          X-XSS-Protection: 0
          Date: Fri, 25 Apr 2025 07:00:42 GMT
          Expires: Fri, 25 Apr 2025 07:50:42 GMT
          Cache-Control: public, max-age=3000
          Age: 135
          Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
          Content-Type: application/pkix-crl
          Vary: Accept-Encoding
          Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
          Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


          0510152025s020406080100

          Click to jump to process

          0510152025s0.0050100MB

          Click to jump to process

          Target ID:0
          Start time:03:02:49
          Start date:25/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff7dcfa0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:03:02:54
          Start date:25/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3
          Imagebase:0x7ff7dcfa0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:7
          Start time:03:02:57
          Start date:25/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7057347569423250158,16475539366718190943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8
          Imagebase:0x7ff7dcfa0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:10
          Start time:03:03:01
          Start date:25/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://address.myairmail.com"
          Imagebase:0x7ff7dcfa0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

          No disassembly