Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://stamfordadelaide.guestreservations.com:443

Overview

General Information

Sample URL:http://stamfordadelaide.guestreservations.com:443
Analysis ID:1501918
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3620 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2268,i,15634059175318366335,5528047185288191013,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stamfordadelaide.guestreservations.com:443" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: stamfordadelaide.guestreservations.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: stamfordadelaide.guestreservations.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: unknown0.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2268,i,15634059175318366335,5528047185288191013,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stamfordadelaide.guestreservations.com:443"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2268,i,15634059175318366335,5528047185288191013,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://stamfordadelaide.guestreservations.com:4430%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://stamfordadelaide.guestreservations.com:443/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
stamfordadelaide.guestreservations.com
104.18.6.251
truefalse
    unknown
    www.google.com
    142.250.185.164
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://stamfordadelaide.guestreservations.com:443/false
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        104.18.6.251
        stamfordadelaide.guestreservations.comUnited States
        13335CLOUDFLARENETUSfalse
        142.250.185.164
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1501918
        Start date and time:2024-08-30 18:40:56 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 1m 51s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://stamfordadelaide.guestreservations.com:443
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:5
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@19/0@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 66.102.1.84, 142.250.185.67, 142.250.185.206, 34.104.35.123, 184.28.90.27, 40.68.123.157, 88.221.110.91, 2.16.100.168, 192.229.221.95, 13.85.23.206
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: http://stamfordadelaide.guestreservations.com:443
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Aug 30, 2024 18:41:39.837635994 CEST49675443192.168.2.4173.222.162.32
        Aug 30, 2024 18:41:49.602190971 CEST49675443192.168.2.4173.222.162.32
        Aug 30, 2024 18:41:50.301886082 CEST49736443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:50.301918030 CEST44349736104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:50.301987886 CEST49736443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:50.302391052 CEST49737443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:50.302421093 CEST44349737104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:50.302656889 CEST49736443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:50.302670956 CEST44349736104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:50.302689075 CEST49737443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:50.302721024 CEST44349736104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.389573097 CEST49740443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.389601946 CEST44349740104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.389681101 CEST49740443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.414010048 CEST49737443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.414026022 CEST44349737104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.414107084 CEST44349737104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.414663076 CEST49740443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.414674997 CEST44349740104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.414717913 CEST44349740104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.415482044 CEST49741443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.415510893 CEST44349741104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.415585995 CEST49741443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.415692091 CEST49741443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:51.415707111 CEST44349741104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:51.415729046 CEST44349741104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:53.037185907 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.037220001 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.037338018 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.038176060 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.038187981 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.693625927 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.693962097 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.693974972 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.695048094 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.695171118 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.696511030 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.696568012 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.742669106 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:53.742677927 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:41:53.789489985 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:41:56.522519112 CEST49745443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.522551060 CEST44349745104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.522793055 CEST49745443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.523017883 CEST49746443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.523024082 CEST44349746104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.523147106 CEST49746443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.531039953 CEST49746443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.531054974 CEST44349746104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.531111956 CEST44349746104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.532126904 CEST49745443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.532138109 CEST44349745104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.532195091 CEST44349745104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.533020973 CEST49747443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.533085108 CEST44349747104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.533188105 CEST49747443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.533343077 CEST49747443192.168.2.4104.18.6.251
        Aug 30, 2024 18:41:56.533379078 CEST44349747104.18.6.251192.168.2.4
        Aug 30, 2024 18:41:56.533407927 CEST44349747104.18.6.251192.168.2.4
        Aug 30, 2024 18:42:03.594208002 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:42:03.594268084 CEST44349742142.250.185.164192.168.2.4
        Aug 30, 2024 18:42:03.594352961 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:42:04.769757986 CEST49742443192.168.2.4142.250.185.164
        Aug 30, 2024 18:42:04.769779921 CEST44349742142.250.185.164192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Aug 30, 2024 18:41:48.469625950 CEST53514891.1.1.1192.168.2.4
        Aug 30, 2024 18:41:48.470140934 CEST53569261.1.1.1192.168.2.4
        Aug 30, 2024 18:41:49.471647024 CEST53569601.1.1.1192.168.2.4
        Aug 30, 2024 18:41:50.278974056 CEST6171653192.168.2.41.1.1.1
        Aug 30, 2024 18:41:50.290263891 CEST53617161.1.1.1192.168.2.4
        Aug 30, 2024 18:41:50.293754101 CEST4946953192.168.2.41.1.1.1
        Aug 30, 2024 18:41:50.311630964 CEST53494691.1.1.1192.168.2.4
        Aug 30, 2024 18:41:53.025542974 CEST6497453192.168.2.41.1.1.1
        Aug 30, 2024 18:41:53.026245117 CEST5282653192.168.2.41.1.1.1
        Aug 30, 2024 18:41:53.032639027 CEST53649741.1.1.1192.168.2.4
        Aug 30, 2024 18:41:53.032866955 CEST53528261.1.1.1192.168.2.4
        Aug 30, 2024 18:42:06.612884998 CEST53554991.1.1.1192.168.2.4
        Aug 30, 2024 18:42:09.203577995 CEST138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPChecksumCodeType
        Aug 30, 2024 18:41:50.312992096 CEST192.168.2.41.1.1.1c242(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Aug 30, 2024 18:41:50.278974056 CEST192.168.2.41.1.1.10xeb8cStandard query (0)stamfordadelaide.guestreservations.comA (IP address)IN (0x0001)false
        Aug 30, 2024 18:41:50.293754101 CEST192.168.2.41.1.1.10xe4b3Standard query (0)stamfordadelaide.guestreservations.com65IN (0x0001)false
        Aug 30, 2024 18:41:53.025542974 CEST192.168.2.41.1.1.10xa21eStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Aug 30, 2024 18:41:53.026245117 CEST192.168.2.41.1.1.10x6306Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Aug 30, 2024 18:41:50.290263891 CEST1.1.1.1192.168.2.40xeb8cNo error (0)stamfordadelaide.guestreservations.com104.18.6.251A (IP address)IN (0x0001)false
        Aug 30, 2024 18:41:50.290263891 CEST1.1.1.1192.168.2.40xeb8cNo error (0)stamfordadelaide.guestreservations.com104.18.7.251A (IP address)IN (0x0001)false
        Aug 30, 2024 18:41:50.311630964 CEST1.1.1.1192.168.2.40xe4b3No error (0)stamfordadelaide.guestreservations.com65IN (0x0001)false
        Aug 30, 2024 18:41:53.032639027 CEST1.1.1.1192.168.2.40xa21eNo error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
        Aug 30, 2024 18:41:53.032866955 CEST1.1.1.1192.168.2.40x6306No error (0)www.google.com65IN (0x0001)false
        Aug 30, 2024 18:42:03.503161907 CEST1.1.1.1192.168.2.40x8f9dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Aug 30, 2024 18:42:03.503161907 CEST1.1.1.1192.168.2.40x8f9dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        • stamfordadelaide.guestreservations.com:443
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449736104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:50.302656889 CEST457OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449737104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:51.414010048 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.449740104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:51.414663076 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.449741104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:51.415692091 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        4192.168.2.449746104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:56.531039953 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        5192.168.2.449745104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:56.532126904 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        6192.168.2.449747104.18.6.2514433748C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 30, 2024 18:41:56.533343077 CEST483OUTGET / HTTP/1.1
        Host: stamfordadelaide.guestreservations.com:443
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:12:41:43
        Start date:30/08/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:12:41:47
        Start date:30/08/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2268,i,15634059175318366335,5528047185288191013,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:12:41:49
        Start date:30/08/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stamfordadelaide.guestreservations.com:443"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly