Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://dhh.nihaopiaoliangaa.top/

Overview

General Information

Sample URL:https://dhh.nihaopiaoliangaa.top/
Analysis ID:1521728
Tags:openphish
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2676 --field-trial-handle=2636,i,18439441402017028220,12898763522697465529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhh.nihaopiaoliangaa.top/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://dhh.nihaopiaoliangaa.top/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:53731 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:53732 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dhh.nihaopiaoliangaa.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dhh.nihaopiaoliangaa.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dhh.nihaopiaoliangaa.top/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: dhh.nihaopiaoliangaa.top
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Sun, 29 Sep 2024 00:49:40 GMTContent-Type: text/plain; charset=utf-8Content-Length: 14Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Sun, 29 Sep 2024 00:49:40 GMTContent-Type: text/plain; charset=utf-8Content-Length: 14Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 53736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/4@5/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2676 --field-trial-handle=2636,i,18439441402017028220,12898763522697465529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhh.nihaopiaoliangaa.top/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2676 --field-trial-handle=2636,i,18439441402017028220,12898763522697465529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    216.58.206.36
    truefalse
      unknown
      dhh.nihaopiaoliangaa.top
      43.228.125.114
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://dhh.nihaopiaoliangaa.top/favicon.icofalse
            unknown
            https://dhh.nihaopiaoliangaa.top/false
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              43.228.125.114
              dhh.nihaopiaoliangaa.topHong Kong
              133905LAYER-ASLayerstackLimitedHKfalse
              216.58.206.36
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.7
              192.168.2.4
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1521728
              Start date and time:2024-09-29 02:48:42 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 9s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://dhh.nihaopiaoliangaa.top/
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@21/4@5/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.185.131, 142.250.186.78, 64.233.167.84, 34.104.35.123, 4.245.163.56, 199.232.210.172, 192.229.221.95, 13.95.31.18, 13.85.23.206, 40.69.42.241, 131.107.255.255
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://dhh.nihaopiaoliangaa.top/
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):14
              Entropy (8bit):3.3787834934861767
              Encrypted:false
              SSDEEP:3:eRbn:eRbn
              MD5:3BE7B8B182CCD96E48989B4E57311193
              SHA1:78FB38F212FA49029AFF24C669A39648D9B4E68B
              SHA-256:D5558CD419C8D46BDC958064CB97F963D1EA793866414C025906EC15033512ED
              SHA-512:F3781CBB4E9E190DF38C3FE7FA80BA69BF6F9DBAFB158E0426DD4604F2F1BA794450679005A38D0F9F1DAD0696E2F22B8B086B2D7D08A0F99BB4FD3B0F7ED5D8
              Malicious:false
              Reputation:low
              URL:https://dhh.nihaopiaoliangaa.top/favicon.ico
              Preview:404: Not Found
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):14
              Entropy (8bit):3.3787834934861767
              Encrypted:false
              SSDEEP:3:eRbn:eRbn
              MD5:3BE7B8B182CCD96E48989B4E57311193
              SHA1:78FB38F212FA49029AFF24C669A39648D9B4E68B
              SHA-256:D5558CD419C8D46BDC958064CB97F963D1EA793866414C025906EC15033512ED
              SHA-512:F3781CBB4E9E190DF38C3FE7FA80BA69BF6F9DBAFB158E0426DD4604F2F1BA794450679005A38D0F9F1DAD0696E2F22B8B086B2D7D08A0F99BB4FD3B0F7ED5D8
              Malicious:false
              Reputation:low
              URL:https://dhh.nihaopiaoliangaa.top/
              Preview:404: Not Found
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Sep 29, 2024 02:49:27.247755051 CEST49675443192.168.2.4173.222.162.32
              Sep 29, 2024 02:49:36.857578039 CEST49675443192.168.2.4173.222.162.32
              Sep 29, 2024 02:49:38.742651939 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.742701054 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:38.742815971 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.743319988 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.743417978 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:38.743483067 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.753174067 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.753207922 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:38.755770922 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:38.755786896 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.680991888 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.681533098 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.681551933 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.682580948 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.682737112 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.687865019 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.687954903 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.688065052 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.688076019 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.688385010 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.688790083 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.688832045 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.690309048 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.690381050 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.692137003 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.692230940 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.731350899 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.746321917 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:39.746349096 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:39.794035912 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:40.229754925 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:40.230631113 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:40.230731964 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:40.231713057 CEST49735443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:40.231733084 CEST4434973543.228.125.114192.168.2.4
              Sep 29, 2024 02:49:40.689191103 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:40.689291000 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:40.689380884 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:40.691159010 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:40.691210032 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:40.695261955 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:40.735426903 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:41.033303022 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:41.033456087 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:41.033538103 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:41.309277058 CEST49736443192.168.2.443.228.125.114
              Sep 29, 2024 02:49:41.309339046 CEST4434973643.228.125.114192.168.2.4
              Sep 29, 2024 02:49:41.348156929 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:41.372817039 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:41.372847080 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:41.373919964 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:41.373996973 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:41.382800102 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:41.382880926 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:41.437577009 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:41.437596083 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:41.484469891 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:41.693186998 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:41.693221092 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:41.693442106 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:41.698833942 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:41.698848963 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.344945908 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.345021963 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.375226021 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.375247002 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.376274109 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.419261932 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.766978025 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.807436943 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.975955009 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.976084948 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.976167917 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.976358891 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.976372957 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:42.976383924 CEST49740443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:42.976388931 CEST44349740184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.079377890 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.079412937 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.079580069 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.080051899 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.080066919 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.721905947 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.722016096 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.735728979 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.735742092 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.736617088 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.737817049 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:43.783405066 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.998032093 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:43.998225927 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:44.000068903 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:44.091423988 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:44.091423988 CEST49741443192.168.2.4184.28.90.27
              Sep 29, 2024 02:49:44.091454029 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:44.091461897 CEST44349741184.28.90.27192.168.2.4
              Sep 29, 2024 02:49:51.268682003 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:51.268838882 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:51.268913031 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:51.355984926 CEST49739443192.168.2.4216.58.206.36
              Sep 29, 2024 02:49:51.356012106 CEST44349739216.58.206.36192.168.2.4
              Sep 29, 2024 02:49:54.141006947 CEST4972380192.168.2.493.184.221.240
              Sep 29, 2024 02:49:54.147161961 CEST804972393.184.221.240192.168.2.4
              Sep 29, 2024 02:49:54.147212982 CEST4972380192.168.2.493.184.221.240
              Sep 29, 2024 02:49:54.301307917 CEST5373153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:54.306154013 CEST53537311.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.306252956 CEST5373153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:54.306252956 CEST5373153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:54.311026096 CEST53537311.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.753443956 CEST53537311.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.757843018 CEST5373153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:54.762990952 CEST53537311.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.763183117 CEST5373153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.052826881 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.057636023 CEST53537321.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.057777882 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.057848930 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.057848930 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.062740088 CEST53537321.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.062767029 CEST53537321.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.514393091 CEST53537321.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.515052080 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:49:55.520107985 CEST53537321.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.520184040 CEST5373253192.168.2.41.1.1.1
              Sep 29, 2024 02:50:40.849709034 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:40.849762917 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:40.849874020 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:40.850290060 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:40.850305080 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:41.514497042 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:41.518795967 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:41.518806934 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:41.519114017 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:41.520025015 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:41.520082951 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:41.560045004 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:43.153863907 CEST4972480192.168.2.493.184.221.240
              Sep 29, 2024 02:50:43.158878088 CEST804972493.184.221.240192.168.2.4
              Sep 29, 2024 02:50:43.158931017 CEST4972480192.168.2.493.184.221.240
              Sep 29, 2024 02:50:51.421546936 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:51.421621084 CEST44353736216.58.206.36192.168.2.4
              Sep 29, 2024 02:50:51.421731949 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:53.108731985 CEST53736443192.168.2.4216.58.206.36
              Sep 29, 2024 02:50:53.108753920 CEST44353736216.58.206.36192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Sep 29, 2024 02:49:36.901478052 CEST53598431.1.1.1192.168.2.4
              Sep 29, 2024 02:49:36.903096914 CEST53645051.1.1.1192.168.2.4
              Sep 29, 2024 02:49:37.917165995 CEST6265953192.168.2.41.1.1.1
              Sep 29, 2024 02:49:37.917651892 CEST5935753192.168.2.41.1.1.1
              Sep 29, 2024 02:49:37.959397078 CEST53654561.1.1.1192.168.2.4
              Sep 29, 2024 02:49:38.366583109 CEST53593571.1.1.1192.168.2.4
              Sep 29, 2024 02:49:38.367042065 CEST5564753192.168.2.41.1.1.1
              Sep 29, 2024 02:49:38.562397957 CEST53626591.1.1.1192.168.2.4
              Sep 29, 2024 02:49:38.967401028 CEST53556471.1.1.1192.168.2.4
              Sep 29, 2024 02:49:40.665139914 CEST5808153192.168.2.41.1.1.1
              Sep 29, 2024 02:49:40.671780109 CEST53580811.1.1.1192.168.2.4
              Sep 29, 2024 02:49:40.678602934 CEST5068653192.168.2.41.1.1.1
              Sep 29, 2024 02:49:40.685134888 CEST53506861.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.300903082 CEST53520061.1.1.1192.168.2.4
              Sep 29, 2024 02:49:54.739006042 CEST138138192.168.2.4192.168.2.255
              Sep 29, 2024 02:49:55.052229881 CEST53592591.1.1.1192.168.2.4
              Sep 29, 2024 02:49:55.052397013 CEST53542131.1.1.1192.168.2.4
              Sep 29, 2024 02:50:36.359291077 CEST53634201.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Sep 29, 2024 02:49:38.967478991 CEST192.168.2.41.1.1.1c1ee(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 29, 2024 02:49:37.917165995 CEST192.168.2.41.1.1.10x831dStandard query (0)dhh.nihaopiaoliangaa.topA (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:37.917651892 CEST192.168.2.41.1.1.10xfbcbStandard query (0)dhh.nihaopiaoliangaa.top65IN (0x0001)false
              Sep 29, 2024 02:49:38.367042065 CEST192.168.2.41.1.1.10x2e1aStandard query (0)dhh.nihaopiaoliangaa.top65IN (0x0001)false
              Sep 29, 2024 02:49:40.665139914 CEST192.168.2.41.1.1.10xa73dStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:40.678602934 CEST192.168.2.41.1.1.10x42bcStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 29, 2024 02:49:38.366583109 CEST1.1.1.1192.168.2.40xfbcbServer failure (2)dhh.nihaopiaoliangaa.topnonenone65IN (0x0001)false
              Sep 29, 2024 02:49:38.562397957 CEST1.1.1.1192.168.2.40x831dNo error (0)dhh.nihaopiaoliangaa.top43.228.125.114A (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:38.967401028 CEST1.1.1.1192.168.2.40x2e1aServer failure (2)dhh.nihaopiaoliangaa.topnonenone65IN (0x0001)false
              Sep 29, 2024 02:49:40.671780109 CEST1.1.1.1192.168.2.40xa73dNo error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:40.685134888 CEST1.1.1.1192.168.2.40x42bcNo error (0)www.google.com65IN (0x0001)false
              Sep 29, 2024 02:49:51.374526978 CEST1.1.1.1192.168.2.40x879No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:51.374526978 CEST1.1.1.1192.168.2.40x879No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Sep 29, 2024 02:49:53.121867895 CEST1.1.1.1192.168.2.40x25aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 29, 2024 02:49:53.121867895 CEST1.1.1.1192.168.2.40x25aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • dhh.nihaopiaoliangaa.top
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973543.228.125.1144432536C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-29 00:49:39 UTC667OUTGET / HTTP/1.1
              Host: dhh.nihaopiaoliangaa.top
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-29 00:49:40 UTC158INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Sun, 29 Sep 2024 00:49:40 GMT
              Content-Type: text/plain; charset=utf-8
              Content-Length: 14
              Connection: close
              2024-09-29 00:49:40 UTC14INData Raw: 34 30 34 3a 20 4e 6f 74 20 46 6f 75 6e 64
              Data Ascii: 404: Not Found


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973643.228.125.1144432536C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-29 00:49:40 UTC604OUTGET /favicon.ico HTTP/1.1
              Host: dhh.nihaopiaoliangaa.top
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://dhh.nihaopiaoliangaa.top/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-29 00:49:41 UTC158INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Sun, 29 Sep 2024 00:49:40 GMT
              Content-Type: text/plain; charset=utf-8
              Content-Length: 14
              Connection: close
              2024-09-29 00:49:41 UTC14INData Raw: 34 30 34 3a 20 4e 6f 74 20 46 6f 75 6e 64
              Data Ascii: 404: Not Found


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449740184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-29 00:49:42 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-29 00:49:42 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF67)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-neu-z1
              Cache-Control: public, max-age=143720
              Date: Sun, 29 Sep 2024 00:49:42 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449741184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-29 00:49:43 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-29 00:49:43 UTC515INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=143749
              Date: Sun, 29 Sep 2024 00:49:43 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-29 00:49:43 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:20:49:30
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:20:49:34
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2676 --field-trial-handle=2636,i,18439441402017028220,12898763522697465529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:20:49:36
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhh.nihaopiaoliangaa.top/"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly