Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://chhimi.com:443/

Overview

General Information

Sample URL:http://chhimi.com:443/
Analysis ID:1521939
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1940,i,12299406671408751305,17941189542448052009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://chhimi.com:443/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.164.97
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.164.97
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: chhimi.com:443Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: chhimi.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: unknown0.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1940,i,12299406671408751305,17941189542448052009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://chhimi.com:443/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1940,i,12299406671408751305,17941189542448052009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.185.132
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        chhimi.com
        193.149.176.248
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://chhimi.com:443/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            193.149.176.248
            chhimi.comDenmark
            15411DANISCODKfalse
            142.250.185.132
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1521939
            Start date and time:2024-09-29 06:08:14 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 59s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://chhimi.com:443/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.186.110, 142.251.168.84, 34.104.35.123, 184.28.90.27, 4.245.163.56, 199.232.210.172, 192.229.221.95, 20.242.39.171
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://chhimi.com:443/
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Sep 29, 2024 06:09:01.307779074 CEST49675443192.168.2.4173.222.162.32
            Sep 29, 2024 06:09:10.915843964 CEST49675443192.168.2.4173.222.162.32
            Sep 29, 2024 06:09:11.011617899 CEST49735443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:11.011639118 CEST44349735193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:11.011703014 CEST49735443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:11.012022018 CEST49736443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:11.012048006 CEST49735443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:11.012058020 CEST44349735193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:11.012064934 CEST44349736193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:11.012095928 CEST44349735193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:11.012125015 CEST49736443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.302210093 CEST49738443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.302253008 CEST44349738193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.302318096 CEST49738443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.325877905 CEST49736443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.325901031 CEST44349736193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.325953007 CEST44349736193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.326447964 CEST49738443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.326507092 CEST44349738193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.326566935 CEST44349738193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.327296019 CEST49740443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.327336073 CEST44349740193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.327467918 CEST49740443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.327577114 CEST49740443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:12.327589035 CEST44349740193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:12.327608109 CEST44349740193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:13.029236078 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.029354095 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:13.029450893 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.029726982 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.029758930 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:13.758476019 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:13.758943081 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.759011984 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:13.760059118 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:13.760143042 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.965233088 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:13.965459108 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:14.009646893 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:14.009692907 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:14.056540966 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:17.372095108 CEST49744443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.372147083 CEST44349744193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.372219086 CEST49744443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.372570992 CEST49745443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.372617960 CEST44349745193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.372714043 CEST49745443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.392729998 CEST49745443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.392756939 CEST44349745193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.392807961 CEST44349745193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.393292904 CEST49744443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.393309116 CEST44349744193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.393347979 CEST44349744193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.393749952 CEST49746443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.393781900 CEST44349746193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.393851042 CEST49746443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.394018888 CEST49746443192.168.2.4193.149.176.248
            Sep 29, 2024 06:09:17.394027948 CEST44349746193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:17.394043922 CEST44349746193.149.176.248192.168.2.4
            Sep 29, 2024 06:09:23.607814074 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:23.607875109 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:23.607956886 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:23.933446884 CEST49741443192.168.2.4142.250.185.132
            Sep 29, 2024 06:09:23.933476925 CEST44349741142.250.185.132192.168.2.4
            Sep 29, 2024 06:09:26.792820930 CEST4972380192.168.2.42.16.164.97
            Sep 29, 2024 06:09:26.802284002 CEST80497232.16.164.97192.168.2.4
            Sep 29, 2024 06:09:26.802341938 CEST4972380192.168.2.42.16.164.97
            TimestampSource PortDest PortSource IPDest IP
            Sep 29, 2024 06:09:09.521656990 CEST53614801.1.1.1192.168.2.4
            Sep 29, 2024 06:09:09.709635019 CEST53567251.1.1.1192.168.2.4
            Sep 29, 2024 06:09:10.586153030 CEST53497001.1.1.1192.168.2.4
            Sep 29, 2024 06:09:10.987173080 CEST5646253192.168.2.41.1.1.1
            Sep 29, 2024 06:09:10.987333059 CEST5732353192.168.2.41.1.1.1
            Sep 29, 2024 06:09:10.998437881 CEST53564621.1.1.1192.168.2.4
            Sep 29, 2024 06:09:11.274566889 CEST53573231.1.1.1192.168.2.4
            Sep 29, 2024 06:09:13.019131899 CEST6538353192.168.2.41.1.1.1
            Sep 29, 2024 06:09:13.019366980 CEST5408853192.168.2.41.1.1.1
            Sep 29, 2024 06:09:13.026510000 CEST53540881.1.1.1192.168.2.4
            Sep 29, 2024 06:09:13.028269053 CEST53653831.1.1.1192.168.2.4
            Sep 29, 2024 06:09:27.156750917 CEST138138192.168.2.4192.168.2.255
            Sep 29, 2024 06:09:28.048928976 CEST53561041.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Sep 29, 2024 06:09:11.274631023 CEST192.168.2.41.1.1.1c21a(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Sep 29, 2024 06:09:10.987173080 CEST192.168.2.41.1.1.10xf7feStandard query (0)chhimi.comA (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:10.987333059 CEST192.168.2.41.1.1.10xcedeStandard query (0)chhimi.com65IN (0x0001)false
            Sep 29, 2024 06:09:13.019131899 CEST192.168.2.41.1.1.10xef1cStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:13.019366980 CEST192.168.2.41.1.1.10xead1Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Sep 29, 2024 06:09:10.998437881 CEST1.1.1.1192.168.2.40xf7feNo error (0)chhimi.com193.149.176.248A (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:13.026510000 CEST1.1.1.1192.168.2.40xead1No error (0)www.google.com65IN (0x0001)false
            Sep 29, 2024 06:09:13.028269053 CEST1.1.1.1192.168.2.40xef1cNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:24.157017946 CEST1.1.1.1192.168.2.40x1001No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:24.157017946 CEST1.1.1.1192.168.2.40x1001No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Sep 29, 2024 06:09:25.666071892 CEST1.1.1.1192.168.2.40xbd69No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Sep 29, 2024 06:09:25.666071892 CEST1.1.1.1192.168.2.40xbd69No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • chhimi.com:443
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:11.012048006 CEST429OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:12.325877905 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449738193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:12.326447964 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449740193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:12.327577114 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449745193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:17.392729998 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.449744193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:17.393292904 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.449746193.149.176.2484433096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Sep 29, 2024 06:09:17.394018888 CEST455OUTGET / HTTP/1.1
            Host: chhimi.com:443
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:00:09:04
            Start date:29/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:00:09:07
            Start date:29/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1940,i,12299406671408751305,17941189542448052009,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:00:09:10
            Start date:29/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://chhimi.com:443/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly