Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://illw.kr/data/asdx

Overview

General Information

Sample URL:https://illw.kr/data/asdx
Analysis ID:1522464
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 4444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3408 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,9542992241968095067,5864178729948817110,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5256 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://illw.kr/data/asdx" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://illw.kr/data/asdxHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.5:50922 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.5:59243 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /data/asdx HTTP/1.1Host: illw.krConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: illw.krConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://illw.kr/data/asdxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: illw.kr
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: 198.187.3.20.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 30 Sep 2024 05:09:10 GMTServer: Apache/2.4.43 (Unix) OpenSSL/1.0.2k-fipsX-Powered-By: PHP/5.3.29Connection: closeTransfer-Encoding: chunkedContent-Type: text/html; charset=UTF-8
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 30 Sep 2024 05:09:10 GMTServer: Apache/2.4.43 (Unix) OpenSSL/1.0.2k-fipsContent-Length: 196Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59249 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59249
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: classification engineClassification label: clean1.win@20/10@8/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,9542992241968095067,5864178729948817110,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://illw.kr/data/asdx"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,9542992241968095067,5864178729948817110,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://illw.kr/data/asdx0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
198.187.3.20.in-addr.arpa1%VirustotalBrowse
www.google.com0%VirustotalBrowse
illw.kr0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
illw.kr
121.78.246.108
truefalseunknown
www.google.com
142.250.184.196
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
198.187.3.20.in-addr.arpa
unknown
unknownfalseunknown
NameMaliciousAntivirus DetectionReputation
https://illw.kr/favicon.icofalse
    unknown
    https://illw.kr/data/asdxfalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      142.250.184.196
      www.google.comUnited States
      15169GOOGLEUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.186.132
      unknownUnited States
      15169GOOGLEUSfalse
      121.78.246.108
      illw.krKorea Republic of
      9286KINXIDC-AS-KRKINXKRfalse
      IP
      192.168.2.5
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1522464
      Start date and time:2024-09-30 07:08:08 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 10s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://illw.kr/data/asdx
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean1.win@20/10@8/5
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 216.58.212.131, 172.217.16.206, 173.194.76.84, 34.104.35.123, 20.12.23.50, 93.184.221.240, 192.229.221.95, 20.242.39.171, 20.3.187.198, 4.175.87.197, 20.114.59.183, 142.250.186.35
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      InputOutput
      URL: https://illw.kr/data/asdx Model: jbxai
      {
      "brand":[],
      "contains_trigger_text":false,
      "trigger_text":"",
      "prominent_button_name":"unknown",
      "text_input_field_labels":"unknown",
      "pdf_icon_visible":false,
      "has_visible_captcha":false,
      "has_urgent_text":false,
      "has_visible_qrcode":false}
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 04:09:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.97754221664957
      Encrypted:false
      SSDEEP:48:8ydBTpxuHS8ZidAKZdA19ehwiZUklqehRy+3:88fa+y
      MD5:21301173B957A04B26FCA6B4C4349C9F
      SHA1:D8B09AB6959BB7F89945D88597AA66E548E5EFA2
      SHA-256:637F1B9914C381B693DB665C9E0162F6C666F9F393885C12BAFAF3F1E36E1439
      SHA-512:F9A4E268160C378C0DD4D55A2023A3B31FFADDAD6D49287A8BD6B5D299B6190D98F14C4617827E071BBF7143F0D5FE554A5166DFBC6EBF8EFF2EAF4DE145B376
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y#)...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 04:09:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):3.9943200456614076
      Encrypted:false
      SSDEEP:48:8qCdBTpxuHS8ZidAKZdA1weh/iZUkAQkqehuy+2:8Dfw9Qzy
      MD5:7D99F18739C1A0E66658D36B7DC5CCA3
      SHA1:50316F7FC70C621C8FFDFAF3A4885AF01A3654BF
      SHA-256:138AE1126AB34A5A3F4E24E0A017729F72BD223A7BF88426F076916DB46E3662
      SHA-512:0274087FDD89F54D344E41DF1468BA0EE47222D4A9946F323119B51A30B6B53331BA48C8AC7A24F84DFCDDD0C6997D4E76E28E56B07DB5891CEEBEBE47ECA1E7
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....@......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y#)...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2693
      Entropy (8bit):4.0019424108166675
      Encrypted:false
      SSDEEP:48:8xCdBTpxsHS8ZidAKZdA14tseh7sFiZUkmgqeh7sYy+BX:8xMfWnqy
      MD5:331D981290D8A5D1303B6B9BD205945E
      SHA1:B67E5CB0742BAF9DB84F7C63C9F6267D538E2E2B
      SHA-256:D6D2A09905049842B1D0AC9D1807788CE6487D46C08D78029208B28F24C3FF83
      SHA-512:BA83274B302EE826E485EF8865DB1AF7FC8CFF0FC2DFD9C06C153802C109348698A4D63AFA68FF0021D2F6E11E914179EF31F92EFCB2FADBBC4BA3874B857E93
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 04:09:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9919400927350823
      Encrypted:false
      SSDEEP:48:8SZdBTpxuHS8ZidAKZdA1vehDiZUkwqehCy+R:8SFfbQy
      MD5:70F9E8CAE5D6FD8F2F2886431CB7A6C1
      SHA1:12CE66476023AB211D9989357C96C05A8D25C26A
      SHA-256:51A2073BED32544CAB2321FE41EEB9095638D242A2FEF84183066C014A874F6E
      SHA-512:4DC41AC65C1B6A1FAB9B330F87B3A26DDFF8434B28119AFFA0D376670CCEA3396EAFB37D64048F809F8E88560D1DD06CCF37A6655AF28C0C29337C8B26D5F9AE
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....#.~.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y#)...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 04:09:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9821475922103193
      Encrypted:false
      SSDEEP:48:88dBTpxuHS8ZidAKZdA1hehBiZUk1W1qehEy+C:8if79ky
      MD5:FF6805E841F9E83D875035EBB7699493
      SHA1:46385B1F8F5A20436DBC2A18B586755DE3AF0DB2
      SHA-256:979099632D09F346DDA36FABB634CA58435F3A99AF8E229B63595A7CA16EF574
      SHA-512:1B6313C3032934BE19EE85FDE57BA02FE33848ED173EFAFFA7E92937EC69535D919B865F888503F1A9BEA65DFBBDEE530C6F10AC624F92613EEEC6C963D793E4
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,...........N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y#)...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 04:09:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2683
      Entropy (8bit):3.987707716742571
      Encrypted:false
      SSDEEP:48:8RCdBTpxuHS8ZidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbqy+yT+:8RMfbT/TbxWOvTbqy7T
      MD5:B8E089C9E6B2DB49EE72AF01A41D29A6
      SHA1:AE27954B70835F174068ED431DE2A0EF1DEE9585
      SHA-256:4DB9676631E55F8B9E2FA45FF5788FA5CB43AAA2D1B5ED5E9DC396922FF1A547
      SHA-512:CE8AB07E166453E7C00373A99C1C92AE8151D73C37AF337B4A80EE383EA4D413A25FDF7C872960B37183FA0C4F089168BE2F667F55A5DD3FDFFF66D0D852EE0D
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......u.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Y )....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y )....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y )....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y )..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y#)...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............w.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):201
      Entropy (8bit):5.1413177884438594
      Encrypted:false
      SSDEEP:6:pn0+t9xqObRKr6TQzetSzRx3G0Cezowoz:J0+t9xqeRKWTQzetSzRxGezG
      MD5:1B5978C9D5F3D9FC51268A3504055E86
      SHA1:8DDEBC8F0141BA718AC9C5A163FF27517D9D2049
      SHA-256:E582880E0C32601567A2201C3AD85E917A0064E1D8C3940B7C1C3356581ECB57
      SHA-512:BF04E749BD520C48A417E5A63B375BFD2EF42DEAA5AC4D8EB006B4EE1A832168C772C209E23ED65004A173E21DDCA9D6C3A8271AEDB3866F7A3AFC046C590EF7
      Malicious:false
      Reputation:low
      URL:https://illw.kr/data/asdx
      Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">..<html><head>..<title>404 Not Found</title>..</head><body>..<h1>Not Found</h1>..<p>The requested URL was not found on this server.</p>..</body></html>
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text
      Category:downloaded
      Size (bytes):196
      Entropy (8bit):5.098952451791238
      Encrypted:false
      SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezocKqD:J0+oxBeRmR9etdzRxGez1T
      MD5:62962DAA1B19BBCC2DB10B7BFD531EA6
      SHA1:D64BAE91091EDA6A7532EBEC06AA70893B79E1F8
      SHA-256:80C3FE2AE1062ABF56456F52518BD670F9EC3917B7F85E152B347AC6B6FAF880
      SHA-512:9002A0475FDB38541E78048709006926655C726E93E823B84E2DBF5B53FD539A5342E7266447D23DB0E5528E27A19961B115B180C94F2272FF124C7E5C8304E7
      Malicious:false
      Reputation:low
      URL:https://illw.kr/favicon.ico
      Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.</body></html>.
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Sep 30, 2024 07:08:57.105866909 CEST49675443192.168.2.523.1.237.91
      Sep 30, 2024 07:08:57.105879068 CEST49674443192.168.2.523.1.237.91
      Sep 30, 2024 07:08:57.199579000 CEST49673443192.168.2.523.1.237.91
      Sep 30, 2024 07:09:06.710746050 CEST49675443192.168.2.523.1.237.91
      Sep 30, 2024 07:09:06.710748911 CEST49674443192.168.2.523.1.237.91
      Sep 30, 2024 07:09:06.804485083 CEST49673443192.168.2.523.1.237.91
      Sep 30, 2024 07:09:08.250895023 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.250950098 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.251010895 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.251789093 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.251801968 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.446595907 CEST4434970323.1.237.91192.168.2.5
      Sep 30, 2024 07:09:08.446701050 CEST49703443192.168.2.523.1.237.91
      Sep 30, 2024 07:09:08.904692888 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.905349016 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.905385017 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.906534910 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.906613111 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.908427954 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.908535957 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.952521086 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:08.952569962 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:08.952634096 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:08.952847958 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:08.952862978 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:08.954899073 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:08.954933882 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:08.996540070 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:09.487726927 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:09.487787962 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:09.487853050 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:09.488229990 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:09.488245010 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.104784012 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.148632050 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.154776096 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.154819012 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.156703949 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.156795025 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.182996035 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.183139086 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.183187962 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.223422050 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.227643967 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.227662086 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.274441957 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.390415907 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:10.390472889 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:10.390573025 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:10.395524979 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:10.395553112 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:10.552761078 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.556251049 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.556319952 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.560601950 CEST49712443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.560623884 CEST44349712121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.645378113 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.646672964 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.646712065 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.647717953 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.647794962 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.651290894 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.651351929 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.686469078 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.686495066 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.730083942 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.993172884 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.993371010 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:10.993438959 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.993995905 CEST49713443192.168.2.5121.78.246.108
      Sep 30, 2024 07:09:10.994034052 CEST44349713121.78.246.108192.168.2.5
      Sep 30, 2024 07:09:11.056329966 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.056390047 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.060269117 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.060298920 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.060805082 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.096834898 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.143408060 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.328231096 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.328344107 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.328413010 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.328804016 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.328824997 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.328861952 CEST49714443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.328866959 CEST44349714184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.541951895 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.542010069 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:11.542152882 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.543225050 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:11.543243885 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.178719997 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.178795099 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.385420084 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.385466099 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.385778904 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.387249947 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.427414894 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.572474957 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.572557926 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.572678089 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.573607922 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.573636055 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:12.573646069 CEST49715443192.168.2.5184.28.90.27
      Sep 30, 2024 07:09:12.573652029 CEST44349715184.28.90.27192.168.2.5
      Sep 30, 2024 07:09:18.797852993 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:18.797916889 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:18.797981977 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:20.940618992 CEST49711443192.168.2.5142.250.184.196
      Sep 30, 2024 07:09:20.940650940 CEST44349711142.250.184.196192.168.2.5
      Sep 30, 2024 07:09:33.328685045 CEST5924353192.168.2.5162.159.36.2
      Sep 30, 2024 07:09:33.333647966 CEST5359243162.159.36.2192.168.2.5
      Sep 30, 2024 07:09:33.333803892 CEST5924353192.168.2.5162.159.36.2
      Sep 30, 2024 07:09:33.333803892 CEST5924353192.168.2.5162.159.36.2
      Sep 30, 2024 07:09:33.338772058 CEST5359243162.159.36.2192.168.2.5
      Sep 30, 2024 07:09:33.798265934 CEST5359243162.159.36.2192.168.2.5
      Sep 30, 2024 07:09:33.799055099 CEST5924353192.168.2.5162.159.36.2
      Sep 30, 2024 07:09:33.804351091 CEST5359243162.159.36.2192.168.2.5
      Sep 30, 2024 07:09:33.804488897 CEST5924353192.168.2.5162.159.36.2
      Sep 30, 2024 07:10:08.302777052 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:08.302817106 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:08.302891970 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:08.303771019 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:08.303785086 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:08.940888882 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:08.953787088 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:08.953804970 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:08.955276966 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:08.955733061 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:08.955895901 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:09.008379936 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:18.843422890 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:18.843508005 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:18.843590975 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:20.761332989 CEST59249443192.168.2.5142.250.186.132
      Sep 30, 2024 07:10:20.761357069 CEST44359249142.250.186.132192.168.2.5
      Sep 30, 2024 07:10:27.327802896 CEST5092253192.168.2.51.1.1.1
      Sep 30, 2024 07:10:27.332918882 CEST53509221.1.1.1192.168.2.5
      Sep 30, 2024 07:10:27.332990885 CEST5092253192.168.2.51.1.1.1
      Sep 30, 2024 07:10:27.333019018 CEST5092253192.168.2.51.1.1.1
      Sep 30, 2024 07:10:27.338238001 CEST53509221.1.1.1192.168.2.5
      Sep 30, 2024 07:10:27.964287043 CEST53509221.1.1.1192.168.2.5
      Sep 30, 2024 07:10:27.965068102 CEST5092253192.168.2.51.1.1.1
      Sep 30, 2024 07:10:27.970223904 CEST53509221.1.1.1192.168.2.5
      Sep 30, 2024 07:10:27.970346928 CEST5092253192.168.2.51.1.1.1
      TimestampSource PortDest PortSource IPDest IP
      Sep 30, 2024 07:09:04.376861095 CEST53648091.1.1.1192.168.2.5
      Sep 30, 2024 07:09:04.438967943 CEST53548501.1.1.1192.168.2.5
      Sep 30, 2024 07:09:05.436804056 CEST53540051.1.1.1192.168.2.5
      Sep 30, 2024 07:09:07.709729910 CEST5519653192.168.2.51.1.1.1
      Sep 30, 2024 07:09:07.709877014 CEST6329053192.168.2.51.1.1.1
      Sep 30, 2024 07:09:08.241728067 CEST6431553192.168.2.51.1.1.1
      Sep 30, 2024 07:09:08.242423058 CEST6145653192.168.2.51.1.1.1
      Sep 30, 2024 07:09:08.248699903 CEST53643151.1.1.1192.168.2.5
      Sep 30, 2024 07:09:08.249104023 CEST53614561.1.1.1192.168.2.5
      Sep 30, 2024 07:09:08.722531080 CEST5740953192.168.2.51.1.1.1
      Sep 30, 2024 07:09:08.723287106 CEST6232453192.168.2.51.1.1.1
      Sep 30, 2024 07:09:08.898552895 CEST53551961.1.1.1192.168.2.5
      Sep 30, 2024 07:09:08.947936058 CEST53632901.1.1.1192.168.2.5
      Sep 30, 2024 07:09:09.640495062 CEST53623241.1.1.1192.168.2.5
      Sep 30, 2024 07:09:09.958076000 CEST53574091.1.1.1192.168.2.5
      Sep 30, 2024 07:09:22.362278938 CEST53538801.1.1.1192.168.2.5
      Sep 30, 2024 07:09:33.328138113 CEST5364514162.159.36.2192.168.2.5
      Sep 30, 2024 07:09:33.939464092 CEST5649653192.168.2.51.1.1.1
      Sep 30, 2024 07:09:33.946772099 CEST53564961.1.1.1192.168.2.5
      Sep 30, 2024 07:10:08.293514013 CEST5428153192.168.2.51.1.1.1
      Sep 30, 2024 07:10:08.300065041 CEST53542811.1.1.1192.168.2.5
      Sep 30, 2024 07:10:27.327295065 CEST53629061.1.1.1192.168.2.5
      TimestampSource IPDest IPChecksumCodeType
      Sep 30, 2024 07:09:09.640568972 CEST192.168.2.51.1.1.1c217(Port unreachable)Destination Unreachable
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Sep 30, 2024 07:09:07.709729910 CEST192.168.2.51.1.1.10xc299Standard query (0)illw.krA (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:07.709877014 CEST192.168.2.51.1.1.10x34baStandard query (0)illw.kr65IN (0x0001)false
      Sep 30, 2024 07:09:08.241728067 CEST192.168.2.51.1.1.10xa4a1Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:08.242423058 CEST192.168.2.51.1.1.10xae5Standard query (0)www.google.com65IN (0x0001)false
      Sep 30, 2024 07:09:08.722531080 CEST192.168.2.51.1.1.10x47fbStandard query (0)illw.krA (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:08.723287106 CEST192.168.2.51.1.1.10xe1deStandard query (0)illw.kr65IN (0x0001)false
      Sep 30, 2024 07:09:33.939464092 CEST192.168.2.51.1.1.10xbc16Standard query (0)198.187.3.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
      Sep 30, 2024 07:10:08.293514013 CEST192.168.2.51.1.1.10xaf40Standard query (0)www.google.comA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Sep 30, 2024 07:09:08.248699903 CEST1.1.1.1192.168.2.50xa4a1No error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:08.249104023 CEST1.1.1.1192.168.2.50xae5No error (0)www.google.com65IN (0x0001)false
      Sep 30, 2024 07:09:08.898552895 CEST1.1.1.1192.168.2.50xc299No error (0)illw.kr121.78.246.108A (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:09.958076000 CEST1.1.1.1192.168.2.50x47fbNo error (0)illw.kr121.78.246.108A (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:18.602132082 CEST1.1.1.1192.168.2.50xc77No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 07:09:18.602132082 CEST1.1.1.1192.168.2.50xc77No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:32.329005003 CEST1.1.1.1192.168.2.50x77e7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 07:09:32.329005003 CEST1.1.1.1192.168.2.50x77e7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 30, 2024 07:09:33.946772099 CEST1.1.1.1192.168.2.50xbc16Name error (3)198.187.3.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
      Sep 30, 2024 07:10:08.300065041 CEST1.1.1.1192.168.2.50xaf40No error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
      • illw.kr
      • https:
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.549712121.78.246.1084433408C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-09-30 05:09:10 UTC659OUTGET /data/asdx HTTP/1.1
      Host: illw.kr
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-09-30 05:09:10 UTC226INHTTP/1.1 404 Not Found
      Date: Mon, 30 Sep 2024 05:09:10 GMT
      Server: Apache/2.4.43 (Unix) OpenSSL/1.0.2k-fips
      X-Powered-By: PHP/5.3.29
      Connection: close
      Transfer-Encoding: chunked
      Content-Type: text/html; charset=UTF-8
      2024-09-30 05:09:10 UTC207INData Raw: 63 39 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
      Data Ascii: c9<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>
      2024-09-30 05:09:10 UTC5INData Raw: 30 0d 0a 0d 0a
      Data Ascii: 0


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.549713121.78.246.1084433408C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-09-30 05:09:10 UTC579OUTGET /favicon.ico HTTP/1.1
      Host: illw.kr
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://illw.kr/data/asdx
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-09-30 05:09:10 UTC198INHTTP/1.1 404 Not Found
      Date: Mon, 30 Sep 2024 05:09:10 GMT
      Server: Apache/2.4.43 (Unix) OpenSSL/1.0.2k-fips
      Content-Length: 196
      Connection: close
      Content-Type: text/html; charset=iso-8859-1
      2024-09-30 05:09:10 UTC196INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
      Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.549714184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-30 05:09:11 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-30 05:09:11 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF67)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-neu-z1
      Cache-Control: public, max-age=41751
      Date: Mon, 30 Sep 2024 05:09:11 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.549715184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-30 05:09:12 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-30 05:09:12 UTC514INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=41780
      Date: Mon, 30 Sep 2024 05:09:12 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-09-30 05:09:12 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:08:59
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:01:09:02
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,9542992241968095067,5864178729948817110,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:01:09:06
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://illw.kr/data/asdx"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly