Windows Analysis Report
http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiI

Overview

General Information

Sample URL: http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqale
Analysis ID: 1525193
Infos:
Errors
  • URL not reachable

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Detected non-DNS traffic on DNS port

Classification

Source: chrome.exe Memory has grown: Private usage: 1MB later: 36MB
Source: global traffic TCP traffic: 192.168.2.4:49730 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.4:60210 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 40terrastaffinggroup.com
Source: global traffic DNS traffic detected: DNS query: google.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engine Classification label: unknown0.win@19/0@14/3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9IiwibmJmIjoxNzI3NzM4OTI3LCJleHAiOjE3Mjc3MzkyMjcsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJoYXBwIjoib3dhIn0.DDCiPDY1j1uNmVpBJdSsAokX770OONzh8rv5z3s3gS-I-LsZMYCozhUrKhO2nQu85lawIrkoCL0RO8eT_rPCoQ3V2_5tTd-ECtyx_m8GRUsYCdWK0T-Az3fT7NIZIgikR3QFZXLLU0TVXK_M7DYsIECpjB4cA2rzUxYWUq20Y-DuKKf2BUUhaEjjqr8eB76_2oGXY1Xmli7920rKxpnH3vI8dTEDOqiSzre4gptAP6UcYoEXVHYMSRG7sdJXbXzw95rp1YaDecWGC5eRukjrW0UJC_PIguBm8pVd8uCcTUweRTH6CJ1725v0e5iFYzPPnTtLozIN7b7d1ZFnZQJ6ww&X-OWA-CANARY=bdvoV2GyMV8AAAAAAAAAAPDZi7in4dwYPpU5wYHasUhFap6Og7aDZ8VkPg5v52xCxWVdx1uX1GI.&owa=outlook.office.com&scriptVer=20240920004.10&clientId=03F5E497FBFD4312A9E577D9C247289D&animation=true"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs