Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://search.braraildye.live

Overview

General Information

Sample URL:http://search.braraildye.live
Analysis ID:1533028
Infos:
Errors
  • URL not reachable

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5216 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2252,i,3519808327175707570,4964838227932449651,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6300 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://search.braraildye.live" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: search.braraildye.liveVirustotal: Detection: 8%Perma Link
Source: http://search.braraildye.liveVirustotal: Detection: 8%Perma Link
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: search.braraildye.live
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal56.win@20/0@25/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2252,i,3519808327175707570,4964838227932449651,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://search.braraildye.live"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2252,i,3519808327175707570,4964838227932449651,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://search.braraildye.live8%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
www.google.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
search.braraildye.live8%VirustotalBrowse
google.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
google.com
142.250.186.110
truefalseunknown
www.google.com
142.250.186.68
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
search.braraildye.live
unknown
unknownfalseunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
142.250.186.68
www.google.comUnited States
15169GOOGLEUSfalse
239.255.255.250
unknownReserved
unknownunknownfalse
IP
192.168.2.4
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1533028
Start date and time:2024-10-14 10:43:49 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:browseurl.jbs
Sample URL:http://search.braraildye.live
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:MAL
Classification:mal56.win@20/0@25/3
Cookbook Comments:
  • URL browsing timeout or error
  • URL not reachable
  • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 142.250.184.227, 64.233.167.84, 142.250.181.238, 34.104.35.123, 20.109.210.53, 199.232.210.172, 192.229.221.95, 13.85.23.206
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtSetInformationFile calls found.
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
No static file info
TimestampSource PortDest PortSource IPDest IP
Oct 14, 2024 10:44:35.654990911 CEST49675443192.168.2.4173.222.162.32
Oct 14, 2024 10:44:45.316643953 CEST49675443192.168.2.4173.222.162.32
Oct 14, 2024 10:44:48.428484917 CEST49739443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.428508997 CEST44349739142.250.186.68192.168.2.4
Oct 14, 2024 10:44:48.428565025 CEST49739443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.428809881 CEST49739443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.428823948 CEST44349739142.250.186.68192.168.2.4
Oct 14, 2024 10:44:48.439728975 CEST44349739142.250.186.68192.168.2.4
Oct 14, 2024 10:44:48.440102100 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.440152884 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:48.440224886 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.440490007 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:48.440526009 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.113164902 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.113614082 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:49.113676071 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.115329981 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.115413904 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:49.116358042 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:49.116456985 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.169945002 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:49.170005083 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:49.216833115 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:49.759136915 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:49.759227991 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:49.759351015 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:49.790129900 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:49.790173054 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.544159889 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.544250011 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.548880100 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.548907042 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.549424887 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.592314959 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.598752975 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.639419079 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.881825924 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.881963968 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.882045031 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.882096052 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.882142067 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.882172108 CEST49741443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.882190943 CEST44349741184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.926040888 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.926079988 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:50.926187038 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.926600933 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:50.926628113 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.636919022 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.637180090 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.638997078 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.639020920 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.639554977 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.640856028 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.687407970 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.973005056 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.973164082 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.973436117 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.974344969 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.974344969 CEST49742443192.168.2.4184.28.90.27
Oct 14, 2024 10:44:51.974389076 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:51.974411964 CEST44349742184.28.90.27192.168.2.4
Oct 14, 2024 10:44:59.029232979 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:59.029371977 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:44:59.029567003 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:59.375381947 CEST49740443192.168.2.4142.250.186.68
Oct 14, 2024 10:44:59.375464916 CEST44349740142.250.186.68192.168.2.4
Oct 14, 2024 10:45:01.351600885 CEST4972380192.168.2.4199.232.214.172
Oct 14, 2024 10:45:01.357345104 CEST8049723199.232.214.172192.168.2.4
Oct 14, 2024 10:45:01.357400894 CEST4972380192.168.2.4199.232.214.172
TimestampSource PortDest PortSource IPDest IP
Oct 14, 2024 10:44:45.241291046 CEST53595601.1.1.1192.168.2.4
Oct 14, 2024 10:44:45.256077051 CEST53653311.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.256741047 CEST53629451.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.322005033 CEST6445153192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.322422981 CEST5622953192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.334094048 CEST53644511.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.334602118 CEST5929453192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.335927010 CEST53562291.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.336286068 CEST5535053192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.353235006 CEST53592941.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.353921890 CEST5367453192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.367417097 CEST53536741.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.375109911 CEST53553501.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.430389881 CEST5048353192.168.2.48.8.8.8
Oct 14, 2024 10:44:46.430780888 CEST5598853192.168.2.41.1.1.1
Oct 14, 2024 10:44:46.437475920 CEST53559881.1.1.1192.168.2.4
Oct 14, 2024 10:44:46.438858986 CEST53504838.8.8.8192.168.2.4
Oct 14, 2024 10:44:47.558757067 CEST5460253192.168.2.41.1.1.1
Oct 14, 2024 10:44:47.558979034 CEST5888853192.168.2.41.1.1.1
Oct 14, 2024 10:44:48.040630102 CEST53546021.1.1.1192.168.2.4
Oct 14, 2024 10:44:48.041157961 CEST6069253192.168.2.41.1.1.1
Oct 14, 2024 10:44:48.041318893 CEST53588881.1.1.1192.168.2.4
Oct 14, 2024 10:44:48.041565895 CEST5141453192.168.2.41.1.1.1
Oct 14, 2024 10:44:48.051249981 CEST53514141.1.1.1192.168.2.4
Oct 14, 2024 10:44:48.056579113 CEST53606921.1.1.1192.168.2.4
Oct 14, 2024 10:44:48.294567108 CEST5151153192.168.2.41.1.1.1
Oct 14, 2024 10:44:48.295099020 CEST5167853192.168.2.41.1.1.1
Oct 14, 2024 10:44:48.427570105 CEST53515111.1.1.1192.168.2.4
Oct 14, 2024 10:44:48.427752018 CEST53516781.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.431415081 CEST5156553192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.431598902 CEST6516153192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.444996119 CEST53651611.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.445907116 CEST5966053192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.446086884 CEST53515651.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.446441889 CEST5154053192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.453695059 CEST53515401.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.458400011 CEST5206453192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.458975077 CEST53596601.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.471533060 CEST53520641.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.487941980 CEST5389653192.168.2.41.1.1.1
Oct 14, 2024 10:44:51.488231897 CEST6112953192.168.2.48.8.8.8
Oct 14, 2024 10:44:51.494864941 CEST53538961.1.1.1192.168.2.4
Oct 14, 2024 10:44:51.495544910 CEST53611298.8.8.8192.168.2.4
Oct 14, 2024 10:44:57.177453041 CEST5635253192.168.2.41.1.1.1
Oct 14, 2024 10:44:57.177692890 CEST6496853192.168.2.41.1.1.1
Oct 14, 2024 10:44:57.189990997 CEST53649681.1.1.1192.168.2.4
Oct 14, 2024 10:44:57.191369057 CEST53563521.1.1.1192.168.2.4
Oct 14, 2024 10:44:57.198808908 CEST5650153192.168.2.41.1.1.1
Oct 14, 2024 10:44:57.199136972 CEST5764953192.168.2.41.1.1.1
Oct 14, 2024 10:44:57.209214926 CEST53565011.1.1.1192.168.2.4
Oct 14, 2024 10:44:57.209286928 CEST53576491.1.1.1192.168.2.4
Oct 14, 2024 10:44:57.215666056 CEST5793653192.168.2.41.1.1.1
Oct 14, 2024 10:44:57.226711988 CEST53579361.1.1.1192.168.2.4
Oct 14, 2024 10:45:02.150037050 CEST138138192.168.2.4192.168.2.255
Oct 14, 2024 10:45:03.413012028 CEST53649591.1.1.1192.168.2.4
TimestampSource IPDest IPChecksumCodeType
Oct 14, 2024 10:44:46.375188112 CEST192.168.2.41.1.1.1c1ec(Port unreachable)Destination Unreachable
Oct 14, 2024 10:44:51.459110975 CEST192.168.2.41.1.1.1c1ec(Port unreachable)Destination Unreachable
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Oct 14, 2024 10:44:46.322005033 CEST192.168.2.41.1.1.10xc3b5Standard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.322422981 CEST192.168.2.41.1.1.10x4b24Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:46.334602118 CEST192.168.2.41.1.1.10x7a5cStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.336286068 CEST192.168.2.41.1.1.10xd017Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:46.353921890 CEST192.168.2.41.1.1.10xb892Standard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.430389881 CEST192.168.2.48.8.8.80xabbfStandard query (0)google.comA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.430780888 CEST192.168.2.41.1.1.10x9fa6Standard query (0)google.comA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:47.558757067 CEST192.168.2.41.1.1.10xc0cdStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:47.558979034 CEST192.168.2.41.1.1.10xafd3Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:48.041157961 CEST192.168.2.41.1.1.10x5db8Standard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.041565895 CEST192.168.2.41.1.1.10x6845Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:48.294567108 CEST192.168.2.41.1.1.10x41a1Standard query (0)www.google.comA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.295099020 CEST192.168.2.41.1.1.10x3049Standard query (0)www.google.com65IN (0x0001)false
Oct 14, 2024 10:44:51.431415081 CEST192.168.2.41.1.1.10xe3a9Standard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.431598902 CEST192.168.2.41.1.1.10x9e34Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:51.445907116 CEST192.168.2.41.1.1.10x3a9Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:51.446441889 CEST192.168.2.41.1.1.10x79cStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.458400011 CEST192.168.2.41.1.1.10x6beeStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.487941980 CEST192.168.2.41.1.1.10x1a26Standard query (0)google.comA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.488231897 CEST192.168.2.48.8.8.80x4812Standard query (0)google.comA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.177453041 CEST192.168.2.41.1.1.10x1cafStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.177692890 CEST192.168.2.41.1.1.10xfbb4Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:57.198808908 CEST192.168.2.41.1.1.10xc11fStandard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.199136972 CEST192.168.2.41.1.1.10x74a0Standard query (0)search.braraildye.live65IN (0x0001)false
Oct 14, 2024 10:44:57.215666056 CEST192.168.2.41.1.1.10xa8e5Standard query (0)search.braraildye.liveA (IP address)IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Oct 14, 2024 10:44:46.334094048 CEST1.1.1.1192.168.2.40xc3b5Server failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.335927010 CEST1.1.1.1192.168.2.40x4b24Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:46.353235006 CEST1.1.1.1192.168.2.40x7a5cServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.367417097 CEST1.1.1.1192.168.2.40xb892Server failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.375109911 CEST1.1.1.1192.168.2.40xd017Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:46.437475920 CEST1.1.1.1192.168.2.40x9fa6No error (0)google.com142.250.186.110A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:46.438858986 CEST8.8.8.8192.168.2.40xabbfNo error (0)google.com142.250.185.174A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.040630102 CEST1.1.1.1192.168.2.40xc0cdServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.041318893 CEST1.1.1.1192.168.2.40xafd3Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:48.051249981 CEST1.1.1.1192.168.2.40x6845Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:48.056579113 CEST1.1.1.1192.168.2.40x5db8Server failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.427570105 CEST1.1.1.1192.168.2.40x41a1No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:48.427752018 CEST1.1.1.1192.168.2.40x3049No error (0)www.google.com65IN (0x0001)false
Oct 14, 2024 10:44:51.444996119 CEST1.1.1.1192.168.2.40x9e34Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:51.446086884 CEST1.1.1.1192.168.2.40xe3a9Server failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.453695059 CEST1.1.1.1192.168.2.40x79cServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.458975077 CEST1.1.1.1192.168.2.40x3a9Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:51.471533060 CEST1.1.1.1192.168.2.40x6beeServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.494864941 CEST1.1.1.1192.168.2.40x1a26No error (0)google.com216.58.206.46A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:51.495544910 CEST8.8.8.8192.168.2.40x4812No error (0)google.com142.250.185.174A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.189990997 CEST1.1.1.1192.168.2.40xfbb4Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:57.191369057 CEST1.1.1.1192.168.2.40x1cafServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.209214926 CEST1.1.1.1192.168.2.40xc11fServer failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:57.209286928 CEST1.1.1.1192.168.2.40x74a0Server failure (2)search.braraildye.livenonenone65IN (0x0001)false
Oct 14, 2024 10:44:57.226711988 CEST1.1.1.1192.168.2.40xa8e5Server failure (2)search.braraildye.livenonenoneA (IP address)IN (0x0001)false
Oct 14, 2024 10:44:58.861943960 CEST1.1.1.1192.168.2.40x1461No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
Oct 14, 2024 10:44:58.861943960 CEST1.1.1.1192.168.2.40x1461No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
Oct 14, 2024 10:45:00.272232056 CEST1.1.1.1192.168.2.40x5eddNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
Oct 14, 2024 10:45:00.272232056 CEST1.1.1.1192.168.2.40x5eddNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
  • fs.microsoft.com
Session IDSource IPSource PortDestination IPDestination PortPIDProcess
0192.168.2.449741184.28.90.27443
TimestampBytes transferredDirectionData
2024-10-14 08:44:50 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.8
Host: fs.microsoft.com
2024-10-14 08:44:50 UTC467INHTTP/1.1 200 OK
Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
Content-Type: application/octet-stream
ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
Last-Modified: Tue, 16 May 2017 22:58:00 GMT
Server: ECAcc (lpl/EF70)
X-CID: 11
X-Ms-ApiVersion: Distribute 1.2
X-Ms-Region: prod-neu-z1
Cache-Control: public, max-age=115245
Date: Mon, 14 Oct 2024 08:44:50 GMT
Connection: close
X-CID: 2


Session IDSource IPSource PortDestination IPDestination PortPIDProcess
1192.168.2.449742184.28.90.27443
TimestampBytes transferredDirectionData
2024-10-14 08:44:51 UTC239OUTGET /fs/windows/config.json HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
Range: bytes=0-2147483646
User-Agent: Microsoft BITS/7.8
Host: fs.microsoft.com
2024-10-14 08:44:51 UTC515INHTTP/1.1 200 OK
ApiVersion: Distribute 1.1
Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
Content-Type: application/octet-stream
ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
Last-Modified: Tue, 16 May 2017 22:58:00 GMT
Server: ECAcc (lpl/EF06)
X-CID: 11
X-Ms-ApiVersion: Distribute 1.2
X-Ms-Region: prod-weu-z1
Cache-Control: public, max-age=115185
Date: Mon, 14 Oct 2024 08:44:51 GMT
Content-Length: 55
Connection: close
X-CID: 2
2024-10-14 08:44:51 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:04:44:40
Start date:14/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:04:44:43
Start date:14/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2252,i,3519808327175707570,4964838227932449651,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:3
Start time:04:44:45
Start date:14/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://search.braraildye.live"
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly