Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://track.starmobmedia.com/

Overview

General Information

Sample URL:http://track.starmobmedia.com/
Analysis ID:1538315
Tags:urlscan
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1936,i,2268817473929801565,4664180868766387776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://track.starmobmedia.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: track.starmobmedia.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: track.starmobmedia.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1936,i,2268817473929801565,4664180868766387776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://track.starmobmedia.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1936,i,2268817473929801565,4664180868766387776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
track.starmobmedia.com
23.111.151.106
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      142.250.185.132
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://track.starmobmedia.com/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            23.111.151.106
            track.starmobmedia.comUnited States
            29802HVC-ASUSfalse
            142.250.185.132
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1538315
            Start date and time:2024-10-21 00:19:29 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 58s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://track.starmobmedia.com/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.185.238, 64.233.184.84, 20.12.23.50, 199.232.210.172, 192.229.221.95, 40.69.42.241
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://track.starmobmedia.com/
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 21, 2024 00:20:28.051156998 CEST4973580192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.051280022 CEST4973680192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.057235003 CEST804973523.111.151.106192.168.2.4
            Oct 21, 2024 00:20:28.057252884 CEST804973623.111.151.106192.168.2.4
            Oct 21, 2024 00:20:28.057322025 CEST4973580192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.057486057 CEST4973680192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.057486057 CEST4973680192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.063908100 CEST804973623.111.151.106192.168.2.4
            Oct 21, 2024 00:20:28.926825047 CEST804973623.111.151.106192.168.2.4
            Oct 21, 2024 00:20:28.926902056 CEST4973680192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.927290916 CEST4973680192.168.2.423.111.151.106
            Oct 21, 2024 00:20:28.932071924 CEST804973623.111.151.106192.168.2.4
            Oct 21, 2024 00:20:29.961622000 CEST4974180192.168.2.423.111.151.106
            Oct 21, 2024 00:20:29.968447924 CEST804974123.111.151.106192.168.2.4
            Oct 21, 2024 00:20:29.968535900 CEST4974180192.168.2.423.111.151.106
            Oct 21, 2024 00:20:29.970199108 CEST4973580192.168.2.423.111.151.106
            Oct 21, 2024 00:20:29.976908922 CEST804973523.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.103852987 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:30.103909016 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:30.103977919 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:30.104204893 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:30.104218006 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:30.186889887 CEST804973523.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.186976910 CEST4973580192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.187086105 CEST4973580192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.187396049 CEST4974180192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.195692062 CEST804973523.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.195704937 CEST804974123.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.841542006 CEST804974123.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.841639042 CEST4974180192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.841722965 CEST4974180192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.842183113 CEST4974380192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.848915100 CEST804974123.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.849931955 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:30.849972010 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:30.850049973 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:30.850644112 CEST804974323.111.151.106192.168.2.4
            Oct 21, 2024 00:20:30.850738049 CEST4974380192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.850893974 CEST4974380192.168.2.423.111.151.106
            Oct 21, 2024 00:20:30.852132082 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:30.852153063 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:30.858150005 CEST804974323.111.151.106192.168.2.4
            Oct 21, 2024 00:20:31.186681986 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:31.187201977 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:31.187242031 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:31.188332081 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:31.188410997 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:31.189579964 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:31.189661026 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:31.231467962 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:31.231509924 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:31.279772043 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:31.714059114 CEST804974323.111.151.106192.168.2.4
            Oct 21, 2024 00:20:31.714118958 CEST4974380192.168.2.423.111.151.106
            Oct 21, 2024 00:20:31.741925955 CEST4974380192.168.2.423.111.151.106
            Oct 21, 2024 00:20:31.748886108 CEST804974323.111.151.106192.168.2.4
            Oct 21, 2024 00:20:31.908608913 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:31.908710003 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:31.954529047 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:31.954560995 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:31.954853058 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:31.997100115 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.155924082 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.203392982 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.455734968 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.455794096 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.455842018 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.455916882 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.455936909 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.455950975 CEST49744443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.455956936 CEST44349744184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.518424034 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.518452883 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:32.518523932 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.518851042 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:32.518857956 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.115808010 CEST4974780192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.115961075 CEST4974880192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.122965097 CEST804974723.111.151.106192.168.2.4
            Oct 21, 2024 00:20:33.125021935 CEST804974823.111.151.106192.168.2.4
            Oct 21, 2024 00:20:33.125073910 CEST4974780192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.125097990 CEST4974880192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.125299931 CEST4974780192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.132333994 CEST804974723.111.151.106192.168.2.4
            Oct 21, 2024 00:20:33.576090097 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.576235056 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.577564001 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.577580929 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.577894926 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.582003117 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.627403975 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.882930040 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.883774996 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:33.883968115 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.883968115 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.883968115 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:33.986393929 CEST804974723.111.151.106192.168.2.4
            Oct 21, 2024 00:20:33.986485004 CEST4974780192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.986802101 CEST4974780192.168.2.423.111.151.106
            Oct 21, 2024 00:20:33.991724014 CEST804974723.111.151.106192.168.2.4
            Oct 21, 2024 00:20:34.199151993 CEST49746443192.168.2.4184.28.90.27
            Oct 21, 2024 00:20:34.199196100 CEST44349746184.28.90.27192.168.2.4
            Oct 21, 2024 00:20:38.576231003 CEST49672443192.168.2.4173.222.162.32
            Oct 21, 2024 00:20:38.576267004 CEST44349672173.222.162.32192.168.2.4
            Oct 21, 2024 00:20:39.325344086 CEST4975080192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.330384970 CEST804975023.111.151.106192.168.2.4
            Oct 21, 2024 00:20:39.330498934 CEST4975080192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.365787029 CEST4974880192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.370663881 CEST804974823.111.151.106192.168.2.4
            Oct 21, 2024 00:20:39.579332113 CEST804974823.111.151.106192.168.2.4
            Oct 21, 2024 00:20:39.579478025 CEST4974880192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.579590082 CEST4974880192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.580296993 CEST4975080192.168.2.423.111.151.106
            Oct 21, 2024 00:20:39.584389925 CEST804974823.111.151.106192.168.2.4
            Oct 21, 2024 00:20:39.585165024 CEST804975023.111.151.106192.168.2.4
            Oct 21, 2024 00:20:40.200059891 CEST804975023.111.151.106192.168.2.4
            Oct 21, 2024 00:20:40.200170040 CEST4975080192.168.2.423.111.151.106
            Oct 21, 2024 00:20:40.200315952 CEST4975080192.168.2.423.111.151.106
            Oct 21, 2024 00:20:40.200891972 CEST4975280192.168.2.423.111.151.106
            Oct 21, 2024 00:20:40.205056906 CEST804975023.111.151.106192.168.2.4
            Oct 21, 2024 00:20:40.205734015 CEST804975223.111.151.106192.168.2.4
            Oct 21, 2024 00:20:40.205986023 CEST4975280192.168.2.423.111.151.106
            Oct 21, 2024 00:20:40.206167936 CEST4975280192.168.2.423.111.151.106
            Oct 21, 2024 00:20:40.210948944 CEST804975223.111.151.106192.168.2.4
            Oct 21, 2024 00:20:41.075867891 CEST804975223.111.151.106192.168.2.4
            Oct 21, 2024 00:20:41.075957060 CEST4975280192.168.2.423.111.151.106
            Oct 21, 2024 00:20:41.076380014 CEST4975280192.168.2.423.111.151.106
            Oct 21, 2024 00:20:41.081244946 CEST804975223.111.151.106192.168.2.4
            Oct 21, 2024 00:20:41.190886974 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:41.190962076 CEST44349742142.250.185.132192.168.2.4
            Oct 21, 2024 00:20:41.191205978 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:42.400708914 CEST4972380192.168.2.4199.232.214.172
            Oct 21, 2024 00:20:42.405980110 CEST8049723199.232.214.172192.168.2.4
            Oct 21, 2024 00:20:42.406104088 CEST4972380192.168.2.4199.232.214.172
            Oct 21, 2024 00:20:42.544936895 CEST49742443192.168.2.4142.250.185.132
            Oct 21, 2024 00:20:42.544958115 CEST44349742142.250.185.132192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 21, 2024 00:20:26.255359888 CEST53526641.1.1.1192.168.2.4
            Oct 21, 2024 00:20:26.266463041 CEST53550951.1.1.1192.168.2.4
            Oct 21, 2024 00:20:28.035470963 CEST6133753192.168.2.41.1.1.1
            Oct 21, 2024 00:20:28.036959887 CEST5574553192.168.2.41.1.1.1
            Oct 21, 2024 00:20:28.043787003 CEST53613371.1.1.1192.168.2.4
            Oct 21, 2024 00:20:28.289565086 CEST53557451.1.1.1192.168.2.4
            Oct 21, 2024 00:20:30.092155933 CEST6409353192.168.2.41.1.1.1
            Oct 21, 2024 00:20:30.092499971 CEST6285753192.168.2.41.1.1.1
            Oct 21, 2024 00:20:30.100786924 CEST53640931.1.1.1192.168.2.4
            Oct 21, 2024 00:20:30.102890968 CEST53628571.1.1.1192.168.2.4
            Oct 21, 2024 00:20:42.361905098 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPChecksumCodeType
            Oct 21, 2024 00:20:28.289652109 CEST192.168.2.41.1.1.1c227(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 21, 2024 00:20:28.035470963 CEST192.168.2.41.1.1.10xa62bStandard query (0)track.starmobmedia.comA (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:28.036959887 CEST192.168.2.41.1.1.10xfae4Standard query (0)track.starmobmedia.com65IN (0x0001)false
            Oct 21, 2024 00:20:30.092155933 CEST192.168.2.41.1.1.10x673dStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:30.092499971 CEST192.168.2.41.1.1.10xa287Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 21, 2024 00:20:28.043787003 CEST1.1.1.1192.168.2.40xa62bNo error (0)track.starmobmedia.com23.111.151.106A (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:30.100786924 CEST1.1.1.1192.168.2.40x673dNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:30.102890968 CEST1.1.1.1192.168.2.40xa287No error (0)www.google.com65IN (0x0001)false
            Oct 21, 2024 00:20:40.862381935 CEST1.1.1.1192.168.2.40x9555No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:40.862381935 CEST1.1.1.1192.168.2.40x9555No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 21, 2024 00:20:43.031450987 CEST1.1.1.1192.168.2.40xaff5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 21, 2024 00:20:43.031450987 CEST1.1.1.1192.168.2.40xaff5No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • track.starmobmedia.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44973623.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:28.057486057 CEST437OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973523.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:29.970199108 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974123.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:30.187396049 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974323.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:30.850893974 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.44974723.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:33.125299931 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.44974823.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:39.365787029 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.44975023.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:39.580296993 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            7192.168.2.44975223.111.151.106804420C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 21, 2024 00:20:40.206167936 CEST463OUTGET / HTTP/1.1
            Host: track.starmobmedia.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449744184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-20 22:20:32 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-20 22:20:32 UTC466INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF70)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=66264
            Date: Sun, 20 Oct 2024 22:20:32 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449746184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-20 22:20:33 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-20 22:20:33 UTC514INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=66310
            Date: Sun, 20 Oct 2024 22:20:33 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-20 22:20:33 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:18:20:21
            Start date:20/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:18:20:24
            Start date:20/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1936,i,2268817473929801565,4664180868766387776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:18:20:27
            Start date:20/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://track.starmobmedia.com/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly