Windows Analysis Report
https://ferrumzks.powerappsportals.com/

Overview

General Information

Sample URL: https://ferrumzks.powerappsportals.com/
Analysis ID: 1543755

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
Stores files to the Windows start menu directory

Classification

Source: https://ferrumzks.byrnemooredocumentattached.sbs/ HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" fill="none"><path fill="#B20F03" d="M16 3a13 13 0 1 0 13 13A13.015 13.015 0 0 0 16 3m0 24a11 11 0 1 1 11-11 11.01 11.01 0 0 1-11 11"/><path fill="#B20F03" d="M17.038 18.615H14.87L14.563 9.5h2....
Source: https://ferrumzks.powerappsportals.com/ HTTP Parser: No favicon
Source: https://ferrumzks.powerappsportals.com/ HTTP Parser: No favicon
Source: https://ferrumzks.byrnemooredocumentattached.sbs/ HTTP Parser: No favicon
Source: https://ferrumzks.byrnemooredocumentattached.sbs/ HTTP Parser: No favicon
Source: https://ferrumzks.byrnemooredocumentattached.sbs/ HTTP Parser: No favicon
Source: https://ferrumzks.byrnemooredocumentattached.sbs/cgi-sys/defaultwebpage.cgi HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:57936 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:58050 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:57927 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: ferrumzks.powerappsportals.com
Source: global traffic DNS traffic detected: DNS query: content.powerapps.com
Source: global traffic DNS traffic detected: DNS query: png.pngtree.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: ferrumzks.byrnemooredocumentattached.sbs
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: unknown Network traffic detected: HTTP traffic on port 58054 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 58031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57929
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57928
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57943 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57989 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57937 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 58060 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 57931 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57937
Source: unknown Network traffic detected: HTTP traffic on port 57977 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57939
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57934
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57933
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57936
Source: unknown Network traffic detected: HTTP traffic on port 58013 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58059 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57930
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57932
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57931
Source: unknown Network traffic detected: HTTP traffic on port 58065 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57995 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58048 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 58002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 57932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57949
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57948
Source: unknown Network traffic detected: HTTP traffic on port 57984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57945
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57946
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57941
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57940
Source: unknown Network traffic detected: HTTP traffic on port 58014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57943
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57942
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58003
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58002
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57950
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58005
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58004
Source: unknown Network traffic detected: HTTP traffic on port 58020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57990 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58001
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58000
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 58047 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 57954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 57948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58036 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57955
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58007
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57951
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58006
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58009
Source: unknown Network traffic detected: HTTP traffic on port 58053 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57953
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58008
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58014
Source: unknown Network traffic detected: HTTP traffic on port 58042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58013
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57961
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58015
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58010
Source: unknown Network traffic detected: HTTP traffic on port 57965 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58012
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58011
Source: unknown Network traffic detected: HTTP traffic on port 58008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58025 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49702
Source: unknown Network traffic detected: HTTP traffic on port 58029 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57982 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57999 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58058 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58035 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57950 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58030 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57955 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57949 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57961 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58052 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57994 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58001 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58007 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 57933 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 57983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 58046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58063 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 57928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58039 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58068
Source: unknown Network traffic detected: HTTP traffic on port 58068 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58065
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58067
Source: unknown Network traffic detected: HTTP traffic on port 57992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58061
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58060
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58063
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58045 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58022 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 57952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57981 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57998 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58034 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58051 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57963 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58027 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57974 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57939 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57945 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57987 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57968 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58028 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58005 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57979 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57962 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58067 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57993 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58000 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57951 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57930 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57953 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57969
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57968
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57963
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58018
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57962
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58017
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57965
Source: unknown Network traffic detected: HTTP traffic on port 58050 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58019
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57970
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58025
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58024
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57972
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58027
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58026
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58021
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58020
Source: unknown Network traffic detected: HTTP traffic on port 57947 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58023
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58022
Source: unknown Network traffic detected: HTTP traffic on port 57985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58049 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58009 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58055 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58003 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57978
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57977
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57979
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57974
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58029
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57973
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58028
Source: unknown Network traffic detected: HTTP traffic on port 58038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57975
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57981
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58036
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57980
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58035
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57983
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58038
Source: unknown Network traffic detected: HTTP traffic on port 57942 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57982
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58037
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58032
Source: unknown Network traffic detected: HTTP traffic on port 57970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58031
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58034
Source: unknown Network traffic detected: HTTP traffic on port 57991 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58033
Source: unknown Network traffic detected: HTTP traffic on port 57936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58061 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58030
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58044 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57980 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57989
Source: unknown Network traffic detected: HTTP traffic on port 57997 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57988
Source: unknown Network traffic detected: HTTP traffic on port 58010 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58039
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57987
Source: unknown Network traffic detected: HTTP traffic on port 58037 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57986
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57992
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58047
Source: unknown Network traffic detected: HTTP traffic on port 58066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57991
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58046
Source: unknown Network traffic detected: HTTP traffic on port 57941 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57994
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58049
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57993
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58048
Source: unknown Network traffic detected: HTTP traffic on port 57964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58043
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57990
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58045
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58044
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58041
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58040
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57975 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57999
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57995
Source: unknown Network traffic detected: HTTP traffic on port 58015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57998
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57997
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58058
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58057
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58059
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58054
Source: unknown Network traffic detected: HTTP traffic on port 57969 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58053
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58055
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58050
Source: unknown Network traffic detected: HTTP traffic on port 57986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58052
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58051
Source: unknown Network traffic detected: HTTP traffic on port 58021 -> 443
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:57936 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:58050 version: TLS 1.2
Source: classification engine Classification label: clean1.win@27/55@28/239
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2000,i,2434418462478297649,10155466664715211141,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ferrumzks.powerappsportals.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2000,i,2434418462478297649,10155466664715211141,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs