Windows Analysis Report
http://azurecr.io

Overview

General Information

Sample URL: http://azurecr.io
Analysis ID: 1544126

Detection

Score: 21
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

AI detected landing page (webpage, office document or email)
Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

Source: https://www.google.com/search?q=azure+cr&oq=azure+cr+&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIJCAEQABgKGIAEMgkIAhAAGAoYgAQyCQgDEAAYChiABDIJCAQQABgKGIAEMgYIBRBFGDwyBggGEEUYPDIGCAcQRRg80gEINjUzM2owajeoAgCwAgA&sourceid=chrome&ie=UTF-8 HTTP Parser: No favicon
Source: https://www.google.com/search?q=azure+cr&oq=azure+cr+&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIJCAEQABgKGIAEMgkIAhAAGAoYgAQyCQgDEAAYChiABDIJCAQQABgKGIAEMgYIBRBFGDwyBggGEEUYPDIGCAcQRRg80gEINjUzM2owajeoAgCwAgA&sourceid=chrome&ie=UTF-8 HTTP Parser: No favicon
Source: https://www.google.com/search?q=azure+cr&oq=azure+cr+&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIJCAEQABgKGIAEMgkIAhAAGAoYgAQyCQgDEAAYChiABDIJCAQQABgKGIAEMgYIBRBFGDwyBggGEEUYPDIGCAcQRRg80gEINjUzM2owajeoAgCwAgA&sourceid=chrome&ie=UTF-8 HTTP Parser: No favicon
Source: https://www.google.com/search?q=azure+cr&oq=azure+cr+&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIJCAEQABgKGIAEMgkIAhAAGAoYgAQyCQgDEAAYChiABDIJCAQQABgKGIAEMgYIBRBFGDwyBggGEEUYPDIGCAcQRRg80gEINjUzM2owajeoAgCwAgA&sourceid=chrome&ie=UTF-8 HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:53896 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:53898 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:53899 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:53969 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53894 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: azurecr.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: azurecr.io
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: apis.google.com
Source: global traffic DNS traffic detected: DNS query: play.google.com
Source: global traffic DNS traffic detected: DNS query: dns-tunnel-check.googlezip.net
Source: global traffic DNS traffic detected: DNS query: tunnel.googlezip.net
Source: global traffic DNS traffic detected: DNS query: id.google.com
Source: global traffic DNS traffic detected: DNS query: mdec.nelreports.net
Source: global traffic DNS traffic detected: DNS query: s.go-mpulse.net
Source: global traffic DNS traffic detected: DNS query: c.go-mpulse.net
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53969
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53966
Source: unknown Network traffic detected: HTTP traffic on port 53973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53961
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54015
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54014
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54013
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53965
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54019
Source: unknown Network traffic detected: HTTP traffic on port 53921 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53963
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54018
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53962
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54017
Source: unknown Network traffic detected: HTTP traffic on port 54032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53896 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54023
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54022
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54021
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54020
Source: unknown Network traffic detected: HTTP traffic on port 53976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54029 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53979
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53978
Source: unknown Network traffic detected: HTTP traffic on port 54023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53977
Source: unknown Network traffic detected: HTTP traffic on port 53993 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53972
Source: unknown Network traffic detected: HTTP traffic on port 54015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54027
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54026
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53970
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54025
Source: unknown Network traffic detected: HTTP traffic on port 53962 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53975
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54029
Source: unknown Network traffic detected: HTTP traffic on port 53924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53973
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54028
Source: unknown Network traffic detected: HTTP traffic on port 53899 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54030
Source: unknown Network traffic detected: HTTP traffic on port 53935 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53956 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54034
Source: unknown Network traffic detected: HTTP traffic on port 54012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54033
Source: unknown Network traffic detected: HTTP traffic on port 53987 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54032
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54031
Source: unknown Network traffic detected: HTTP traffic on port 54026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53989
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53988
Source: unknown Network traffic detected: HTTP traffic on port 53998 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53969 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53983
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54038
Source: unknown Network traffic detected: HTTP traffic on port 53927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54037
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54036
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54035
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53987
Source: unknown Network traffic detected: HTTP traffic on port 54018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53961 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54041
Source: unknown Network traffic detected: HTTP traffic on port 53984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54040
Source: unknown Network traffic detected: HTTP traffic on port 53898 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54030 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54027 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53913 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53914
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53913
Source: unknown Network traffic detected: HTTP traffic on port 54021 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53912
Source: unknown Network traffic detected: HTTP traffic on port 53970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53999
Source: unknown Network traffic detected: HTTP traffic on port 53989 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53993
Source: unknown Network traffic detected: HTTP traffic on port 53964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53910
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53998
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53997
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53996
Source: unknown Network traffic detected: HTTP traffic on port 54038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53958 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54007 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54035 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54056
Source: unknown Network traffic detected: HTTP traffic on port 54010 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53975 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53924
Source: unknown Network traffic detected: HTTP traffic on port 54022 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53923
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53927
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53926
Source: unknown Network traffic detected: HTTP traffic on port 53963 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53921
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54060
Source: unknown Network traffic detected: HTTP traffic on port 54013 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54025 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53936
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53935
Source: unknown Network traffic detected: HTTP traffic on port 54019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53937
Source: unknown Network traffic detected: HTTP traffic on port 53997 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53895
Source: unknown Network traffic detected: HTTP traffic on port 53928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53899
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53898
Source: unknown Network traffic detected: HTTP traffic on port 54036 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53896
Source: unknown Network traffic detected: HTTP traffic on port 53983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54060 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54005 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53977 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53895 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53914 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53946
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53965 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54037 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53923 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54034 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54000
Source: unknown Network traffic detected: HTTP traffic on port 54011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53958
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53956
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53999 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53959
Source: unknown Network traffic detected: HTTP traffic on port 54000 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54005
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54003
Source: unknown Network traffic detected: HTTP traffic on port 54017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54008
Source: unknown Network traffic detected: HTTP traffic on port 53926 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54007
Source: unknown Network traffic detected: HTTP traffic on port 54056 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53979 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54012
Source: unknown Network traffic detected: HTTP traffic on port 54031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54011
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54010
Source: unknown Network traffic detected: HTTP traffic on port 54003 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54028 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53937 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53912 -> 443
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:53896 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:53898 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:53899 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:53969 version: TLS 1.2
Source: classification engine Classification label: sus21.win@29/91@29/278
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1944,i,10147407103075529040,6438901996377724678,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://azurecr.io"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1944,i,10147407103075529040,6438901996377724678,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: https://www.google.com/search?q=azure+cr&oq=azure+cr+&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIJCAEQABgKGIAEMgkIAhAAGAoYgAQyCQgDEAAYChiABDIJCAQQABgKGIAEMgYIBRBFGDwyBggGEEUYPDIGCAcQRRg80gEINjUzM2owajeoAgCwAgA&sourceid=chrome&ie=UTF-8 LLM: Page contains button: 'Create Your Free Account Today - Microsoft Azure Sign Up' Source: '2.0.pages.csv'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs