Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_e

Overview

General Information

Sample URL:https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see
Analysis ID:1545196
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 3128 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1732 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2008 --field-trial-handle=2004,i,10813808725484045636,6189609329014632957,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6372 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficTCP traffic: 192.168.2.4:49618 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali HTTP/1.1Host: 4lnxbn1b.r.eu-west-1.awstrack.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali HTTP/1.1Host: 4lnxbn1b.r.eu-west-1.awstrack.meConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: 4lnxbn1b.r.eu-west-1.awstrack.me
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2008 --field-trial-handle=2004,i,10813808725484045636,6189609329014632957,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2008 --field-trial-handle=2004,i,10813808725484045636,6189609329014632957,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    172.217.18.4
    truefalse
      unknown
      baconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.com
      63.35.55.174
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          4lnxbn1b.r.eu-west-1.awstrack.me
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardalifalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              63.35.55.174
              baconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.comUnited States
              16509AMAZON-02USfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.217.18.4
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1545196
              Start date and time:2024-10-30 08:25:54 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 1m 57s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:UNKNOWN
              Classification:unknown0.win@18/0@4/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • URL browsing timeout or error
              • URL not reachable
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.181.238, 142.251.168.84, 34.104.35.123, 184.28.90.27, 20.12.23.50, 199.232.210.172, 192.229.221.95, 20.3.187.198, 13.85.23.206
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Oct 30, 2024 08:26:52.113065958 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113116980 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:52.113197088 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113523006 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113584995 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:52.113719940 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113730907 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:52.113750935 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113956928 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:52.113967896 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.185781956 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.203412056 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.231800079 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.251050949 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.371217966 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.371265888 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.371364117 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.371416092 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.372668028 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.372737885 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.373735905 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.373831034 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.382400036 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.382508039 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.382607937 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.382752895 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.382757902 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.382776976 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.429689884 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.432996988 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.433027029 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.482649088 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.623487949 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.623570919 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:53.623652935 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.624243021 CET49736443192.168.2.463.35.55.174
              Oct 30, 2024 08:26:53.624309063 CET4434973663.35.55.174192.168.2.4
              Oct 30, 2024 08:26:54.056250095 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:54.056320906 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:54.056396961 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:54.056794882 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:54.056811094 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:54.909383059 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:54.909689903 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:54.909713984 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:54.910993099 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:54.911056042 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:55.182045937 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:55.182482004 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:55.228116035 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:26:55.228142023 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:26:55.273999929 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:27:04.894593954 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:27:04.894680023 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:27:04.894751072 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:27:04.994976997 CET49739443192.168.2.4172.217.18.4
              Oct 30, 2024 08:27:04.995027065 CET44349739172.217.18.4192.168.2.4
              Oct 30, 2024 08:27:05.133882046 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.133927107 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.135845900 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.136269093 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.136286020 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.142070055 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.183350086 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.390873909 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.390954971 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.391020060 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.391436100 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.391458035 CET4434973563.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.391486883 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.391506910 CET49735443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.972111940 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.972388983 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.972414017 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.972879887 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:05.973200083 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:05.973257065 CET4434974463.35.55.174192.168.2.4
              Oct 30, 2024 08:27:06.023919106 CET49744443192.168.2.463.35.55.174
              Oct 30, 2024 08:27:08.815867901 CET4961853192.168.2.41.1.1.1
              Oct 30, 2024 08:27:08.821304083 CET53496181.1.1.1192.168.2.4
              Oct 30, 2024 08:27:08.821367025 CET4961853192.168.2.41.1.1.1
              Oct 30, 2024 08:27:08.821448088 CET4961853192.168.2.41.1.1.1
              Oct 30, 2024 08:27:08.827028036 CET53496181.1.1.1192.168.2.4
              Oct 30, 2024 08:27:09.427274942 CET53496181.1.1.1192.168.2.4
              Oct 30, 2024 08:27:09.449053049 CET4961853192.168.2.41.1.1.1
              Oct 30, 2024 08:27:09.454987049 CET53496181.1.1.1192.168.2.4
              Oct 30, 2024 08:27:09.455051899 CET4961853192.168.2.41.1.1.1
              TimestampSource PortDest PortSource IPDest IP
              Oct 30, 2024 08:26:50.124090910 CET53627251.1.1.1192.168.2.4
              Oct 30, 2024 08:26:50.281965017 CET53575221.1.1.1192.168.2.4
              Oct 30, 2024 08:26:51.589149952 CET53577171.1.1.1192.168.2.4
              Oct 30, 2024 08:26:52.059498072 CET5974853192.168.2.41.1.1.1
              Oct 30, 2024 08:26:52.059638023 CET5257253192.168.2.41.1.1.1
              Oct 30, 2024 08:26:52.092164993 CET53597481.1.1.1192.168.2.4
              Oct 30, 2024 08:26:52.280160904 CET53525721.1.1.1192.168.2.4
              Oct 30, 2024 08:26:54.021608114 CET5729453192.168.2.41.1.1.1
              Oct 30, 2024 08:26:54.021950006 CET5589953192.168.2.41.1.1.1
              Oct 30, 2024 08:26:54.029139996 CET53572941.1.1.1192.168.2.4
              Oct 30, 2024 08:26:54.029191971 CET53558991.1.1.1192.168.2.4
              Oct 30, 2024 08:27:07.809745073 CET138138192.168.2.4192.168.2.255
              Oct 30, 2024 08:27:08.629492044 CET53632711.1.1.1192.168.2.4
              Oct 30, 2024 08:27:08.815380096 CET53527641.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Oct 30, 2024 08:26:52.280252934 CET192.168.2.41.1.1.1c2c4(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Oct 30, 2024 08:26:52.059498072 CET192.168.2.41.1.1.10x3345Standard query (0)4lnxbn1b.r.eu-west-1.awstrack.meA (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:52.059638023 CET192.168.2.41.1.1.10xf32bStandard query (0)4lnxbn1b.r.eu-west-1.awstrack.me65IN (0x0001)false
              Oct 30, 2024 08:26:54.021608114 CET192.168.2.41.1.1.10x10bStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:54.021950006 CET192.168.2.41.1.1.10x157aStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)4lnxbn1b.r.eu-west-1.awstrack.mer.eu-west-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)r.eu-west-1.awstrack.mer.delegate.eu-west-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)r.delegate.eu-west-1.awstrack.mebaconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)baconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.com63.35.55.174A (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)baconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.com52.19.200.139A (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:52.092164993 CET1.1.1.1192.168.2.40x3345No error (0)baconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.com34.241.216.206A (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:52.280160904 CET1.1.1.1192.168.2.40xf32bNo error (0)4lnxbn1b.r.eu-west-1.awstrack.mer.eu-west-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:52.280160904 CET1.1.1.1192.168.2.40xf32bNo error (0)r.eu-west-1.awstrack.mer.delegate.eu-west-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:52.280160904 CET1.1.1.1192.168.2.40xf32bNo error (0)r.delegate.eu-west-1.awstrack.mebaconredirects-elb-1vu8uzbbqecyf-1056340931.eu-west-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:26:54.029139996 CET1.1.1.1192.168.2.40x10bNo error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
              Oct 30, 2024 08:26:54.029191971 CET1.1.1.1192.168.2.40x157aNo error (0)www.google.com65IN (0x0001)false
              Oct 30, 2024 08:27:05.034492016 CET1.1.1.1192.168.2.40xe9deNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Oct 30, 2024 08:27:05.034492016 CET1.1.1.1192.168.2.40xe9deNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Oct 30, 2024 08:27:06.764305115 CET1.1.1.1192.168.2.40x5b26No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Oct 30, 2024 08:27:06.764305115 CET1.1.1.1192.168.2.40x5b26No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • 4lnxbn1b.r.eu-west-1.awstrack.me
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973663.35.55.1744431732C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-10-30 07:26:53 UTC953OUTGET /L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali HTTP/1.1
              Host: 4lnxbn1b.r.eu-west-1.awstrack.me
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-10-30 07:26:53 UTC103INHTTP/1.1 400 Bad Request
              Date: Wed, 30 Oct 2024 07:26:52 GMT
              Content-Length: 0
              Connection: Close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973563.35.55.1744431732C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-10-30 07:27:05 UTC985OUTGET /L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali HTTP/1.1
              Host: 4lnxbn1b.r.eu-west-1.awstrack.me
              Connection: keep-alive
              Cache-Control: max-age=0
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: cross-site
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-10-30 07:27:05 UTC103INHTTP/1.1 400 Bad Request
              Date: Wed, 30 Oct 2024 07:27:04 GMT
              Content-Length: 0
              Connection: Close


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:03:26:45
              Start date:30/10/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:03:26:48
              Start date:30/10/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2008 --field-trial-handle=2004,i,10813808725484045636,6189609329014632957,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:03:26:51
              Start date:30/10/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4lnxbn1b.r.eu-west-1.awstrack.me/L0/https:%2F%2FWww.immoweb.be%2Fen%2Fcustomer_login.cfm%3Fredirect=emailAlert_reroute.cfm%26page=myiweb_alert.cfm%26metrics=MAIL_CLI%26idmetrics=1%26action=see%26xnum1=X_0%26xnum2=X_0%23utm_source=crm-b2c%26utm_medium=email%26utm_campaign=ali_seeker_iwb_b2c_emailing_standardali"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly