Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://swhvsghw.blob.core.windows.net/debhje/bhde.html

Overview

General Information

Sample URL:https://swhvsghw.blob.core.windows.net/debhje/bhde.html
Analysis ID:1546302

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Stores files to the Windows start menu directory
Suspicious form URL found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 3056 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 2232 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 3868 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3316 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 6596 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://swhvsghw.blob.core.windows.net/debhje/bhde.html" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Number of links: 0
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: Number of links: 0
Source: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8zYjeAHZ8mo8UfBYN8qKvzk1Bn%2BON3OleBGWKyVwoxPcBqQqUZhvwODPHB4Y82z4zDjuwqffxO05HmeUj4rXIs7%2Bp0jP6eEdhDx8ErfSGp1GRNXANhU9t8yiggMhZGgpZQ2gP9LHX49M1wNJVRn1hiryoqo8NGCEqzZLEfBW133DJ8OuW1lke0JgwZQw3TdwEAR4BCN1IrqAm2kypki%2FwGEdPpzUQx4Cyt%2B3%2B%2FiXl5fSnaPzEpVtjssWqVqilyghSlhN%2B2FJbvNY5vM5w9BuX4EYdPTmNVnfqQ%2BhUNaENXgneLXXsxwPKeyhUPg2ki2rHbkcqnjwV%2F8%2BBRbzG%2FrH9gz4MZm8MtQG5aL11ieALI8BvUDqBy8VJhnUUfq0S6r%2F5faN89MbOejvlO%2FRB2gfJr7L0TwXk4IR13rBBACAgBfIzRZZdGcLilHnTSCdmUYnt9GDS9OPirt6Xcs4URz3mO4QwlYQndDjyM%2FXZHHvNgGI84uBYGSbhE8BVoomoHs%2BjUAlJ1iywk0QKBzj35Rr4Nb8dvM6IZ5n1MoopBYNLlqIf4L3s%2BmjU3piMEcmAbk6sdYrtv8%2FD0jUkNKfGgEN2J4FcCaHLxkaaikillDmPwUsAtiswZHqY52cowz0%2BgLkJhdviMgfIbc%2FCce2NmzquVpXN8IalGXm9sDhFqxdrozsKksPk8b1sN7%2FHNUVvf4868t6%2FM5tf3a696p%2BWO4CNX...HTTP Parser: Base64 decoded: eyJyb290IjoiXC9wYXJ3YWxsXC8iLCJmaWxlIjoiLlwvZmlsZXNcL3N0eWxlMi5jc3MiLCJ0eXBlIjoiY3NzIiwidiI6IjIifQ==
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Title: iPad Pro + Magic Keyboard does not match URL
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: Title: Alpha X Smartwatch does not match URL
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Form action: ajax.php?method=new_prospect
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Form action: ajax.php?method=new_prospect
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Form action: ajax.php?method=new_prospect
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Form action: ajax.php?method=new_prospect
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Form action: ajax.php?method=new_prospect
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Iframe src: https://api.pushnami.com/scripts/v1/hub
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Iframe src: https://api.pushnami.com/scripts/v1/hub
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Iframe src: https://api.pushnami.com/scripts/v1/hub
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Iframe src: https://api.pushnami.com/scripts/v1/hub
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: Iframe src: https://api.pushnami.com/scripts/v1/hub
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No favicon
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="author".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="author".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="author".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="author".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="author".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="author".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="author".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="author".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="author".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="author".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="copyright".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="copyright".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="copyright".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="copyright".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="copyright".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="copyright".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="copyright".. found
Source: https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6HTTP Parser: No <meta name="copyright".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="copyright".. found
Source: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49768 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:61653 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.0:443 -> 192.168.2.17:61800 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:61803 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.23.209.130:443 -> 192.168.2.17:61811 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:49964 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.17:61650 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: global trafficDNS traffic detected: DNS query: www.workjamtech.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.nadstrackify.com
Source: global trafficDNS traffic detected: DNS query: t4.catalystquasar.com
Source: global trafficDNS traffic detected: DNS query: kaxo.linkcollectiveads.com
Source: global trafficDNS traffic detected: DNS query: clipresource.com
Source: global trafficDNS traffic detected: DNS query: insightsandmarkets.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: pushrev.pushbroker.com
Source: global trafficDNS traffic detected: DNS query: tracknshosp.com
Source: global trafficDNS traffic detected: DNS query: pushlite.pushbroker.com
Source: global trafficDNS traffic detected: DNS query: www.swagtrk.com
Source: global trafficDNS traffic detected: DNS query: grandprizetrail.com
Source: global trafficDNS traffic detected: DNS query: api.pushnami.com
Source: global trafficDNS traffic detected: DNS query: trc.pushnami.com
Source: global trafficDNS traffic detected: DNS query: cdn.pushnami.com
Source: global trafficDNS traffic detected: DNS query: www.dmj52yrtk.com
Source: global trafficDNS traffic detected: DNS query: www.technojoyhaven.com
Source: global trafficDNS traffic detected: DNS query: videos.techtreasureworld.com
Source: global trafficDNS traffic detected: DNS query: stun3.l.google.com
Source: global trafficDNS traffic detected: DNS query: stun4.l.google.com
Source: global trafficDNS traffic detected: DNS query: psp.pushnami.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 61740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 61705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 61659 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49968
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49966
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
Source: unknownNetwork traffic detected: HTTP traffic on port 61717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
Source: unknownNetwork traffic detected: HTTP traffic on port 61762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 61739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61655
Source: unknownNetwork traffic detected: HTTP traffic on port 61798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61656
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61657
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61658
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61659
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 61660 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61651
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61653
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61654
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49968 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61682 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 61764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 61669 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 61670 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 61805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 61674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61666
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61668
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61669
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61660
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61661
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61662
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61663
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61664
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61665
Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61677
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61678
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61679
Source: unknownNetwork traffic detected: HTTP traffic on port 61744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61670
Source: unknownNetwork traffic detected: HTTP traffic on port 61815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61662 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61671
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61672
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61673
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61674
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61675
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61676
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61690
Source: unknownNetwork traffic detected: HTTP traffic on port 61732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61688
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61689
Source: unknownNetwork traffic detected: HTTP traffic on port 61684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61680
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61681
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61682
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61683
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61684
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61685
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61686
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61687
Source: unknownNetwork traffic detected: HTTP traffic on port 61766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61692
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61693
Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61694
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61695
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61696
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61698
Source: unknownNetwork traffic detected: HTTP traffic on port 61654 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61666 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61664 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61809
Source: unknownNetwork traffic detected: HTTP traffic on port 61691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61800
Source: unknownNetwork traffic detected: HTTP traffic on port 61703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61801
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61804
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61805
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61814
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61816
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61668 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 61715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49930
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 61727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49927
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61656 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49919
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49913
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 49948 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49909
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49908
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49907
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 61794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 61763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61745
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61742
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 61716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61754
Source: unknownNetwork traffic detected: HTTP traffic on port 61808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61759
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 61683 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 61671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61768
Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61760
Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61763
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 61787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61779
Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61772
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49768 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:61653 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.0:443 -> 192.168.2.17:61800 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:61803 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.23.209.130:443 -> 192.168.2.17:61811 version: TLS 1.2
Source: classification engineClassification label: clean3.win@24/6@70/337
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://swhvsghw.blob.core.windows.net/debhje/bhde.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3316 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3316 --field-trial-handle=2008,i,12306223218507249495,12805652351156953071,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Drive-by Compromise
Windows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
android.l.google.com
216.58.212.174
truefalse
    unknown
    grandprizetrail.com
    172.67.213.156
    truefalse
      unknown
      stun4.l.google.com
      74.125.250.129
      truefalse
        unknown
        a.nel.cloudflare.com
        35.190.80.1
        truefalse
          unknown
          cdn.pushnami.com
          18.244.18.49
          truefalse
            unknown
            stun3.l.google.com
            74.125.250.129
            truefalse
              unknown
              trc.pushnami.com
              52.71.167.26
              truefalse
                unknown
                psp.pushnami.com
                34.199.24.114
                truefalse
                  unknown
                  pushrev.pushbroker.com
                  188.114.97.3
                  truefalse
                    unknown
                    mobile-gtalk.l.google.com
                    74.125.206.188
                    truefalse
                      unknown
                      www.workjamtech.com
                      103.191.132.68
                      truefalse
                        unknown
                        insightsandmarkets.com
                        188.114.96.3
                        truefalse
                          unknown
                          tracknshosp.com
                          188.114.97.3
                          truefalse
                            unknown
                            t4.catalystquasar.com
                            188.114.96.3
                            truefalse
                              unknown
                              www.nadstrackify.com
                              104.21.75.26
                              truefalse
                                unknown
                                videos.techtreasureworld.com
                                66.135.0.127
                                truefalse
                                  unknown
                                  pushlite.pushbroker.com
                                  188.114.96.3
                                  truefalse
                                    unknown
                                    clipresource.com
                                    104.21.31.175
                                    truefalse
                                      unknown
                                      www.swagtrk.com
                                      35.241.26.240
                                      truefalse
                                        unknown
                                        www.google.com
                                        142.250.185.68
                                        truefalse
                                          unknown
                                          kaxo.linkcollectiveads.com
                                          188.114.96.3
                                          truefalse
                                            unknown
                                            api.pushnami.com
                                            13.32.99.54
                                            truefalse
                                              unknown
                                              www.technojoyhaven.com
                                              104.21.27.249
                                              truefalse
                                                unknown
                                                www.dmj52yrtk.com
                                                34.110.166.184
                                                truefalse
                                                  unknown
                                                  NameMaliciousAntivirus DetectionReputation
                                                  https://grandprizetrail.com/z/v2/ipad-magic-key/?affid=1309&subAff=&c1=1857&c2=INMe08d2a2f443dcb9&c3=&c4=&c7=&c8=&c9=&c10=&c11=&c12=&c13=&click_id=ae731d0ef96e4f1982cf9cdd0db267e6false
                                                    unknown
                                                    https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31false
                                                      unknown
                                                      • No. of IPs < 25%
                                                      • 25% < No. of IPs < 50%
                                                      • 50% < No. of IPs < 75%
                                                      • 75% < No. of IPs
                                                      IPDomainCountryFlagASNASN NameMalicious
                                                      142.250.186.67
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      52.71.167.26
                                                      trc.pushnami.comUnited States
                                                      14618AMAZON-AESUSfalse
                                                      13.32.99.63
                                                      unknownUnited States
                                                      16509AMAZON-02USfalse
                                                      34.199.24.114
                                                      psp.pushnami.comUnited States
                                                      14618AMAZON-AESUSfalse
                                                      18.244.18.49
                                                      cdn.pushnami.comUnited States
                                                      16509AMAZON-02USfalse
                                                      18.238.243.120
                                                      unknownUnited States
                                                      16509AMAZON-02USfalse
                                                      103.191.132.68
                                                      www.workjamtech.comunknown
                                                      7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
                                                      34.110.166.184
                                                      www.dmj52yrtk.comUnited States
                                                      15169GOOGLEUSfalse
                                                      35.190.80.1
                                                      a.nel.cloudflare.comUnited States
                                                      15169GOOGLEUSfalse
                                                      216.58.212.174
                                                      android.l.google.comUnited States
                                                      15169GOOGLEUSfalse
                                                      172.217.18.10
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      74.125.250.129
                                                      stun4.l.google.comUnited States
                                                      15169GOOGLEUSfalse
                                                      142.250.185.68
                                                      www.google.comUnited States
                                                      15169GOOGLEUSfalse
                                                      1.1.1.1
                                                      unknownAustralia
                                                      13335CLOUDFLARENETUSfalse
                                                      108.177.15.84
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      104.21.37.219
                                                      unknownUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      172.217.16.206
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      44.215.174.252
                                                      unknownUnited States
                                                      14618AMAZON-AESUSfalse
                                                      142.250.186.163
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      57.150.87.129
                                                      unknownBelgium
                                                      2686ATGS-MMD-ASUSfalse
                                                      172.67.213.156
                                                      grandprizetrail.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      172.217.18.3
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      13.32.99.54
                                                      api.pushnami.comUnited States
                                                      16509AMAZON-02USfalse
                                                      3.212.247.119
                                                      unknownUnited States
                                                      14618AMAZON-AESUSfalse
                                                      142.250.185.234
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      104.21.27.249
                                                      www.technojoyhaven.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      216.58.206.42
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      74.125.206.188
                                                      mobile-gtalk.l.google.comUnited States
                                                      15169GOOGLEUSfalse
                                                      66.135.0.127
                                                      videos.techtreasureworld.comUnited States
                                                      18566MEGAPATH5-USfalse
                                                      142.250.186.106
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      142.250.185.170
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      239.255.255.250
                                                      unknownReserved
                                                      unknownunknownfalse
                                                      188.114.97.3
                                                      pushrev.pushbroker.comEuropean Union
                                                      13335CLOUDFLARENETUSfalse
                                                      188.114.96.3
                                                      insightsandmarkets.comEuropean Union
                                                      13335CLOUDFLARENETUSfalse
                                                      142.250.186.142
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      104.21.31.175
                                                      clipresource.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      142.250.186.42
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      104.21.75.26
                                                      www.nadstrackify.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      142.250.185.74
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      35.241.26.240
                                                      www.swagtrk.comUnited States
                                                      15169GOOGLEUSfalse
                                                      IP
                                                      192.168.2.17
                                                      192.168.2.16
                                                      Joe Sandbox version:41.0.0 Charoite
                                                      Analysis ID:1546302
                                                      Start date and time:2024-10-31 18:46:44 +01:00
                                                      Joe Sandbox product:CloudBasic
                                                      Overall analysis duration:
                                                      Hypervisor based Inspection enabled:false
                                                      Report type:full
                                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                      Sample URL:https://swhvsghw.blob.core.windows.net/debhje/bhde.html
                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                      Number of analysed new started processes analysed:25
                                                      Number of new started drivers analysed:1
                                                      Number of existing processes analysed:0
                                                      Number of existing drivers analysed:0
                                                      Number of injected processes analysed:0
                                                      Technologies:
                                                      • EGA enabled
                                                      Analysis Mode:stream
                                                      Analysis stop reason:Timeout
                                                      Detection:CLEAN
                                                      Classification:clean3.win@24/6@70/337
                                                      • Exclude process from analysis (whitelisted): TextInputHost.exe
                                                      • Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.250.186.142, 108.177.15.84, 34.104.35.123, 57.150.87.129
                                                      • Not all processes where analyzed, report is missing behavior information
                                                      • VT rate limit hit for: https://swhvsghw.blob.core.windows.net/debhje/bhde.html
                                                      InputOutput
                                                      URL: Model: claude-3-5-sonnet-latest
                                                      {
                                                          "typosquatting": false,
                                                          "unusual_query_string": false,
                                                          "suspicious_tld": false,
                                                          "ip_in_url": false,
                                                          "long_subdomain": true,
                                                          "malicious_keywords": false,
                                                          "encoded_characters": false,
                                                          "redirection": false,
                                                          "contains_email_address": false,
                                                          "known_domain": true,
                                                          "brand_spoofing_attempt": false,
                                                          "third_party_hosting": true
                                                      }
                                                      URL: URL: https://swhvsghw.blob.core.windows.net
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": true,
                                                        "trigger_text": "Your membership has expired!",
                                                        "prominent_button_name": "Extend and Select Reward",
                                                        "text_input_field_labels": "unknown",
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: Model: claude-3-5-sonnet-latest
                                                      {
                                                          "typosquatting": false,
                                                          "unusual_query_string": false,
                                                          "suspicious_tld": false,
                                                          "ip_in_url": false,
                                                          "long_subdomain": false,
                                                          "malicious_keywords": true,
                                                          "encoded_characters": false,
                                                          "redirection": false,
                                                          "contains_email_address": false,
                                                          "known_domain": false,
                                                          "brand_spoofing_attempt": false,
                                                          "third_party_hosting": true
                                                      }
                                                      URL: URL: https://kaxo.linkcollectiveads.com
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": true,
                                                        "trigger_text": "COMPLETE YOUR RENEWAL BY SELECTING A REWARD",
                                                        "prominent_button_name": "Claim Reward",
                                                        "text_input_field_labels": "unknown",
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Paramount+"
                                                        ]
                                                      }
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Paramount"
                                                        ]
                                                      }
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "Claim Reward",
                                                        "text_input_field_labels": "unknown",
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": false,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: Model: claude-3-5-sonnet-latest
                                                      {
                                                          "typosquatting": false,
                                                          "unusual_query_string": false,
                                                          "suspicious_tld": false,
                                                          "ip_in_url": false,
                                                          "long_subdomain": false,
                                                          "malicious_keywords": true,
                                                          "encoded_characters": false,
                                                          "redirection": false,
                                                          "contains_email_address": false,
                                                          "known_domain": false,
                                                          "brand_spoofing_attempt": false,
                                                          "third_party_hosting": false
                                                      }
                                                      URL: URL: https://grandprizetrail.com
                                                      URL: https://kaxo.linkcollectiveads.com/toliya/nuru/simowida/xaxoce/vexaxe/index.php?rpclk=Ug5BphGt6whdp%2BGoKu1qAHf3p98ScLTqwBvgk19FTercTGscnsRsfloepIQ5crw1wimh8cyNcPIpzZNJnFFtiZuXPekH%2BVKd%2FmxO6Jt7ZuB37UT6aRNovMu%2FU1JApSt%2F6lWqXROiAnQIyUS8Qn8EdkHBtpcYTu8 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Paramount"
                                                        ]
                                                      }
                                                      URL: Model: claude-3-5-sonnet-latest
                                                      {
                                                          "typosquatting": false,
                                                          "unusual_query_string": false,
                                                          "suspicious_tld": false,
                                                          "ip_in_url": false,
                                                          "long_subdomain": false,
                                                          "malicious_keywords": false,
                                                          "encoded_characters": false,
                                                          "redirection": false,
                                                          "contains_email_address": false,
                                                          "known_domain": false,
                                                          "brand_spoofing_attempt": false,
                                                          "third_party_hosting": false
                                                      }
                                                      URL: URL: https://www.technojoyhaven.com
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "ORDER NOW",
                                                        "text_input_field_labels": [
                                                          "First Name",
                                                          "Last Name",
                                                          "Email Address",
                                                          "Phone",
                                                          "Shipping Address",
                                                          "Apartment, suite, etc. (optional)",
                                                          "Zip Code",
                                                          "City",
                                                          "State/State"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "Get Your Alpha X Smartwatch Today",
                                                        "text_input_field_labels": [
                                                          "First Name",
                                                          "Last Name",
                                                          "Email Address",
                                                          "Phone"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X"
                                                        ]
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X"
                                                        ]
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: gpt-4o
                                                      ```json{  "legit_domain": "unknown",  "classification": "unknown",  "reasons": [    "The brand 'Alpha X' is not widely recognized, making it difficult to associate with a specific legitimate domain.",    "The URL 'www.technojoyhaven.com' does not directly suggest any well-known brand or service.",    "The domain name does not match any known legitimate domain associated with a well-known brand.",    "The URL does not contain any obvious misspellings or suspicious elements, but the lack of brand association is concerning.",    "The presence of multiple input fields for personal information is typical for e-commerce or service sites, but without a known brand association, it raises suspicion."  ],  "riskscore": 7}
                                                      URL: www.technojoyhaven.com
                                                                  Brands: Alpha X
                                                                  Input Fields: First Name, Last Name, Email Address, Phone, Shipping Address, Apartment, suite, etc. (optional), Zip Code, City, State/State
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "ORDER NOW",
                                                        "text_input_field_labels": [
                                                          "First Name",
                                                          "Last Name",
                                                          "Email Address",
                                                          "Phone",
                                                          "Shipping Address",
                                                          "Apartment, suite, etc. (optional)",
                                                          "Zip Code",
                                                          "City",
                                                          "State/State"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "FREE Product Discount Activated",
                                                        "text_input_field_labels": [
                                                          "First Name",
                                                          "Last Name",
                                                          "Email Address",
                                                          "Phone",
                                                          "Shipping Address",
                                                          "Apartment, suite, etc. (optional)",
                                                          "Zip Code",
                                                          "City",
                                                          "State / State"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X"
                                                        ]
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X"
                                                        ]
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: gpt-4o
                                                      ```json{  "legit_domain": "unknown",  "classification": "unknown",  "reasons": [    "The brand 'Alpha X' is not widely recognized, making it difficult to associate with a specific legitimate domain.",    "The URL 'www.technojoyhaven.com' does not directly suggest any well-known brand association.",    "The domain name does not match any known legitimate domain for a well-known brand.",    "The URL does not contain any obvious misspellings or suspicious elements, but the lack of brand recognition is a concern.",    "The presence of multiple input fields for personal information is typical for e-commerce or service sites, but without a known brand association, it raises suspicion."  ],  "riskscore": 7}
                                                      URL: www.technojoyhaven.com
                                                                  Brands: Alpha X
                                                                  Input Fields: First Name, Last Name, Email Address, Phone, Shipping Address, Apartment, suite, etc. (optional), Zip Code, City, State/State
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: gpt-4o
                                                      ```json{  "legit_domain": "unknown",  "classification": "unknown",  "reasons": [    "The brand 'Alpha X' is not widely recognized, making it difficult to associate with a specific legitimate domain.",    "The URL 'www.technojoyhaven.com' does not directly suggest any well-known brand or service.",    "The domain name does not match any known legitimate domain associated with a well-known brand.",    "The URL does not contain any obvious misspellings or suspicious elements, but it is not associated with a known brand.",    "The presence of multiple input fields for personal information is typical for e-commerce or service sites, but without a known brand association, it raises caution."  ],  "riskscore": 7}
                                                      URL: www.technojoyhaven.com
                                                                  Brands: Alpha X
                                                                  Input Fields: First Name, Last Name, Email Address, Phone, Shipping Address, Apartment, suite, etc. (optional), Zip Code, City, State / State
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "ORDER NOW",
                                                        "text_input_field_labels": [
                                                          "Zip Code",
                                                          "City",
                                                          "State/State"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": true,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X",
                                                          "Assistant"
                                                        ]
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "contains_trigger_text": false,
                                                        "trigger_text": "unknown",
                                                        "prominent_button_name": "ORDER NOW",
                                                        "text_input_field_labels": [
                                                          "What is this?"
                                                        ],
                                                        "pdf_icon_visible": false,
                                                        "has_visible_captcha": false,
                                                        "has_urgent_text": false,
                                                        "has_visible_qrcode": false
                                                      }
                                                      URL: https://www.technojoyhaven.com/smart-watch/GKP-2CL/checkout.php?AFFID=18&C1=68&C2=wbd0quo2gmvun995jsi5vq4q&C3=&C4=&C5=5d75cf61654a4d578d9e9caaf73a5f8a&click_id=4c14e7ecc86746fc985839b1e1c74e31 Model: claude-3-haiku-20240307
                                                      ```json
                                                      {
                                                        "brands": [
                                                          "Alpha X"
                                                        ]
                                                      }
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 16:47:15 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2677
                                                      Entropy (8bit):3.9901602229317636
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B0183DC28202136EAFAA938827EAF5CC
                                                      SHA1:AD5DC528E567902244D9B93607C1065D015AE3DC
                                                      SHA-256:95944110B05E0BDD1BB92A90B77447AEF9A6E89094D26EEF804C5146784F5366
                                                      SHA-512:BEE5553ABA35D6F7A07CCFFA3D305EDCA428E9E88D2CC799C6487BB87B62BC1B16552B57FDD9534E9528751742697078E6089FCEE83F3D1351090641E42178F8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,....L...+......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V_Y............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 16:47:15 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2679
                                                      Entropy (8bit):4.005937876759027
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C698C3975BFA2B2F9ECFEDB83FBC22C3
                                                      SHA1:331467F6974DF75808BA2EDC235B865B6BC01C9A
                                                      SHA-256:3FD8B031C645113639E282E5DC2C22B6169AAB831BE728E43E6BB52FA43CEE6C
                                                      SHA-512:7E8CE30AFE3BD1B46FC9B4E80FB765F21446711CBDB4145BC25A4C5D172EE44845F406F1B55F069F825BC6471C6BA9543EFAF24AA3C77DC2A7465AE580FFA7CA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,.....J..+......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V_Y............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2693
                                                      Entropy (8bit):4.013640931248565
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:83E67D297D0210EB28D88E5CFA024ACF
                                                      SHA1:A3CABB7C0E985D6A95EB7C0AC9040452C6332EE0
                                                      SHA-256:0F3F04EC6A7AB52957EAF483B28B55B7E6CC641158D4B71792DC65F7C5979EFE
                                                      SHA-512:DB9D63E6CB129FA13D9E9068D4480C479833E32C09686B94C0B80B9012BF2C5244540B3EAFAD70C6A1FD78C092E040EBF2AD790832D3829B2169CEB2540A8E2C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 16:47:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2681
                                                      Entropy (8bit):4.00424710470785
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:732BC1AFC3AFCF48C4E8B6C182A6304F
                                                      SHA1:F6D35A4A7396C1BB435AA169053E8679CF0F6406
                                                      SHA-256:C46B0FE3BD614E5765963F1236D90B92FDF572CFC6CFECA8A0FC271B6C8B679C
                                                      SHA-512:D7666DDB7E6F3E1B116E4A3F3FF5686391C98A9A5B426EB50962B1D43FF7EA470E9C1A87252ECECC7E69AA5B1EADDD5318E75F5B008D63A15DF07BFDC3840562
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,........+......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V_Y............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 16:47:15 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2681
                                                      Entropy (8bit):3.991927050764045
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8A11D060856B39CC763C7B576E0785AA
                                                      SHA1:ECF40A7475070DA5FE6C3D71633F334E37280748
                                                      SHA-256:C2CDFE967E0B4E1F8944BAE22CBB11D92BCD6A9312DC09B16AB820760BB0E2A2
                                                      SHA-512:34407EFB34169D79BBAFDDE5C751A620060B907E055CC7508BFEC15EA7BE0366427E1666A80B47F68BC945B384B728A091D5D3BBD78C8D3AA51DBF99F796F54B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,........+......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V_Y............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 16:47:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2683
                                                      Entropy (8bit):4.004661658836566
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:24A94F0BB5463D97A869CCD5C5F60269
                                                      SHA1:710DD39AA604974E786F1E6241998C2210C1B09A
                                                      SHA-256:14696F44B8B5D54CEC4B1781B7FBC73EE892CF49938A6166A9E1E969E1253B96
                                                      SHA-512:92C984C20F176F2628587148330FDE96C1CA095B61E44FA1AB5A18ACB5B024BFAE5D69EE94618CED9AC1041908842C582ED9BAA0E2EB3A04E58CCE479864471F
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,....(...+......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I_Y.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V_Y.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V_Y.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V_Y............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V_Y............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      No static file info