Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$

Overview

General Information

Sample URL:https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$
Analysis ID:1592085
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 2668 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5668 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2580 --field-trial-handle=2548,i,14005819817100885711,11826130259648070711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6560 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49744 version: TLS 1.0
Source: unknownHTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49744 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.36
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.36
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.36
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.36
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$ HTTP/1.1Host: armadasamudraglobal.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: armadasamudraglobal.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: armadasamudraglobal.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 15 Jan 2025 17:27:45 GMTContent-Type: text/html; charset=iso-8859-1Content-Length: 315Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 15 Jan 2025 17:27:46 GMTContent-Type: text/html; charset=iso-8859-1Content-Length: 315Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2580 --field-trial-handle=2548,i,14005819817100885711,11826130259648070711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2580 --field-trial-handle=2548,i,14005819817100885711,11826130259648070711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://armadasamudraglobal.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.132
truefalse
    high
    armadasamudraglobal.com
    51.79.247.131
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$false
        unknown
        https://armadasamudraglobal.com/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.185.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        51.79.247.131
        armadasamudraglobal.comCanada
        16276OVHFRfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1592085
        Start date and time:2025-01-15 18:26:43 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 53s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@16/4@4/4
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.78, 142.250.185.67, 108.177.15.84, 172.217.23.110, 142.250.181.238, 172.217.16.206, 84.201.210.39, 142.250.184.238, 142.250.186.46, 199.232.210.172, 2.23.77.188, 142.250.185.163, 216.58.206.46, 199.232.214.172, 184.28.90.27, 4.245.163.56, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):315
        Entropy (8bit):5.0572271090563765
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
        MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
        SHA1:A82190FC530C265AA40A045C21770D967F4767B8
        SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
        SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
        Malicious:false
        Reputation:low
        URL:https://armadasamudraglobal.com/favicon.ico
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):315
        Entropy (8bit):5.0572271090563765
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
        MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
        SHA1:A82190FC530C265AA40A045C21770D967F4767B8
        SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
        SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
        Malicious:false
        Reputation:low
        URL:https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jan 15, 2025 18:27:30.088057041 CET49675443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:39.742770910 CET49675443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:42.456048012 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:42.456100941 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:42.456197023 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:42.456388950 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:42.456403971 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.095913887 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.096162081 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:43.096174955 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.097184896 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.097248077 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:43.098505020 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:43.098562956 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.149274111 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:43.149296999 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:43.196152925 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:44.516973972 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.517014980 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:44.517081022 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.517303944 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.517318010 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:44.554755926 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.554807901 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:44.554883957 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.555335045 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:44.555351019 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.449930906 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.450201035 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.450212955 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.451250076 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.451309919 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.456074953 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.456155062 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.456254005 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.456267118 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.457171917 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.457360983 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.457379103 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.458858967 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.458923101 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.459352016 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.459420919 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.495486021 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.510687113 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.510695934 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.558159113 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.986852884 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.986958981 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:45.987052917 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.987843037 CET49741443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:45.987860918 CET4434974151.79.247.131192.168.2.4
        Jan 15, 2025 18:27:46.052931070 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:46.095325947 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:46.551709890 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:46.551908970 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:46.552026033 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:46.594059944 CET49742443192.168.2.451.79.247.131
        Jan 15, 2025 18:27:46.594093084 CET4434974251.79.247.131192.168.2.4
        Jan 15, 2025 18:27:46.956080914 CET44349730173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:46.956192970 CET49730443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.602392912 CET49730443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.602459908 CET49730443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.603185892 CET49744443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.603252888 CET44349744173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:50.603344917 CET49744443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.603981018 CET49744443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:50.604020119 CET44349744173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:50.607394934 CET44349730173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:50.607436895 CET44349730173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:51.208574057 CET44349744173.222.162.32192.168.2.4
        Jan 15, 2025 18:27:51.208741903 CET49744443192.168.2.4173.222.162.32
        Jan 15, 2025 18:27:53.022624016 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:53.022696972 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:53.022829056 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:53.666793108 CET49739443192.168.2.4142.250.185.132
        Jan 15, 2025 18:27:53.666832924 CET44349739142.250.185.132192.168.2.4
        Jan 15, 2025 18:27:55.984230042 CET8049723217.20.57.36192.168.2.4
        Jan 15, 2025 18:27:55.984483004 CET4972380192.168.2.4217.20.57.36
        Jan 15, 2025 18:27:55.984560013 CET4972380192.168.2.4217.20.57.36
        Jan 15, 2025 18:27:55.989438057 CET8049723217.20.57.36192.168.2.4
        Jan 15, 2025 18:28:10.364008904 CET44349744173.222.162.32192.168.2.4
        Jan 15, 2025 18:28:10.364166021 CET49744443192.168.2.4173.222.162.32
        Jan 15, 2025 18:28:11.592143059 CET8049724217.20.57.36192.168.2.4
        Jan 15, 2025 18:28:11.592386007 CET4972480192.168.2.4217.20.57.36
        Jan 15, 2025 18:28:11.592458963 CET4972480192.168.2.4217.20.57.36
        Jan 15, 2025 18:28:11.598581076 CET8049724217.20.57.36192.168.2.4
        Jan 15, 2025 18:28:42.510085106 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:42.510135889 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:42.510215044 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:42.510503054 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:42.510518074 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:43.177422047 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:43.177851915 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:43.177864075 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:43.178229094 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:43.178605080 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:43.178702116 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:43.227394104 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:53.256767035 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:53.256839991 CET44349802142.250.185.132192.168.2.4
        Jan 15, 2025 18:28:53.257030964 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:53.669485092 CET49802443192.168.2.4142.250.185.132
        Jan 15, 2025 18:28:53.669542074 CET44349802142.250.185.132192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jan 15, 2025 18:27:39.097147942 CET53635301.1.1.1192.168.2.4
        Jan 15, 2025 18:27:39.098165989 CET53589891.1.1.1192.168.2.4
        Jan 15, 2025 18:27:40.105313063 CET53567661.1.1.1192.168.2.4
        Jan 15, 2025 18:27:42.447500944 CET5655153192.168.2.41.1.1.1
        Jan 15, 2025 18:27:42.447648048 CET5269353192.168.2.41.1.1.1
        Jan 15, 2025 18:27:42.454911947 CET53526931.1.1.1192.168.2.4
        Jan 15, 2025 18:27:42.454927921 CET53565511.1.1.1192.168.2.4
        Jan 15, 2025 18:27:44.358164072 CET6275853192.168.2.41.1.1.1
        Jan 15, 2025 18:27:44.361212015 CET5342553192.168.2.41.1.1.1
        Jan 15, 2025 18:27:44.372503042 CET53534251.1.1.1192.168.2.4
        Jan 15, 2025 18:27:44.516345978 CET53627581.1.1.1192.168.2.4
        Jan 15, 2025 18:27:56.658840895 CET138138192.168.2.4192.168.2.255
        Jan 15, 2025 18:27:56.985882044 CET53607691.1.1.1192.168.2.4
        Jan 15, 2025 18:28:16.001579046 CET53625331.1.1.1192.168.2.4
        Jan 15, 2025 18:28:38.175756931 CET53501671.1.1.1192.168.2.4
        Jan 15, 2025 18:28:38.611592054 CET53508381.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 15, 2025 18:27:42.447500944 CET192.168.2.41.1.1.10x4010Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 15, 2025 18:27:42.447648048 CET192.168.2.41.1.1.10xc73eStandard query (0)www.google.com65IN (0x0001)false
        Jan 15, 2025 18:27:44.358164072 CET192.168.2.41.1.1.10x8fb6Standard query (0)armadasamudraglobal.comA (IP address)IN (0x0001)false
        Jan 15, 2025 18:27:44.361212015 CET192.168.2.41.1.1.10xf8b0Standard query (0)armadasamudraglobal.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 15, 2025 18:27:42.454911947 CET1.1.1.1192.168.2.40xc73eNo error (0)www.google.com65IN (0x0001)false
        Jan 15, 2025 18:27:42.454927921 CET1.1.1.1192.168.2.40x4010No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
        Jan 15, 2025 18:27:44.516345978 CET1.1.1.1192.168.2.40x8fb6No error (0)armadasamudraglobal.com51.79.247.131A (IP address)IN (0x0001)false
        • armadasamudraglobal.com
        • https:
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44974151.79.247.1314435668C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-15 17:27:45 UTC788OUTGET /doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$ HTTP/1.1
        Host: armadasamudraglobal.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-15 17:27:45 UTC163INHTTP/1.1 404 Not Found
        Server: nginx
        Date: Wed, 15 Jan 2025 17:27:45 GMT
        Content-Type: text/html; charset=iso-8859-1
        Content-Length: 315
        Connection: close
        2025-01-15 17:27:45 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974251.79.247.1314435668C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-15 17:27:46 UTC724OUTGET /favicon.ico HTTP/1.1
        Host: armadasamudraglobal.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-15 17:27:46 UTC163INHTTP/1.1 404 Not Found
        Server: nginx
        Date: Wed, 15 Jan 2025 17:27:46 GMT
        Content-Type: text/html; charset=iso-8859-1
        Content-Length: 315
        Connection: close
        2025-01-15 17:27:46 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:12:27:34
        Start date:15/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:12:27:36
        Start date:15/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2580 --field-trial-handle=2548,i,14005819817100885711,11826130259648070711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:12:27:43
        Start date:15/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://armadasamudraglobal.com/doc/mm.php__;!!Ofz1Xjg!8IBoxRCqe1nRRI5FNSOW6ZxmlMSqVCDMpC9kd_g-Gy4P0nJdYLMVo0RoUxEypxsi02YaZ5dhy5x2r4wqNsVTlISh1wo5opSYeA$"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly