Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://vl3r9t.duckdns.org/

Overview

General Information

Sample URL:https://vl3r9t.duckdns.org/
Analysis ID:1433046
Infos:
Errors
  • URL not reachable

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Uses dynamic DNS services

Classification

  • System is w10x64
  • chrome.exe (PID: 3180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5764 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2272,i,397317280939191624,3197294450678171814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6452 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vl3r9t.duckdns.org/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://vl3r9t.duckdns.org/Avira URL Cloud: detection malicious, Label: phishing
Source: vl3r9t.duckdns.orgVirustotal: Detection: 5%Perma Link
Source: https://vl3r9t.duckdns.org/Virustotal: Detection: 10%Perma Link

Networking

barindex
Source: unknownDNS query: name: vl3r9t.duckdns.org
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: vl3r9t.duckdns.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: vl3r9t.duckdns.orgConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: vl3r9t.duckdns.orgConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: vl3r9t.duckdns.orgConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: vl3r9t.duckdns.org
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: mal68.troj.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2272,i,397317280939191624,3197294450678171814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vl3r9t.duckdns.org/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2272,i,397317280939191624,3197294450678171814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive13
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://vl3r9t.duckdns.org/100%Avira URL Cloudphishing
https://vl3r9t.duckdns.org/11%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
vl3r9t.duckdns.org5%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.191.228
truefalse
    high
    vl3r9t.duckdns.org
    117.52.18.147
    truetrueunknown
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://vl3r9t.duckdns.org/true
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      117.52.18.147
      vl3r9t.duckdns.orgKorea Republic of
      3786LGDACOMLGDACOMCorporationKRtrue
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.191.228
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1433046
      Start date and time:2024-04-29 01:50:26 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 1m 53s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://vl3r9t.duckdns.org/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:5
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal68.troj.win@19/0@4/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.217.1.99, 142.250.190.46, 142.250.123.84, 34.104.35.123, 23.11.208.106, 40.127.169.103, 72.21.81.240, 192.229.211.108, 52.165.164.15
      • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 29, 2024 01:51:08.931689978 CEST49678443192.168.2.4104.46.162.224
      Apr 29, 2024 01:51:08.993976116 CEST49675443192.168.2.4173.222.162.32
      Apr 29, 2024 01:51:21.830193043 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.830296993 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:21.830379009 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.831214905 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.831264973 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:21.831322908 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.831577063 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.831612110 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:21.833271027 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:21.833285093 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.434401989 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.434834957 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.434962034 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.435024977 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.435415030 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.435480118 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.435513973 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.435532093 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.435847044 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.435897112 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.436126947 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.436172009 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.436450958 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.436491966 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.440964937 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.441044092 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.442066908 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.442126036 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.442558050 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.442575932 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.493520021 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.493535995 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:22.493571997 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:22.542179108 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:23.017671108 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:23.017749071 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:23.017965078 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:23.018085957 CEST49737443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:23.018125057 CEST44349737117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:23.774328947 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:23.774420023 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:23.774509907 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:23.774982929 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:23.775018930 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.014266014 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.014934063 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:24.014971018 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.015964985 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.016031981 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:24.017096043 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:24.017170906 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.065072060 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:24.065090895 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:24.072012901 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:24.072124958 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.072271109 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:24.072662115 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:24.072698116 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.106416941 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:24.116537094 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:24.164150000 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.410943031 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.410990000 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.411045074 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:24.643507957 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:24.692807913 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.739833117 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.739866972 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:25.739932060 CEST49738443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.739958048 CEST44349738117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:25.740494013 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:25.786374092 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.889389038 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.889555931 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:25.889581919 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:25.889612913 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:26.013204098 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:26.171626091 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:26.171679974 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:26.171734095 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:26.179517031 CEST49741443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:26.179554939 CEST44349741117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:31.991573095 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.991600037 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:31.991780996 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.992222071 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.992228031 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:31.992345095 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.993623972 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.993638039 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:31.993972063 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:31.993983030 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.568784952 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.570223093 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.570233107 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.570550919 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.572129011 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.572129011 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.572140932 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.572181940 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.573566914 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.573988914 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.573997021 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.574516058 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.574951887 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.575031996 CEST44349744117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:32.732033014 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:32.732088089 CEST49744443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:33.135966063 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:33.136007071 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:33.136055946 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:33.136351109 CEST49743443192.168.2.4117.52.18.147
      Apr 29, 2024 01:51:33.136358023 CEST44349743117.52.18.147192.168.2.4
      Apr 29, 2024 01:51:34.042722940 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:34.042870998 CEST44349739142.250.191.228192.168.2.4
      Apr 29, 2024 01:51:34.042941093 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:35.120949030 CEST49739443192.168.2.4142.250.191.228
      Apr 29, 2024 01:51:35.120992899 CEST44349739142.250.191.228192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 29, 2024 01:51:18.973521948 CEST53574791.1.1.1192.168.2.4
      Apr 29, 2024 01:51:19.003490925 CEST53607241.1.1.1192.168.2.4
      Apr 29, 2024 01:51:19.638991117 CEST53591251.1.1.1192.168.2.4
      Apr 29, 2024 01:51:21.655288935 CEST5617853192.168.2.41.1.1.1
      Apr 29, 2024 01:51:21.655342102 CEST5911753192.168.2.41.1.1.1
      Apr 29, 2024 01:51:21.795365095 CEST53591171.1.1.1192.168.2.4
      Apr 29, 2024 01:51:21.799171925 CEST53561781.1.1.1192.168.2.4
      Apr 29, 2024 01:51:23.661675930 CEST5823553192.168.2.41.1.1.1
      Apr 29, 2024 01:51:23.661861897 CEST5816753192.168.2.41.1.1.1
      Apr 29, 2024 01:51:23.772381067 CEST53582351.1.1.1192.168.2.4
      Apr 29, 2024 01:51:23.772810936 CEST53581671.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 29, 2024 01:51:21.655288935 CEST192.168.2.41.1.1.10xf545Standard query (0)vl3r9t.duckdns.orgA (IP address)IN (0x0001)false
      Apr 29, 2024 01:51:21.655342102 CEST192.168.2.41.1.1.10x5269Standard query (0)vl3r9t.duckdns.org65IN (0x0001)false
      Apr 29, 2024 01:51:23.661675930 CEST192.168.2.41.1.1.10x4e27Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 29, 2024 01:51:23.661861897 CEST192.168.2.41.1.1.10x19b6Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 29, 2024 01:51:21.799171925 CEST1.1.1.1192.168.2.40xf545No error (0)vl3r9t.duckdns.org117.52.18.147A (IP address)IN (0x0001)false
      Apr 29, 2024 01:51:23.772381067 CEST1.1.1.1192.168.2.40x4e27No error (0)www.google.com142.250.191.228A (IP address)IN (0x0001)false
      Apr 29, 2024 01:51:23.772810936 CEST1.1.1.1192.168.2.40x19b6No error (0)www.google.com65IN (0x0001)false
      Apr 29, 2024 01:51:33.867047071 CEST1.1.1.1192.168.2.40xb146No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 29, 2024 01:51:33.867047071 CEST1.1.1.1192.168.2.40xb146No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • vl3r9t.duckdns.org
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449737117.52.18.1474435764C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-28 23:51:22 UTC661OUTGET / HTTP/1.1
      Host: vl3r9t.duckdns.org
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449738117.52.18.1474435764C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-28 23:51:24 UTC687OUTGET / HTTP/1.1
      Host: vl3r9t.duckdns.org
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.449741117.52.18.1474435764C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-28 23:51:25 UTC687OUTGET / HTTP/1.1
      Host: vl3r9t.duckdns.org
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.449743117.52.18.1474435764C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-28 23:51:32 UTC687OUTGET / HTTP/1.1
      Host: vl3r9t.duckdns.org
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:51:12
      Start date:29/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:01:51:17
      Start date:29/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2272,i,397317280939191624,3197294450678171814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:01:51:20
      Start date:29/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vl3r9t.duckdns.org/"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly