Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr

Overview

General Information

Sample URL:http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr
Analysis ID:1271053
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64native
  • chrome.exe (PID: 6188 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 464953824E644F10FFDC9E093FD18F94)
    • chrome.exe (PID: 9056 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1676,5534151309402295221,11728340676976103501,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 /prefetch:8 MD5: 464953824E644F10FFDC9E093FD18F94)
  • chrome.exe (PID: 1876 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr MD5: 464953824E644F10FFDC9E093FD18F94)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50188 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50189 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50189 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50190 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:54679 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.23.104.113:443 -> 192.168.11.20:62000 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.223.46.67:443 -> 192.168.11.20:62001 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:62452 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:62453 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:59716 version: TLS 1.2
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=94.0.4606.61&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-94.0.4606.61Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com HTTP/1.1Host: smenet.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com HTTP/1.1Host: www.smenet.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ARRAffinity=4f614c86e9b5e6193efc0ca76334e75894cd3a64871780a2020181bb53745290; ARRAffinitySameSite=4f614c86e9b5e6193efc0ca76334e75894cd3a64871780a2020181bb53745290
Source: global trafficHTTP traffic detected: GET /?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVr HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: http://xx6v1x.caobatours.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/style.css HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVr HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /assets/style.css HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivePragma: no-cacheCache-Control: no-cachesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVr HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /assets/style.css HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-alivePragma: no-cacheCache-Control: no-cachesec-ch-ua: "Chromium";v="94", "Google Chrome";v="94", ";Not A Brand";v="99"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://yylinvaant.bureaurid.tech/?email=YXRvbC5vbmxpbmVAY2FhLmNvLnVrAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: yylinvaant.bureaurid.techConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=12b7a0fb2c4e8907d90ed7ccac6c1276
Source: global trafficHTTP traffic detected: GET /ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com HTTP/1.1Host: smenet.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com HTTP/1.1Host: www.smenet.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: xx6v1x.caobatours.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: global trafficTCP traffic: 192.168.11.20:62190 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:62190 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:62190 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:62190 -> 239.255.255.250:1900
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKConnection: Keep-AliveKeep-Alive: timeout=5, max=100content-type: text/html; charset=UTF-8content-length: 159content-encoding: gzipvary: Accept-Encodingdate: Tue, 11 Jul 2023 15:41:27 GMTserver: LiteSpeedData Raw: 1f 8b 08 00 00 00 00 00 00 03 5d 8f 41 0a c2 30 14 44 f7 85 de e1 13 17 b5 54 92 bd 69 ea 59 be 69 20 1f 63 12 92 b4 b5 b7 97 6a 15 71 35 30 0c f3 66 fa ac 13 c5 32 40 5d 01 00 cc 98 c0 62 b6 a0 60 21 3f 86 85 bb a0 b1 50 f0 7c b3 e5 3b a5 9d 41 bf c7 36 e1 c9 44 87 da 1c d9 81 9d 80 b1 56 fe d4 39 f2 b7 87 62 b6 94 98 cf 42 ac ab 23 3f 23 fa c2 af 53 32 38 25 1a 79 31 da 8a 8b b9 23 39 c5 76 c8 3f ff c3 78 f5 75 4d d3 7d 57 b4 b2 ae 7a b1 1f 79 02 d1 28 84 1f d1 00 00 00 Data Ascii: ]A0DTiYi cjq50f2@]b`!?P|;A6DV9bB#?#S28%y1#9v?xuM}Wzy(
Source: unknownNetwork traffic detected: HTTP traffic on port 64991 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62001 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57982 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59425
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51592
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59193
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60657
Source: unknownNetwork traffic detected: HTTP traffic on port 59497 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62000 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50190 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 58756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50188
Source: unknownNetwork traffic detected: HTTP traffic on port 62451 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50189
Source: unknownNetwork traffic detected: HTTP traffic on port 54678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50190
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57982
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62000
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62001
Source: unknownNetwork traffic detected: HTTP traffic on port 59716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61113
Source: unknownNetwork traffic detected: HTTP traffic on port 61649 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 60657 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 60550 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61113 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57669
Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62452 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54679
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54678
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58756
Source: unknownNetwork traffic detected: HTTP traffic on port 54679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64034 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60550
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61649
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59497
Source: unknownNetwork traffic detected: HTTP traffic on port 59193 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53030
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64991
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64034
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62451
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62452
Source: unknownNetwork traffic detected: HTTP traffic on port 51592 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62453
Source: unknownNetwork traffic detected: HTTP traffic on port 59715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50889
Source: unknownNetwork traffic detected: HTTP traffic on port 62453 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50188 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 53030 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61217
Source: unknownNetwork traffic detected: HTTP traffic on port 57669 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53082
Source: unknownNetwork traffic detected: HTTP traffic on port 53082 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59425 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61217 -> 443
Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19042.0.0; IDCRL-cfg 16.000.29143.3; App svchost.exe, 10.0.19041.546, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 4725Host: login.live.com
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.140
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50188 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50189 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50189 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:50190 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.140:443 -> 192.168.11.20:54679 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.23.104.113:443 -> 192.168.11.20:62000 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.223.46.67:443 -> 192.168.11.20:62001 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:62452 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:62453 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.184.217.20:443 -> 192.168.11.20:59716 version: TLS 1.2
Source: classification engineClassification label: clean0.win@32/0@7/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1676,5534151309402295221,11728340676976103501,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1676,5534151309402295221,11728340676976103501,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
Network Service Scanning
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr0%VirustotalBrowse
http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
xx6v1x.caobatours.com0%VirustotalBrowse
smenet.org0%VirustotalBrowse
www.smenet.org0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://www.smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com0%Avira URL Cloudsafe
http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com0%Avira URL Cloudsafe
https://www.smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com0%Avira URL Cloudsafe
https://yylinvaant.bureaurid.tech/favicon.ico0%Avira URL Cloudsafe
https://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com0%Avira URL Cloudsafe
http://xx6v1x.caobatours.com/0%Avira URL Cloudsafe
https://yylinvaant.bureaurid.tech/assets/style.css0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.185.77
truefalse
    high
    xx6v1x.caobatours.com
    185.244.151.84
    truefalseunknown
    yylinvaant.bureaurid.tech
    199.192.25.226
    truefalse
      unknown
      www.google.com
      142.250.186.68
      truefalse
        high
        clients.l.google.com
        216.58.212.142
        truefalse
          high
          smenet.org
          40.69.190.41
          truefalseunknown
          clients2.google.com
          unknown
          unknownfalse
            high
            www.smenet.org
            unknown
            unknownfalseunknown
            NameMaliciousAntivirus DetectionReputation
            https://www.smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.comfalse
            • Avira URL Cloud: safe
            unknown
            http://www.smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.comfalse
            • Avira URL Cloud: safe
            unknown
            http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.comfalse
            • Avira URL Cloud: safe
            unknown
            https://yylinvaant.bureaurid.tech/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.comfalse
            • Avira URL Cloud: safe
            unknown
            http://xx6v1x.caobatours.com/false
            • Avira URL Cloud: safe
            unknown
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              https://yylinvaant.bureaurid.tech/assets/style.cssfalse
              • Avira URL Cloud: safe
              unknown
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=94.0.4606.61&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.185.77
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                142.250.186.68
                www.google.comUnited States
                15169GOOGLEUSfalse
                216.58.212.142
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                40.69.190.41
                smenet.orgUnited States
                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                185.244.151.84
                xx6v1x.caobatours.comNetherlands
                60117HSAEfalse
                199.192.25.226
                yylinvaant.bureaurid.techUnited States
                22612NAMECHEAP-NETUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                IP
                192.168.11.20
                Joe Sandbox Version:38.0.0 Beryl
                Analysis ID:1271053
                Start date and time:2023-07-11 17:39:27 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 4m 24s
                Hypervisor based Inspection enabled:false
                Report type:light
                Cookbook file name:browseurl.jbs
                Sample URL:http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr
                Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                Number of analysed new started processes analysed:6
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@32/0@7/8
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): dllhost.exe, CompPkgSrv.exe, TextInputHost.exe
                • TCP Packets have been reduced to 100
                • Excluded IPs from analysis (whitelisted): 142.250.74.195, 34.104.35.123, 142.250.186.170, 142.250.185.195, 172.217.23.99
                • Excluded domains from analysis (whitelisted): wdcpalt.microsoft.com, array507.prod.do.dsp.mp.microsoft.com, edgedl.me.gvt1.com, login.live.com, ajax.googleapis.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.gstatic.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Jul 11, 2023 17:41:18.212951899 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.213073015 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.213432074 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.213809967 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.213891983 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.334655046 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.334853888 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.354479074 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.354494095 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.354898930 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.356115103 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.356116056 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.356139898 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.356153011 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.494103909 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.494210958 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.494441032 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.494525909 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.494525909 CEST50188443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.494539976 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.494544029 CEST4435018840.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.557037115 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.557056904 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.557267904 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.557450056 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.557457924 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.624162912 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.624444008 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.625601053 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.625610113 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.625834942 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.626306057 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.626306057 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.626322985 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.626364946 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:18.626420021 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:18.626466036 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.446650982 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.446675062 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.446696997 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.446861982 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.446878910 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.447006941 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.447174072 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.447201967 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.447201967 CEST50189443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.447216988 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.447222948 CEST4435018940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.477540016 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.477612972 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.477813005 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.477976084 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.478028059 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.563316107 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.563546896 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.564870119 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.564898968 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.565570116 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:20.566009045 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.566009045 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:20.566135883 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.429580927 CEST64991443192.168.11.20142.250.185.77
                Jul 11, 2023 17:41:21.429661036 CEST44364991142.250.185.77192.168.11.20
                Jul 11, 2023 17:41:21.429819107 CEST64991443192.168.11.20142.250.185.77
                Jul 11, 2023 17:41:21.429877996 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.429939032 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.429997921 CEST64991443192.168.11.20142.250.185.77
                Jul 11, 2023 17:41:21.430042982 CEST44364991142.250.185.77192.168.11.20
                Jul 11, 2023 17:41:21.430131912 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.430231094 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.430273056 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.501256943 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.501276016 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.501391888 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.501431942 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.501471043 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.501662970 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.501853943 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.502037048 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.502037048 CEST50190443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.502049923 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.502055883 CEST4435019040.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.523720980 CEST54679443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.523741961 CEST4435467940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.523871899 CEST54679443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.524036884 CEST54679443192.168.11.2040.126.32.140
                Jul 11, 2023 17:41:21.524044991 CEST4435467940.126.32.140192.168.11.20
                Jul 11, 2023 17:41:21.528287888 CEST44364991142.250.185.77192.168.11.20
                Jul 11, 2023 17:41:21.528536081 CEST64991443192.168.11.20142.250.185.77
                Jul 11, 2023 17:41:21.528549910 CEST44364991142.250.185.77192.168.11.20
                Jul 11, 2023 17:41:21.529979944 CEST44364991142.250.185.77192.168.11.20
                Jul 11, 2023 17:41:21.530078888 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.530154943 CEST64991443192.168.11.20142.250.185.77
                Jul 11, 2023 17:41:21.531085968 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.531091928 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.531452894 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.531666994 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.532067060 CEST44354678216.58.212.142192.168.11.20
                Jul 11, 2023 17:41:21.532303095 CEST54678443192.168.11.20216.58.212.142
                Jul 11, 2023 17:41:21.547282934 CEST64991443192.168.11.20142.250.185.77
                TimestampSource PortDest PortSource IPDest IP
                Jul 11, 2023 17:41:21.419178963 CEST5665053192.168.11.201.1.1.1
                Jul 11, 2023 17:41:21.419770002 CEST6218953192.168.11.201.1.1.1
                Jul 11, 2023 17:41:21.428889990 CEST53621891.1.1.1192.168.11.20
                Jul 11, 2023 17:41:21.428946972 CEST53566501.1.1.1192.168.11.20
                Jul 11, 2023 17:41:21.435481071 CEST621901900192.168.11.20239.255.255.250
                Jul 11, 2023 17:41:22.439332008 CEST621901900192.168.11.20239.255.255.250
                Jul 11, 2023 17:41:23.448947906 CEST621901900192.168.11.20239.255.255.250
                Jul 11, 2023 17:41:23.470927000 CEST5461253192.168.11.201.1.1.1
                Jul 11, 2023 17:41:23.483186007 CEST53546121.1.1.1192.168.11.20
                Jul 11, 2023 17:41:24.449915886 CEST621901900192.168.11.20239.255.255.250
                Jul 11, 2023 17:41:25.262794018 CEST4925153192.168.11.201.1.1.1
                Jul 11, 2023 17:41:25.275032997 CEST53492511.1.1.1192.168.11.20
                Jul 11, 2023 17:41:26.336528063 CEST5231553192.168.11.201.1.1.1
                Jul 11, 2023 17:41:26.345886946 CEST53523151.1.1.1192.168.11.20
                Jul 11, 2023 17:41:26.536489010 CEST5111353192.168.11.201.1.1.1
                Jul 11, 2023 17:41:27.075735092 CEST53511131.1.1.1192.168.11.20
                Jul 11, 2023 17:41:27.226675987 CEST5863753192.168.11.201.1.1.1
                Jul 11, 2023 17:41:27.823784113 CEST53586371.1.1.1192.168.11.20
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Jul 11, 2023 17:41:21.419178963 CEST192.168.11.201.1.1.10xeb1Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:21.419770002 CEST192.168.11.201.1.1.10x5adaStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:23.470927000 CEST192.168.11.201.1.1.10x53d7Standard query (0)smenet.orgA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:25.262794018 CEST192.168.11.201.1.1.10x1d4Standard query (0)www.smenet.orgA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:26.336528063 CEST192.168.11.201.1.1.10x4631Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:26.536489010 CEST192.168.11.201.1.1.10x2ee1Standard query (0)xx6v1x.caobatours.comA (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:27.226675987 CEST192.168.11.201.1.1.10xf651Standard query (0)yylinvaant.bureaurid.techA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Jul 11, 2023 17:41:21.428889990 CEST1.1.1.1192.168.11.200x5adaNo error (0)accounts.google.com142.250.185.77A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:21.428946972 CEST1.1.1.1192.168.11.200xeb1No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Jul 11, 2023 17:41:21.428946972 CEST1.1.1.1192.168.11.200xeb1No error (0)clients.l.google.com216.58.212.142A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:23.483186007 CEST1.1.1.1192.168.11.200x53d7No error (0)smenet.org40.69.190.41A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:25.275032997 CEST1.1.1.1192.168.11.200x1d4No error (0)www.smenet.orgsmenet.orgCNAME (Canonical name)IN (0x0001)false
                Jul 11, 2023 17:41:25.275032997 CEST1.1.1.1192.168.11.200x1d4No error (0)smenet.org40.69.190.41A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:26.345886946 CEST1.1.1.1192.168.11.200x4631No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:27.075735092 CEST1.1.1.1192.168.11.200x2ee1No error (0)xx6v1x.caobatours.com185.244.151.84A (IP address)IN (0x0001)false
                Jul 11, 2023 17:41:27.823784113 CEST1.1.1.1192.168.11.200xf651No error (0)yylinvaant.bureaurid.tech199.192.25.226A (IP address)IN (0x0001)false
                • login.live.com
                • accounts.google.com
                • clients2.google.com
                • smenet.org
                • www.smenet.org
                • xx6v1x.caobatours.com
                  • yylinvaant.bureaurid.tech
                • https:
                • array507.prod.do.dsp.mp.microsoft.com

                Click to jump to process

                Target ID:0
                Start time:17:41:19
                Start date:11/07/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff7a3a80000
                File size:2'509'656 bytes
                MD5 hash:464953824E644F10FFDC9E093FD18F94
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:17:41:20
                Start date:11/07/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1676,5534151309402295221,11728340676976103501,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 /prefetch:8
                Imagebase:0x7ff7a3a80000
                File size:2'509'656 bytes
                MD5 hash:464953824E644F10FFDC9E093FD18F94
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:4
                Start time:17:41:22
                Start date:11/07/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://smenet.org/ViewSwitcher/SwitchView?mobile=True&returnUrl=http://xx6v1x.caobatours.com#YXRvbC5vbmxpbmVAY2FhLmNvLnVr
                Imagebase:0x7ff7a3a80000
                File size:2'509'656 bytes
                MD5 hash:464953824E644F10FFDC9E093FD18F94
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly