Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2F

Overview

General Information

Sample URL:http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P
Analysis ID:1415998
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3512 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 736 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1900,i,2778349078760715129,998919831149617411,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6 HTTP/1.1Host: el.westmichiganhomesearcher.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: el.westmichiganhomesearcher.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6 HTTP/1.1Host: el.westmichiganhomesearcher.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: el.westmichiganhomesearcher.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundserver: nginxdate: Tue, 26 Mar 2024 17:14:51 GMTcontent-type: text/htmlcontent-length: 548connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1900,i,2778349078760715129,998919831149617411,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1900,i,2778349078760715129,998919831149617411,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx60%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://el.westmichiganhomesearcher.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.163.103
truefalse
    high
    LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.com
    3.134.250.255
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        el.westmichiganhomesearcher.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://el.westmichiganhomesearcher.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6false
            unknown
            http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6false
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              3.134.250.255
              LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.comUnited States
              16509AMAZON-02USfalse
              142.251.163.103
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1415998
              Start date and time:2024-03-26 18:14:00 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 56s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@17/4@6/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.253.62.94, 142.251.163.84, 142.251.163.100, 142.251.163.138, 142.251.163.113, 142.251.163.101, 142.251.163.139, 142.251.163.102, 34.104.35.123, 40.127.169.103, 23.207.202.26, 23.207.202.33, 23.207.202.40, 23.207.202.6, 23.207.202.24, 192.229.211.108, 20.166.126.56, 13.85.23.206, 40.68.123.157, 172.253.115.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):291
              Entropy (8bit):4.477778146874743
              Encrypted:false
              SSDEEP:6:qzxUsjMR1X96b2+Ubghxc8le3rn9MGzMd4aa6++Oix9qD:kxBMR1knUkhGXpPoa6++3xMD
              MD5:F0C66914A58FC74FC98A7C9BB4C288F2
              SHA1:3E0E43F567138623CABFF91C14100D144AC56949
              SHA-256:54E173BE753D03B2C163CEBBEE02BE7F4BDC1D6663154D4D60A3833F7BA3436B
              SHA-512:7AEDAEBA112D43E2B2FF845355199A11A141D637C0306155BE2356AE297DF118D2C0D2768D44C35A1D89841DB428E95686E29E9D15DEADF4233F3713893514BF
              Malicious:false
              Reputation:low
              URL:https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6
              Preview:<html><head><title>Wrong Link</title></head><body><h1>Wrong Link</h1><p>You have clicked on an invalid link. Please make sure that you have typed the link correctly. If are copying this link from a mail reader please ensure that you have copied all the lines in the link.</p></body></html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):548
              Entropy (8bit):4.688532577858027
              Encrypted:false
              SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
              MD5:370E16C3B7DBA286CFF055F93B9A94D8
              SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
              SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
              SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
              Malicious:false
              Reputation:low
              URL:https://el.westmichiganhomesearcher.com/favicon.ico
              Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Mar 26, 2024 18:14:43.042264938 CET49678443192.168.2.4104.46.162.224
              Mar 26, 2024 18:14:43.089070082 CET49675443192.168.2.4173.222.162.32
              Mar 26, 2024 18:14:50.459985971 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.460484028 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.507062912 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.567608118 CET80497343.134.250.255192.168.2.4
              Mar 26, 2024 18:14:50.567692041 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.567703009 CET80497353.134.250.255192.168.2.4
              Mar 26, 2024 18:14:50.567778111 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.567951918 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.614850998 CET80497363.134.250.255192.168.2.4
              Mar 26, 2024 18:14:50.614933014 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.675384045 CET80497343.134.250.255192.168.2.4
              Mar 26, 2024 18:14:50.720776081 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.890256882 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.890292883 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:50.890345097 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.890587091 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:50.890599966 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.116250992 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.116579056 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.116611004 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.117582083 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.117656946 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.124006987 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.124077082 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.124236107 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.124243021 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.170027018 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.348368883 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.348434925 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.348493099 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.349461079 CET49739443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.349479914 CET443497393.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.484833956 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.484868050 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.484942913 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.485218048 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.485232115 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.707350969 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.707905054 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.707916021 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.708266020 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.708920956 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.708995104 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.709604979 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.752240896 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.938779116 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.938848972 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:51.938894987 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.942195892 CET49740443192.168.2.43.134.250.255
              Mar 26, 2024 18:14:51.942207098 CET443497403.134.250.255192.168.2.4
              Mar 26, 2024 18:14:52.783982992 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:52.784008980 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:52.784092903 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:52.784503937 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:52.784518003 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:53.042469025 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.042495012 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.042567015 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.044197083 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.044210911 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.244025946 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.244087934 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.250137091 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.250144005 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.250396013 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.290908098 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.409869909 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.452245951 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.514600992 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.514691114 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.514821053 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.515053034 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.515060902 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.515124083 CET49742443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.515129089 CET4434974223.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.566917896 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.566941977 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.567018986 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.567250013 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.567264080 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.762548923 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.762623072 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.763792992 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.763798952 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.764038086 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.765120983 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.812227011 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.952070951 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.952136040 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.952181101 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.952788115 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.952799082 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:53.952810049 CET49743443192.168.2.423.221.242.90
              Mar 26, 2024 18:14:53.952815056 CET4434974323.221.242.90192.168.2.4
              Mar 26, 2024 18:14:54.056451082 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:54.056915045 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:54.056938887 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:54.057991028 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:54.058054924 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:54.065635920 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:54.065701962 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:54.119028091 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:14:54.119036913 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:14:54.165920973 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:00.675463915 CET80497353.134.250.255192.168.2.4
              Mar 26, 2024 18:15:00.675479889 CET80497353.134.250.255192.168.2.4
              Mar 26, 2024 18:15:00.675539970 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:15:00.680331945 CET80497343.134.250.255192.168.2.4
              Mar 26, 2024 18:15:00.680496931 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:15:00.723290920 CET80497363.134.250.255192.168.2.4
              Mar 26, 2024 18:15:00.723304987 CET80497363.134.250.255192.168.2.4
              Mar 26, 2024 18:15:00.723479986 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:15:02.159135103 CET4973480192.168.2.43.134.250.255
              Mar 26, 2024 18:15:02.266546011 CET80497343.134.250.255192.168.2.4
              Mar 26, 2024 18:15:04.074419975 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:04.074492931 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:04.074584007 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:04.629678965 CET49741443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:04.629703999 CET44349741142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:45.686578989 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:15:45.728382111 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:15:45.793534040 CET80497353.134.250.255192.168.2.4
              Mar 26, 2024 18:15:45.835728884 CET80497363.134.250.255192.168.2.4
              Mar 26, 2024 18:15:50.656686068 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:15:50.656721115 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:15:50.656739950 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:15:50.656765938 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:15:50.763849974 CET80497353.134.250.255192.168.2.4
              Mar 26, 2024 18:15:50.764211893 CET80497363.134.250.255192.168.2.4
              Mar 26, 2024 18:15:50.764282942 CET4973580192.168.2.43.134.250.255
              Mar 26, 2024 18:15:50.764653921 CET4973680192.168.2.43.134.250.255
              Mar 26, 2024 18:15:52.730302095 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:52.730335951 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:52.730499029 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:52.730726957 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:52.730745077 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:52.996126890 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:52.996593952 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:52.996609926 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:52.996896029 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:52.997508049 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:15:52.997556925 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:15:53.040896893 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:16:01.997097015 CET4972480192.168.2.472.21.81.240
              Mar 26, 2024 18:16:01.997097015 CET4972380192.168.2.472.21.81.240
              Mar 26, 2024 18:16:02.091403961 CET804972372.21.81.240192.168.2.4
              Mar 26, 2024 18:16:02.091561079 CET4972380192.168.2.472.21.81.240
              Mar 26, 2024 18:16:02.091634035 CET804972472.21.81.240192.168.2.4
              Mar 26, 2024 18:16:02.091744900 CET4972480192.168.2.472.21.81.240
              Mar 26, 2024 18:16:03.017292023 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:16:03.017349958 CET44349752142.251.163.103192.168.2.4
              Mar 26, 2024 18:16:03.017395973 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:16:04.593517065 CET49752443192.168.2.4142.251.163.103
              Mar 26, 2024 18:16:04.593547106 CET44349752142.251.163.103192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Mar 26, 2024 18:14:48.291663885 CET53500651.1.1.1192.168.2.4
              Mar 26, 2024 18:14:48.339168072 CET53505081.1.1.1192.168.2.4
              Mar 26, 2024 18:14:49.125994921 CET53599181.1.1.1192.168.2.4
              Mar 26, 2024 18:14:50.235912085 CET5413253192.168.2.41.1.1.1
              Mar 26, 2024 18:14:50.236129045 CET6216453192.168.2.41.1.1.1
              Mar 26, 2024 18:14:50.401299000 CET53621641.1.1.1192.168.2.4
              Mar 26, 2024 18:14:50.459274054 CET53541321.1.1.1192.168.2.4
              Mar 26, 2024 18:14:50.677331924 CET5269553192.168.2.41.1.1.1
              Mar 26, 2024 18:14:50.677484989 CET6510953192.168.2.41.1.1.1
              Mar 26, 2024 18:14:50.841475010 CET53526951.1.1.1192.168.2.4
              Mar 26, 2024 18:14:50.889713049 CET53651091.1.1.1192.168.2.4
              Mar 26, 2024 18:14:52.677483082 CET5586653192.168.2.41.1.1.1
              Mar 26, 2024 18:14:52.677602053 CET6376353192.168.2.41.1.1.1
              Mar 26, 2024 18:14:52.774236917 CET53558661.1.1.1192.168.2.4
              Mar 26, 2024 18:14:52.774698973 CET53637631.1.1.1192.168.2.4
              Mar 26, 2024 18:15:06.248382092 CET53556921.1.1.1192.168.2.4
              Mar 26, 2024 18:15:13.562081099 CET138138192.168.2.4192.168.2.255
              Mar 26, 2024 18:15:25.394382000 CET53640301.1.1.1192.168.2.4
              Mar 26, 2024 18:15:47.949367046 CET53586401.1.1.1192.168.2.4
              Mar 26, 2024 18:15:48.397969961 CET53573301.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 26, 2024 18:14:50.235912085 CET192.168.2.41.1.1.10x5674Standard query (0)el.westmichiganhomesearcher.comA (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.236129045 CET192.168.2.41.1.1.10xc08bStandard query (0)el.westmichiganhomesearcher.com65IN (0x0001)false
              Mar 26, 2024 18:14:50.677331924 CET192.168.2.41.1.1.10xca42Standard query (0)el.westmichiganhomesearcher.comA (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.677484989 CET192.168.2.41.1.1.10x754fStandard query (0)el.westmichiganhomesearcher.com65IN (0x0001)false
              Mar 26, 2024 18:14:52.677483082 CET192.168.2.41.1.1.10xa4ceStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.677602053 CET192.168.2.41.1.1.10x9dd5Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 26, 2024 18:14:50.401299000 CET1.1.1.1192.168.2.40xc08bNo error (0)el.westmichiganhomesearcher.comel.cincpro.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.401299000 CET1.1.1.1192.168.2.40xc08bNo error (0)el.cincpro.comLoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.459274054 CET1.1.1.1192.168.2.40x5674No error (0)el.westmichiganhomesearcher.comel.cincpro.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.459274054 CET1.1.1.1192.168.2.40x5674No error (0)el.cincpro.comLoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.459274054 CET1.1.1.1192.168.2.40x5674No error (0)LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.com3.134.250.255A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.459274054 CET1.1.1.1192.168.2.40x5674No error (0)LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.com3.139.145.136A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.841475010 CET1.1.1.1192.168.2.40xca42No error (0)el.westmichiganhomesearcher.comel.cincpro.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.841475010 CET1.1.1.1192.168.2.40xca42No error (0)el.cincpro.comLoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.841475010 CET1.1.1.1192.168.2.40xca42No error (0)LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.com3.134.250.255A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.841475010 CET1.1.1.1192.168.2.40xca42No error (0)LoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.com3.139.145.136A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:50.889713049 CET1.1.1.1192.168.2.40x754fNo error (0)el.westmichiganhomesearcher.comel.cincpro.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:50.889713049 CET1.1.1.1192.168.2.40x754fNo error (0)el.cincpro.comLoadBalancer-ed4b8f4192111844.elb.us-east-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.103A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.105A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.104A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.106A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.99A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774236917 CET1.1.1.1192.168.2.40xa4ceNo error (0)www.google.com142.251.163.147A (IP address)IN (0x0001)false
              Mar 26, 2024 18:14:52.774698973 CET1.1.1.1192.168.2.40x9dd5No error (0)www.google.com65IN (0x0001)false
              Mar 26, 2024 18:15:06.648299932 CET1.1.1.1192.168.2.40x702fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:15:06.648299932 CET1.1.1.1192.168.2.40x702fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Mar 26, 2024 18:15:19.292664051 CET1.1.1.1192.168.2.40xdf29No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:15:19.292664051 CET1.1.1.1192.168.2.40xdf29No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Mar 26, 2024 18:15:40.497731924 CET1.1.1.1192.168.2.40x79f8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Mar 26, 2024 18:15:40.497731924 CET1.1.1.1192.168.2.40x79f8No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • el.westmichiganhomesearcher.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.4497343.134.250.25580736C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Mar 26, 2024 18:14:50.567951918 CET726OUTGET /ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6 HTTP/1.1
              Host: el.westmichiganhomesearcher.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Mar 26, 2024 18:14:50.675384045 CET385INHTTP/1.1 301 Moved Permanently
              content-length: 0
              location: https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.4497353.134.250.25580736C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Mar 26, 2024 18:15:00.675463915 CET233INHTTP/1.1 408 Request Time-out
              Content-length: 110
              Cache-Control: no-cache
              Connection: close
              Content-Type: text/html
              Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
              Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
              Mar 26, 2024 18:15:45.686578989 CET6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.4497363.134.250.25580736C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Mar 26, 2024 18:15:00.723290920 CET233INHTTP/1.1 408 Request Time-out
              Content-length: 110
              Cache-Control: no-cache
              Connection: close
              Content-Type: text/html
              Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
              Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
              Mar 26, 2024 18:15:45.728382111 CET6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.4497393.134.250.255443736C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-03-26 17:14:51 UTC954OUTGET /ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6 HTTP/1.1
              Host: el.westmichiganhomesearcher.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-03-26 17:14:51 UTC193INHTTP/1.1 400 Bad Request
              server: nginx
              date: Tue, 26 Mar 2024 17:14:51 GMT
              content-type: text/html; charset=utf-8
              content-length: 291
              x-robots-tag: noindex, nofollow
              connection: close
              2024-03-26 17:14:51 UTC291INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 57 72 6f 6e 67 20 4c 69 6e 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 68 31 3e 57 72 6f 6e 67 20 4c 69 6e 6b 3c 2f 68 31 3e 3c 70 3e 59 6f 75 20 68 61 76 65 20 63 6c 69 63 6b 65 64 20 6f 6e 20 61 6e 20 69 6e 76 61 6c 69 64 20 6c 69 6e 6b 2e 20 20 50 6c 65 61 73 65 20 6d 61 6b 65 20 73 75 72 65 20 74 68 61 74 20 79 6f 75 20 68 61 76 65 20 74 79 70 65 64 20 74 68 65 20 6c 69 6e 6b 20 63 6f 72 72 65 63 74 6c 79 2e 20 20 49 66 20 61 72 65 20 63 6f 70 79 69 6e 67 20 74 68 69 73 20 6c 69 6e 6b 20 66 72 6f 6d 20 61 20 6d 61 69 6c 20 72 65 61 64 65 72 20 70 6c 65 61 73 65 20 65 6e 73 75 72 65 20 74 68 61 74 20 79 6f 75 20 68 61 76 65 20 63 6f 70 69 65 64 20 61 6c 6c 20 74 68 65 20
              Data Ascii: <html><head><title>Wrong Link</title></head><body><h1>Wrong Link</h1><p>You have clicked on an invalid link. Please make sure that you have typed the link correctly. If are copying this link from a mail reader please ensure that you have copied all the


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.4497403.134.250.255443736C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-03-26 17:14:51 UTC898OUTGET /favicon.ico HTTP/1.1
              Host: el.westmichiganhomesearcher.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-03-26 17:14:51 UTC143INHTTP/1.1 404 Not Found
              server: nginx
              date: Tue, 26 Mar 2024 17:14:51 GMT
              content-type: text/html
              content-length: 548
              connection: close
              2024-03-26 17:14:51 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
              Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974223.221.242.90443
              TimestampBytes transferredDirectionData
              2024-03-26 17:14:53 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-03-26 17:14:53 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/073D)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=136192
              Date: Tue, 26 Mar 2024 17:14:53 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44974323.221.242.90443
              TimestampBytes transferredDirectionData
              2024-03-26 17:14:53 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-03-26 17:14:53 UTC774INHTTP/1.1 200 OK
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-CID: 7
              X-CCC: US
              X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
              X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
              Content-Type: application/octet-stream
              X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=136147
              Date: Tue, 26 Mar 2024 17:14:53 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-03-26 17:14:53 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:15:14:44
              Start date:26/03/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:15:14:46
              Start date:26/03/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1900,i,2778349078760715129,998919831149617411,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:15:14:49
              Start date:26/03/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://el.westmichiganhomesearcher.com/ls/click?upn=u001.K3ZIliMUvblbn2IjRVO9NcUXFuHoatxO1Wut7fqa-2FwWrwjI-2FRVWEUl4w0J3zZL8NAeEQmUx1BV7J203sr-2F0auKc2UEOCcG7Vvnx-2FQ6-2F2A-2Bj8m1fj-2B2O-2B5UOmvGQON9P2hL1O28JIwXBHgWPQrO2pt07XyGBhTp4kpb4bFfj1DRoIipcPlJRtuSb5JIBXv9mSLlKgKhaDOkmtikPs6aiNUypvxyqaV8po-2FrlRc9pQH7vxvsPjQGx6"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly