Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784

Overview

General Information

Sample URL:https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784
Analysis ID:1417297
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4948 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3496 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1960,i,1723251391280396206,2162911915079263973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6408 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.41.168.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.41.168.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.41.168.93
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784 HTTP/1.1Host: mariosmotorcentremw.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mariosmotorcentremw.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: mariosmotorcentremw.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 21:21:29 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.41.168.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.41.168.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1960,i,1723251391280396206,2162911915079263973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1960,i,1723251391280396206,2162911915079263973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo07840%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://mariosmotorcentremw.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.253.115.103
truefalse
    high
    mariosmotorcentremw.com
    41.216.228.28
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://mariosmotorcentremw.com/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          172.253.115.103
          www.google.comUnited States
          15169GOOGLEUSfalse
          41.216.228.28
          mariosmotorcentremw.comMalawi
          37098globe-asMWfalse
          IP
          192.168.2.16
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1417297
          Start date and time:2024-03-28 22:20:39 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 2s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/4@4/5
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 172.253.63.94, 172.253.115.84, 142.251.16.102, 142.251.16.100, 142.251.16.101, 142.251.16.138, 142.251.16.139, 142.251.16.113, 34.104.35.123, 40.68.123.157, 72.21.81.240, 192.229.211.108, 20.3.187.198, 52.165.164.15, 142.250.31.94
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):10
          Entropy (8bit):1.0
          Encrypted:false
          SSDEEP:3:r+:q
          MD5:E9767BE8092050427FFC3A2F1D4B3B7B
          SHA1:1F83CEEE4822C97DB8FD9AC8BD150BF441F826AC
          SHA-256:9C28A83690B8FC6015BB21B820735507402D8869A7BAE78C3133BCAAD8622433
          SHA-512:1CB81F712FFC7E80783C440B56CCF8E58B151E1E88B18A590A6A7CCEE9F21F2FBAE28D2411F81E746E72A40DDDBF6C4514B70C65D7F49492D3C464D8C62E4E4F
          Malicious:false
          Reputation:low
          URL:https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784
          Preview:..........
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):315
          Entropy (8bit):5.0572271090563765
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
          MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
          SHA1:A82190FC530C265AA40A045C21770D967F4767B8
          SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
          SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
          Malicious:false
          Reputation:low
          URL:https://mariosmotorcentremw.com/favicon.ico
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 22:21:21.079276085 CET49675443192.168.2.4173.222.162.32
          Mar 28, 2024 22:21:21.360563040 CET49678443192.168.2.4104.46.162.224
          Mar 28, 2024 22:21:27.906966925 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907023907 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:27.907092094 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907474995 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907495975 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:27.907707930 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907726049 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:27.907742977 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907891035 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:27.907902956 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.611603975 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.611857891 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.611875057 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.612811089 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.612879038 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.613825083 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.613886118 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.614034891 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.614041090 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.615036011 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.615230083 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.615252972 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.616142988 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.616194010 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.616945028 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.617002010 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.656883001 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.656949997 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:28.656961918 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:28.704209089 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:29.921567917 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:29.921644926 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:29.921694994 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:29.926218987 CET49736443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:29.926230907 CET4434973641.216.228.28192.168.2.4
          Mar 28, 2024 22:21:30.010190010 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:30.056233883 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:30.361006021 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:30.361072063 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:30.361126900 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:30.361771107 CET49735443192.168.2.441.216.228.28
          Mar 28, 2024 22:21:30.361787081 CET4434973541.216.228.28192.168.2.4
          Mar 28, 2024 22:21:30.568821907 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.568876028 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.569979906 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.573648930 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.573664904 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.687922001 CET49675443192.168.2.4173.222.162.32
          Mar 28, 2024 22:21:30.792823076 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.805809975 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.805834055 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.806716919 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.806837082 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.819489002 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.819550991 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.859805107 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:30.859822989 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:30.906888008 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:31.094088078 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.094120979 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.097815037 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.101650000 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.101661921 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.314316034 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.314456940 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.317974091 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.317981958 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.318200111 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.359877110 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.361202955 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.408235073 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.512383938 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.512422085 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.512464046 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.512521029 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.512531996 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.512542009 CET49740443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.512546062 CET4434974023.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.552149057 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.552175045 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.552239895 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.552459955 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.552480936 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.760699987 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.760771036 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.762989044 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.762996912 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.763248920 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.765731096 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.808238029 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.963311911 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.963354111 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.963398933 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.964838982 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.964858055 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:31.964876890 CET49741443192.168.2.423.41.168.93
          Mar 28, 2024 22:21:31.964883089 CET4434974123.41.168.93192.168.2.4
          Mar 28, 2024 22:21:40.792377949 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:40.792431116 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:21:40.792649984 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:42.321676970 CET49739443192.168.2.4172.253.115.103
          Mar 28, 2024 22:21:42.321712017 CET44349739172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.503586054 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:30.503633022 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.503704071 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:30.504368067 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:30.504380941 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.710272074 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.710549116 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:30.710565090 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.710858107 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.711163998 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:30.711216927 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:30.750607967 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:40.760967970 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:40.761038065 CET44349750172.253.115.103192.168.2.4
          Mar 28, 2024 22:22:40.761198997 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:42.330250978 CET49750443192.168.2.4172.253.115.103
          Mar 28, 2024 22:22:42.330282927 CET44349750172.253.115.103192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 22:21:26.132818937 CET53553521.1.1.1192.168.2.4
          Mar 28, 2024 22:21:26.134706020 CET53569511.1.1.1192.168.2.4
          Mar 28, 2024 22:21:26.774816990 CET53546401.1.1.1192.168.2.4
          Mar 28, 2024 22:21:27.505850077 CET6335653192.168.2.41.1.1.1
          Mar 28, 2024 22:21:27.505960941 CET5044353192.168.2.41.1.1.1
          Mar 28, 2024 22:21:27.851476908 CET53633561.1.1.1192.168.2.4
          Mar 28, 2024 22:21:28.125824928 CET53504431.1.1.1192.168.2.4
          Mar 28, 2024 22:21:30.451569080 CET5853853192.168.2.41.1.1.1
          Mar 28, 2024 22:21:30.453330040 CET6299953192.168.2.41.1.1.1
          Mar 28, 2024 22:21:30.547244072 CET53585381.1.1.1192.168.2.4
          Mar 28, 2024 22:21:30.547858953 CET53629991.1.1.1192.168.2.4
          Mar 28, 2024 22:21:43.973424911 CET53613381.1.1.1192.168.2.4
          Mar 28, 2024 22:21:51.880614996 CET138138192.168.2.4192.168.2.255
          Mar 28, 2024 22:22:02.766379118 CET53630261.1.1.1192.168.2.4
          Mar 28, 2024 22:22:25.550914049 CET53624741.1.1.1192.168.2.4
          Mar 28, 2024 22:22:25.943103075 CET53581161.1.1.1192.168.2.4
          TimestampSource IPDest IPChecksumCodeType
          Mar 28, 2024 22:21:28.125911951 CET192.168.2.41.1.1.1c222(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 28, 2024 22:21:27.505850077 CET192.168.2.41.1.1.10x208Standard query (0)mariosmotorcentremw.comA (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:27.505960941 CET192.168.2.41.1.1.10x6d66Standard query (0)mariosmotorcentremw.com65IN (0x0001)false
          Mar 28, 2024 22:21:30.451569080 CET192.168.2.41.1.1.10x3a3cStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.453330040 CET192.168.2.41.1.1.10x9499Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 28, 2024 22:21:27.851476908 CET1.1.1.1192.168.2.40x208No error (0)mariosmotorcentremw.com41.216.228.28A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.103A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.99A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.104A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.105A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.147A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547244072 CET1.1.1.1192.168.2.40x3a3cNo error (0)www.google.com172.253.115.106A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:30.547858953 CET1.1.1.1192.168.2.40x9499No error (0)www.google.com65IN (0x0001)false
          Mar 28, 2024 22:21:44.345535994 CET1.1.1.1192.168.2.40x7281No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 22:21:44.345535994 CET1.1.1.1192.168.2.40x7281No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 22:21:57.100625038 CET1.1.1.1192.168.2.40x911bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 22:21:57.100625038 CET1.1.1.1192.168.2.40x911bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 22:22:17.862585068 CET1.1.1.1192.168.2.40xd206No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 22:22:17.862585068 CET1.1.1.1192.168.2.40xd206No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 22:22:38.552419901 CET1.1.1.1192.168.2.40x368bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 22:22:38.552419901 CET1.1.1.1192.168.2.40x368bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • mariosmotorcentremw.com
          • https:
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44973641.216.228.284433496C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-03-28 21:21:28 UTC722OUTGET /event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784 HTTP/1.1
          Host: mariosmotorcentremw.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-03-28 21:21:29 UTC159INHTTP/1.1 200 OK
          Date: Thu, 28 Mar 2024 21:21:28 GMT
          Server: Apache
          Connection: close
          Transfer-Encoding: chunked
          Content-Type: text/html; charset=UTF-8
          2024-03-28 21:21:29 UTC20INData Raw: 61 0d 0a 0d 0a 0d 0a 0d 0a 0d 0a 0d 0a 0d 0a 30 0d 0a 0d 0a
          Data Ascii: a0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44973541.216.228.284433496C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-03-28 21:21:30 UTC658OUTGET /favicon.ico HTTP/1.1
          Host: mariosmotorcentremw.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-03-28 21:21:30 UTC164INHTTP/1.1 404 Not Found
          Date: Thu, 28 Mar 2024 21:21:29 GMT
          Server: Apache
          Content-Length: 315
          Connection: close
          Content-Type: text/html; charset=iso-8859-1
          2024-03-28 21:21:30 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.44974023.41.168.93443
          TimestampBytes transferredDirectionData
          2024-03-28 21:21:31 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 21:21:31 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-neu-z1
          Cache-Control: public, max-age=154146
          Date: Thu, 28 Mar 2024 21:21:31 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.44974123.41.168.93443
          TimestampBytes transferredDirectionData
          2024-03-28 21:21:31 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 21:21:31 UTC531INHTTP/1.1 200 OK
          Content-Type: application/octet-stream
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-Azure-Ref: 08K+nYgAAAACXC/Ywsy9UQ60qHfPpvzYzU0pDRURHRTA1MTIAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=154080
          Date: Thu, 28 Mar 2024 21:21:31 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-03-28 21:21:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:22:21:23
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:22:21:24
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1960,i,1723251391280396206,2162911915079263973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:22:21:26
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mariosmotorcentremw.com/event/?fDiXdWv=2fb171-85kkdgz921670-5kd735-17l1165fo0784"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly