Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://aeno.co.jp.talglfts.cc/aeon

Overview

General Information

Sample URL:https://aeno.co.jp.talglfts.cc/aeon
Analysis ID:1428485
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 4248 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2016,i,14745735436949683847,4867058927726840083,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aeno.co.jp.talglfts.cc/aeon" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: aeno.co.jp.talglfts.ccVirustotal: Detection: 7%Perma Link
Source: https://aeno.co.jp.talglfts.cc/aeonVirustotal: Detection: 9%Perma Link
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /aeon HTTP/1.1Host: aeno.co.jp.talglfts.ccConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: aeno.co.jp.talglfts.cc
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: classification engineClassification label: mal56.win@20/0@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2016,i,14745735436949683847,4867058927726840083,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aeno.co.jp.talglfts.cc/aeon"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2016,i,14745735436949683847,4867058927726840083,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://aeno.co.jp.talglfts.cc/aeon10%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
aeno.co.jp.talglfts.cc8%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
aeno.co.jp.talglfts.cc
150.109.196.190
truefalseunknown
www.google.com
142.251.15.99
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://aeno.co.jp.talglfts.cc/aeontrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.251.15.99
      www.google.comUnited States
      15169GOOGLEUSfalse
      150.109.196.190
      aeno.co.jp.talglfts.ccSingapore
      132203TENCENT-NET-AP-CNTencentBuildingKejizhongyiAvenueCNfalse
      IP
      192.168.2.4
      127.0.0.1
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1428485
      Start date and time:2024-04-19 02:01:45 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 7s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://aeno.co.jp.talglfts.cc/aeon
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal56.win@20/0@4/5
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.253.124.94, 64.233.185.101, 64.233.185.113, 64.233.185.138, 64.233.185.139, 64.233.185.102, 64.233.185.100, 142.250.105.84, 34.104.35.123, 20.114.59.183, 72.21.81.240, 192.229.211.108, 20.3.187.198, 13.85.23.206, 142.250.9.94
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 19, 2024 02:02:27.981412888 CEST49675443192.168.2.4173.222.162.32
      Apr 19, 2024 02:02:28.293940067 CEST49678443192.168.2.4104.46.162.224
      Apr 19, 2024 02:02:35.804850101 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.804909945 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:35.805012941 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.805253983 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.805329084 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:35.805387020 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.805463076 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.805476904 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:35.805691957 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:35.805710077 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.322738886 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.323082924 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.323120117 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.324527979 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.324708939 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.326190948 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.330609083 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.330754042 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.330868006 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.330890894 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.331125975 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.331141949 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.332034111 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.332122087 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.333427906 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.333517075 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.373742104 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.373743057 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:36.373784065 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:36.424546957 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:37.070261002 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:37.070348024 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:37.070401907 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:37.073560953 CEST49736443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:37.073590040 CEST44349736150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:37.582010984 CEST49675443192.168.2.4173.222.162.32
      Apr 19, 2024 02:02:38.224498987 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.224574089 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.224803925 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.226020098 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.226037025 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.442759037 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.446717024 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.446752071 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.447942019 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.448034048 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.453632116 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.453747988 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.495548010 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.495580912 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:38.542433023 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:38.696928978 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:38.696980000 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:38.697151899 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:38.702203035 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:38.702233076 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:38.924011946 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:38.924094915 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:38.927481890 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:38.927503109 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:38.927934885 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:38.979790926 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.012406111 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.060128927 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.125838995 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.125938892 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.125991106 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.126126051 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.126138926 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.126149893 CEST49744443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.126153946 CEST4434974423.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.178181887 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.178260088 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.178354025 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.179514885 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.179528952 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.393882990 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.393982887 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.395390034 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.395405054 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.395896912 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.396986008 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.440140963 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.601020098 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.601144075 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.601218939 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.602147102 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.602174044 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:39.602185965 CEST49745443192.168.2.423.36.68.63
      Apr 19, 2024 02:02:39.602191925 CEST4434974523.36.68.63192.168.2.4
      Apr 19, 2024 02:02:48.462097883 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:48.462162971 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:48.462378025 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:50.166786909 CEST49743443192.168.2.4142.251.15.99
      Apr 19, 2024 02:02:50.166837931 CEST44349743142.251.15.99192.168.2.4
      Apr 19, 2024 02:02:56.603195906 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:56.603300095 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:02:56.603418112 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:58.097053051 CEST49735443192.168.2.4150.109.196.190
      Apr 19, 2024 02:02:58.097131968 CEST44349735150.109.196.190192.168.2.4
      Apr 19, 2024 02:03:38.157469034 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:38.157531977 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.161624908 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:38.165400028 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:38.165420055 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.382740021 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.383054018 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:38.383089066 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.383469105 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.383836031 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:38.383898020 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:38.436630964 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:48.393076897 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:48.393162966 CEST44349772142.251.15.99192.168.2.4
      Apr 19, 2024 02:03:48.393213987 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:50.093445063 CEST49772443192.168.2.4142.251.15.99
      Apr 19, 2024 02:03:50.093492031 CEST44349772142.251.15.99192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 19, 2024 02:02:33.891482115 CEST53622921.1.1.1192.168.2.4
      Apr 19, 2024 02:02:33.975141048 CEST53645771.1.1.1192.168.2.4
      Apr 19, 2024 02:02:34.567413092 CEST53520551.1.1.1192.168.2.4
      Apr 19, 2024 02:02:35.640372038 CEST5379653192.168.2.41.1.1.1
      Apr 19, 2024 02:02:35.640505075 CEST5260153192.168.2.41.1.1.1
      Apr 19, 2024 02:02:35.790216923 CEST53526011.1.1.1192.168.2.4
      Apr 19, 2024 02:02:35.803956985 CEST53537961.1.1.1192.168.2.4
      Apr 19, 2024 02:02:38.107259035 CEST5849353192.168.2.41.1.1.1
      Apr 19, 2024 02:02:38.107417107 CEST6334053192.168.2.41.1.1.1
      Apr 19, 2024 02:02:38.211488008 CEST53584931.1.1.1192.168.2.4
      Apr 19, 2024 02:02:38.212796926 CEST53633401.1.1.1192.168.2.4
      Apr 19, 2024 02:02:53.243663073 CEST53548731.1.1.1192.168.2.4
      Apr 19, 2024 02:02:58.842506886 CEST138138192.168.2.4192.168.2.255
      Apr 19, 2024 02:03:12.274010897 CEST53624891.1.1.1192.168.2.4
      Apr 19, 2024 02:03:33.521708012 CEST53637721.1.1.1192.168.2.4
      Apr 19, 2024 02:03:34.963125944 CEST53528281.1.1.1192.168.2.4
      Apr 19, 2024 02:04:01.664001942 CEST53613961.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 19, 2024 02:02:35.640372038 CEST192.168.2.41.1.1.10xc148Standard query (0)aeno.co.jp.talglfts.ccA (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:35.640505075 CEST192.168.2.41.1.1.10x549eStandard query (0)aeno.co.jp.talglfts.cc65IN (0x0001)false
      Apr 19, 2024 02:02:38.107259035 CEST192.168.2.41.1.1.10x5d14Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.107417107 CEST192.168.2.41.1.1.10xd21Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 19, 2024 02:02:35.803956985 CEST1.1.1.1192.168.2.40xc148No error (0)aeno.co.jp.talglfts.cc150.109.196.190A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.99A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.147A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.106A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.103A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.104A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.211488008 CEST1.1.1.1192.168.2.40x5d14No error (0)www.google.com142.251.15.105A (IP address)IN (0x0001)false
      Apr 19, 2024 02:02:38.212796926 CEST1.1.1.1192.168.2.40xd21No error (0)www.google.com65IN (0x0001)false
      Apr 19, 2024 02:02:52.107980967 CEST1.1.1.1192.168.2.40xe2a4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 19, 2024 02:02:52.107980967 CEST1.1.1.1192.168.2.40xe2a4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 19, 2024 02:03:04.852199078 CEST1.1.1.1192.168.2.40x5a5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 19, 2024 02:03:04.852199078 CEST1.1.1.1192.168.2.40x5a5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 19, 2024 02:03:27.368762970 CEST1.1.1.1192.168.2.40x5ebNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 19, 2024 02:03:27.368762970 CEST1.1.1.1192.168.2.40x5ebNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 19, 2024 02:03:46.362133980 CEST1.1.1.1192.168.2.40x4fcaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 19, 2024 02:03:46.362133980 CEST1.1.1.1192.168.2.40x4fcaNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • aeno.co.jp.talglfts.cc
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449736150.109.196.1904434520C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-19 00:02:36 UTC669OUTGET /aeon HTTP/1.1
      Host: aeno.co.jp.talglfts.cc
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-04-19 00:02:37 UTC665INHTTP/1.1 302 Found
      Date: Fri, 19 Apr 2024 00:02:36 GMT
      Server: Apache
      Expires: Thu, 19 Nov 1981 08:52:00 GMT
      Cache-Control: no-store, no-cache, must-revalidate
      Pragma: no-cache
      Set-Cookie: PHPSESSID=oijtpr285ldntsi08rt1lk56v6; path=/
      Access-Control-Allow-Origin: *
      Access-Control-Allow-Methods: GET,POST,OPTIONS,PUT,DELETE
      Content-Security-Policy: frame-ancestors 'none'
      X-Content-Type-Options: nosniff
      X-Dns-Prefetch-Control: off
      X-Frame-Options: SAMEORIGIN
      x-xss-protection: 1; mode=block
      Upgrade-Insecure-Requests: 1
      Upgrade: h2
      Connection: Upgrade, close
      Location: http://localhost
      Content-Length: 0
      Content-Type: text/html; charset=UTF-8


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974423.36.68.63443
      TimestampBytes transferredDirectionData
      2024-04-19 00:02:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-19 00:02:39 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0758)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=198069
      Date: Fri, 19 Apr 2024 00:02:39 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.44974523.36.68.63443
      TimestampBytes transferredDirectionData
      2024-04-19 00:02:39 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-19 00:02:39 UTC531INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=198067
      Date: Fri, 19 Apr 2024 00:02:39 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-19 00:02:39 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:02:02:29
      Start date:19/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:02:02:31
      Start date:19/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2016,i,14745735436949683847,4867058927726840083,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:02:02:34
      Start date:19/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aeno.co.jp.talglfts.cc/aeon"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly