Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriΡtionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQub

Overview

General Information

Sample URL:https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriΡtionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=2
Analysis ID:1604910
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected suspicious crossdomain redirect

Classification

  • System is w10x64
  • chrome.exe (PID: 5064 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 560 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,8152583084134761886,11834052594652706973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6616 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.htmlAvira URL Cloud: Label: phishing
Source: https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/favicon.icoAvira URL Cloud: Label: malware
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: f6p4fxqv.r.us-east-1.awstrack.me to https://www.penguinrandomhouse.com/singlepref/unsubscribe?subscriptionguid=69f89be7d7330ce7e0534fd66b0aef04&preferenceid=85001&preferencekey=26961&target=https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html#dmfoawqubwfszwtpqgfyewfzyxnvbc5jb20=
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410 HTTP/1.1Host: f6p4fxqv.r.us-east-1.awstrack.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /singlepref/unsubscribe?SubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04&PreferenceId=85001&PreferenceKey=26961&target=https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html HTTP/1.1Host: www.penguinrandomhouse.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /b4.html HTTP/1.1Host: ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: f6p4fxqv.r.us-east-1.awstrack.me
Source: global trafficDNS traffic detected: DNS query: www.penguinrandomhouse.com
Source: global trafficDNS traffic detected: DNS query: ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sun, 02 Feb 2025 05:26:14 GMTContent-Type: application/xmlContent-Length: 244Connection: closex-amz-request-id: tx000000a4093a9823ab7a9-00679f01f6-9c36dd7d-defaultAccept-Ranges: bytes
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sun, 02 Feb 2025 05:26:15 GMTContent-Type: application/xmlContent-Length: 244Connection: closex-amz-request-id: tx000005c160596e33b47b3-00679f01f7-9bc92673-defaultAccept-Ranges: bytes
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: classification engineClassification label: mal48.win@17/4@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,8152583084134761886,11834052594652706973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,8152583084134761886,11834052594652706973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=4100%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html100%Avira URL Cloudphishing
https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
www.penguinrandomhouse.com
13.32.99.20
truefalse
    high
    us-lax-1.linodeobjects.com.akadns.net
    172.233.158.186
    truefalse
      unknown
      www.google.com
      142.250.185.68
      truefalse
        high
        baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com
        34.199.56.108
        truefalse
          high
          ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com
          unknown
          unknownfalse
            unknown
            f6p4fxqv.r.us-east-1.awstrack.me
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.htmlfalse
              • Avira URL Cloud: phishing
              unknown
              https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410false
                unknown
                https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/favicon.icofalse
                • Avira URL Cloud: malware
                unknown
                https://www.penguinrandomhouse.com/singlepref/unsubscribe?SubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04&PreferenceId=85001&PreferenceKey=26961&target=https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.htmlfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.185.68
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  34.199.56.108
                  baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.comUnited States
                  14618AMAZON-AESUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  13.32.99.20
                  www.penguinrandomhouse.comUnited States
                  16509AMAZON-02USfalse
                  172.233.158.186
                  us-lax-1.linodeobjects.com.akadns.netUnited States
                  20940AKAMAI-ASN1EUfalse
                  IP
                  192.168.2.4
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1604910
                  Start date and time:2025-02-02 06:25:00 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 4s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriΡtionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@17/4@8/6
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.186.163, 142.250.186.110, 108.177.15.84, 216.58.206.78, 142.250.184.206, 142.250.186.174, 199.232.210.172, 2.23.77.188, 142.250.186.78, 142.250.186.46, 172.217.18.14, 142.250.186.142, 142.250.185.142, 216.58.206.67, 142.250.184.238, 184.28.90.27, 172.202.163.200, 13.107.246.45
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                  • Not all processes where analyzed, report is missing behavior information
                  • VT rate limit hit for: https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:XML 1.0 document, ASCII text, with no line terminators
                  Category:downloaded
                  Size (bytes):244
                  Entropy (8bit):5.335804085538883
                  Encrypted:false
                  SSDEEP:6:TMVBd/IqZjvGgnQSIcNzBhi7cK52baKjFan:TMHd1Bv1r+ceGaKa
                  MD5:3B9E7782180561BAC30A884D0AC6263D
                  SHA1:EF05DC79215C53534E6EF7C3D4F00A98B2D07C90
                  SHA-256:9B7BEE9EFC5F710647DFFCF83C3DDC19BDB6ECBC2678B0FF06A71EE2BDC918D5
                  SHA-512:C45D5F2D79092E34132039D7D95BD4C14E8A0DC436D499EE6EC97F8B7D01A68736825DB8F4C5F680066CABA32D8E19F7633F087C193C526DBFC1920F7AD102A2
                  Malicious:false
                  Reputation:low
                  URL:https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/favicon.ico
                  Preview:<?xml version="1.0" encoding="UTF-8"?><Error><Code>UserSuspended</Code><BucketName>ioplkauw-iwiwkkw-29282wjw</BucketName><RequestId>tx000005c160596e33b47b3-00679f01f7-9bc92673-default</RequestId><HostId>9bc92673-default-default</HostId></Error>
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:XML 1.0 document, ASCII text, with no line terminators
                  Category:downloaded
                  Size (bytes):244
                  Entropy (8bit):5.251408988568035
                  Encrypted:false
                  SSDEEP:6:TMVBd/IqZjvGgnQSIcNzBh8iADX52n0DXjFan:TMHd1Bv1reLDpbDZa
                  MD5:0545222634BC006B927D5956E562B79B
                  SHA1:E3B375C3DACBBFB53E4C2DFEAD2C33E0919AB4B1
                  SHA-256:3BE983495A8D3B7BDC23A9C56152D49A460C78D858C5B4A9C32178D75BE20AB1
                  SHA-512:AC4450B5061DD5521C51F81574C995BE0EF8FCB4270D029563E04C81349B4AFE38DAD71ED5820F5D2DD3F9CB8B822BFF91E6FCF730DE4FB6AE016EDE5021F4F5
                  Malicious:false
                  Reputation:low
                  URL:https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html
                  Preview:<?xml version="1.0" encoding="UTF-8"?><Error><Code>UserSuspended</Code><BucketName>ioplkauw-iwiwkkw-29282wjw</BucketName><RequestId>tx000000a4093a9823ab7a9-00679f01f6-9c36dd7d-default</RequestId><HostId>9c36dd7d-default-default</HostId></Error>
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 2, 2025 06:25:50.357917070 CET49675443192.168.2.4173.222.162.32
                  Feb 2, 2025 06:26:00.154783010 CET49675443192.168.2.4173.222.162.32
                  Feb 2, 2025 06:26:03.021334887 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.021383047 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.021455050 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.021686077 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.021699905 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.663616896 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.663996935 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.664016962 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.665056944 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.665126085 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.666661024 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.666738987 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.716026068 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:03.716033936 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:03.762866020 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:06.988765955 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.988797903 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:06.988923073 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.989290953 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.989340067 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:06.989394903 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.989589930 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.989600897 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:06.989664078 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:06.989684105 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.578488111 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.584115982 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.622580051 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.634664059 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.685944080 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.685969114 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.686099052 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.686113119 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.687294006 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.687376022 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.690078020 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.690143108 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.714595079 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.714714050 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.715651989 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.715665102 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.715835094 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.715984106 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.770076990 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.770109892 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.770137072 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.816464901 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.870024920 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.870114088 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.870165110 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.870587111 CET49741443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:07.870609999 CET4434974134.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:07.892015934 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:07.892061949 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:07.892119884 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:07.892338037 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:07.892357111 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.622129917 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.622468948 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:08.622493029 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.623565912 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.623626947 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:08.624967098 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:08.625044107 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.625206947 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:08.625219107 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:08.671902895 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:13.566921949 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:13.566981077 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:13.567059994 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:13.687005043 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:13.687241077 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:13.687335014 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:13.687453985 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:13.687475920 CET4434974313.32.99.20192.168.2.4
                  Feb 2, 2025 06:26:13.687484980 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:13.687527895 CET49743443192.168.2.413.32.99.20
                  Feb 2, 2025 06:26:13.689450979 CET49737443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:26:13.689475060 CET44349737142.250.185.68192.168.2.4
                  Feb 2, 2025 06:26:13.721287966 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:13.721319914 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:13.721410036 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:13.721647024 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:13.721653938 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.052619934 CET4972380192.168.2.4199.232.214.172
                  Feb 2, 2025 06:26:14.057631969 CET8049723199.232.214.172192.168.2.4
                  Feb 2, 2025 06:26:14.057706118 CET4972380192.168.2.4199.232.214.172
                  Feb 2, 2025 06:26:14.310307980 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.310635090 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.310657024 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.312134027 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.312192917 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.313468933 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.313535929 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.313642979 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.313651085 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.364726067 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.529083014 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.529198885 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.529262066 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.530793905 CET49746443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.530808926 CET44349746172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.613486052 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.613543987 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:14.613646030 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.614100933 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:14.614114046 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.227330923 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.227663040 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:15.227688074 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.228209019 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.228564978 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:15.228646994 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.228770971 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:15.275330067 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.541913986 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.542031050 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:15.542092085 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:15.543045998 CET49749443192.168.2.4172.233.158.186
                  Feb 2, 2025 06:26:15.543060064 CET44349749172.233.158.186192.168.2.4
                  Feb 2, 2025 06:26:38.289238930 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:38.289319992 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:26:38.289375067 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:39.265746117 CET49742443192.168.2.434.199.56.108
                  Feb 2, 2025 06:26:39.265760899 CET4434974234.199.56.108192.168.2.4
                  Feb 2, 2025 06:27:02.638631105 CET4972480192.168.2.4199.232.214.172
                  Feb 2, 2025 06:27:02.643779039 CET8049724199.232.214.172192.168.2.4
                  Feb 2, 2025 06:27:02.643872976 CET4972480192.168.2.4199.232.214.172
                  Feb 2, 2025 06:27:03.046261072 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:03.046287060 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.046358109 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:03.046585083 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:03.046595097 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.681323051 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.681732893 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:03.681745052 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.682207108 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.682575941 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:03.682657957 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:03.732192039 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:13.631628990 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:13.631690025 CET44349821142.250.185.68192.168.2.4
                  Feb 2, 2025 06:27:13.631846905 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:15.271820068 CET49821443192.168.2.4142.250.185.68
                  Feb 2, 2025 06:27:15.271836042 CET44349821142.250.185.68192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 2, 2025 06:26:00.840385914 CET53517421.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:00.846944094 CET53517491.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:01.871794939 CET53574551.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:03.003242970 CET5788853192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:03.006810904 CET5394353192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:03.009944916 CET53578881.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:03.013411045 CET53539431.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:06.961822987 CET5122953192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:06.962040901 CET5380253192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:06.969377995 CET53538021.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:06.987925053 CET53512291.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:07.873313904 CET5061553192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:07.873454094 CET5176453192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:07.882965088 CET53517641.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:07.891448021 CET53506151.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:13.690031052 CET4944653192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:13.690262079 CET5873553192.168.2.41.1.1.1
                  Feb 2, 2025 06:26:13.708266020 CET53494461.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:13.736521006 CET53587351.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:14.135574102 CET138138192.168.2.4192.168.2.255
                  Feb 2, 2025 06:26:18.914216042 CET53571401.1.1.1192.168.2.4
                  Feb 2, 2025 06:26:38.006177902 CET53495501.1.1.1192.168.2.4
                  Feb 2, 2025 06:27:00.490498066 CET53615251.1.1.1192.168.2.4
                  Feb 2, 2025 06:27:00.633151054 CET53519121.1.1.1192.168.2.4
                  TimestampSource IPDest IPChecksumCodeType
                  Feb 2, 2025 06:26:13.736597061 CET192.168.2.41.1.1.1c28a(Port unreachable)Destination Unreachable
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 2, 2025 06:26:03.003242970 CET192.168.2.41.1.1.10x818cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:03.006810904 CET192.168.2.41.1.1.10x7ed2Standard query (0)www.google.com65IN (0x0001)false
                  Feb 2, 2025 06:26:06.961822987 CET192.168.2.41.1.1.10xe30aStandard query (0)f6p4fxqv.r.us-east-1.awstrack.meA (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.962040901 CET192.168.2.41.1.1.10x6c1eStandard query (0)f6p4fxqv.r.us-east-1.awstrack.me65IN (0x0001)false
                  Feb 2, 2025 06:26:07.873313904 CET192.168.2.41.1.1.10x48a4Standard query (0)www.penguinrandomhouse.comA (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:07.873454094 CET192.168.2.41.1.1.10x5650Standard query (0)www.penguinrandomhouse.com65IN (0x0001)false
                  Feb 2, 2025 06:26:13.690031052 CET192.168.2.41.1.1.10x70bcStandard query (0)ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.comA (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.690262079 CET192.168.2.41.1.1.10x977bStandard query (0)ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 2, 2025 06:26:03.009944916 CET1.1.1.1192.168.2.40x818cNo error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:03.013411045 CET1.1.1.1192.168.2.40x7ed2No error (0)www.google.com65IN (0x0001)false
                  Feb 2, 2025 06:26:06.969377995 CET1.1.1.1192.168.2.40x6c1eNo error (0)f6p4fxqv.r.us-east-1.awstrack.mer.us-east-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.969377995 CET1.1.1.1192.168.2.40x6c1eNo error (0)r.us-east-1.awstrack.mer.delegate.us-east-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.969377995 CET1.1.1.1192.168.2.40x6c1eNo error (0)r.delegate.us-east-1.awstrack.mebaconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)f6p4fxqv.r.us-east-1.awstrack.mer.us-east-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)r.us-east-1.awstrack.mer.delegate.us-east-1.awstrack.meCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)r.delegate.us-east-1.awstrack.mebaconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com34.199.56.108A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com35.168.217.27A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com3.233.29.100A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com52.21.129.197A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com3.227.123.195A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com23.22.184.139A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com35.170.141.24A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:06.987925053 CET1.1.1.1192.168.2.40xe30aNo error (0)baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com23.21.125.118A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:07.891448021 CET1.1.1.1192.168.2.40x48a4No error (0)www.penguinrandomhouse.com13.32.99.20A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:07.891448021 CET1.1.1.1192.168.2.40x48a4No error (0)www.penguinrandomhouse.com13.32.99.92A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:07.891448021 CET1.1.1.1192.168.2.40x48a4No error (0)www.penguinrandomhouse.com13.32.99.125A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:07.891448021 CET1.1.1.1192.168.2.40x48a4No error (0)www.penguinrandomhouse.com13.32.99.9A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.comus-lax-1.linodeobjects.comCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.comus-lax-1.linodeobjects.com.akadns.netCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.158.186A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.143.169A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.146.27A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.235.36.35A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.235.36.248A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.143.248A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.156.112A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.143.207A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.235.36.68A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.154.81A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.233.143.236A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.708266020 CET1.1.1.1192.168.2.40x70bcNo error (0)us-lax-1.linodeobjects.com.akadns.net172.235.36.26A (IP address)IN (0x0001)false
                  Feb 2, 2025 06:26:13.736521006 CET1.1.1.1192.168.2.40x977bNo error (0)ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.comus-lax-1.linodeobjects.comCNAME (Canonical name)IN (0x0001)false
                  Feb 2, 2025 06:26:13.736521006 CET1.1.1.1192.168.2.40x977bNo error (0)us-lax-1.linodeobjects.comus-lax-1.linodeobjects.com.akadns.netCNAME (Canonical name)IN (0x0001)false
                  • f6p4fxqv.r.us-east-1.awstrack.me
                  • www.penguinrandomhouse.com
                  • ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com
                  • https:
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44974134.199.56.108443560C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-02-02 05:26:07 UTC1056OUTGET /L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410 HTTP/1.1
                  Host: f6p4fxqv.r.us-east-1.awstrack.me
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-02-02 05:26:07 UTC368INHTTP/1.1 302 Found
                  Date: Sun, 02 Feb 2025 05:26:07 GMT
                  Location: https://www.penguinrandomhouse.com/singlepref/unsubscribe?SubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04&PreferenceId=85001&PreferenceKey=26961&target=https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html#dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=
                  Content-Length: 0
                  Connection: Close


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44974313.32.99.20443560C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-02-02 05:26:08 UTC856OUTGET /singlepref/unsubscribe?SubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04&PreferenceId=85001&PreferenceKey=26961&target=https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html HTTP/1.1
                  Host: www.penguinrandomhouse.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-02-02 05:26:13 UTC967INHTTP/1.1 302 Moved Temporarily
                  Content-Type: text/html; charset=UTF-8
                  Transfer-Encoding: chunked
                  Connection: close
                  Date: Sun, 02 Feb 2025 05:26:13 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubdomains
                  Referrer-Policy: strict-origin
                  Server: nginx
                  X-Prh-Unsubscribe: unsub pref failed
                  Location: https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html
                  X-XSS-Protection: 1
                  Content-Security-Policy: frame-ancestors 'self' https://cart.penguinrandomhouse.com/ https://sites.dev.penguinrandomhouse.com/ https://sites.tst.penguinrandomhouse.com/ https://sites.prh.com/ https://iteratehq.com/ *.penguinrandomhouse.com *.dev.penguinrandomhouse.com *.tst.penguinrandomhouse.com
                  X-Content-Type-Options: nosniff
                  X-Cache: Miss from cloudfront
                  Via: 1.1 d262e104d5d9dd6a4a52f090bdf9395c.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA60-P3
                  Alt-Svc: h3=":443"; ma=86400
                  X-Amz-Cf-Id: VRf-0r6Z3xpsDT8Qy_R_ENsdntdHVa8NNHjHWw0ellsHTjS9nRksng==
                  2025-02-02 05:26:13 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449746172.233.158.186443560C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-02-02 05:26:14 UTC702OUTGET /b4.html HTTP/1.1
                  Host: ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-02-02 05:26:14 UTC227INHTTP/1.1 403 Forbidden
                  Date: Sun, 02 Feb 2025 05:26:14 GMT
                  Content-Type: application/xml
                  Content-Length: 244
                  Connection: close
                  x-amz-request-id: tx000000a4093a9823ab7a9-00679f01f6-9c36dd7d-default
                  Accept-Ranges: bytes
                  2025-02-02 05:26:14 UTC244INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 55 73 65 72 53 75 73 70 65 6e 64 65 64 3c 2f 43 6f 64 65 3e 3c 42 75 63 6b 65 74 4e 61 6d 65 3e 69 6f 70 6c 6b 61 75 77 2d 69 77 69 77 6b 6b 77 2d 32 39 32 38 32 77 6a 77 3c 2f 42 75 63 6b 65 74 4e 61 6d 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 74 78 30 30 30 30 30 30 61 34 30 39 33 61 39 38 32 33 61 62 37 61 39 2d 30 30 36 37 39 66 30 31 66 36 2d 39 63 33 36 64 64 37 64 2d 64 65 66 61 75 6c 74 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 39 63 33 36 64 64 37 64 2d 64 65 66 61 75 6c 74 2d 64 65 66 61 75 6c 74 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e
                  Data Ascii: <?xml version="1.0" encoding="UTF-8"?><Error><Code>UserSuspended</Code><BucketName>ioplkauw-iwiwkkw-29282wjw</BucketName><RequestId>tx000000a4093a9823ab7a9-00679f01f6-9c36dd7d-default</RequestId><HostId>9c36dd7d-default-default</HostId></Error>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.449749172.233.158.186443560C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-02-02 05:26:15 UTC667OUTGET /favicon.ico HTTP/1.1
                  Host: ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://ioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com/b4.html
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-02-02 05:26:15 UTC227INHTTP/1.1 403 Forbidden
                  Date: Sun, 02 Feb 2025 05:26:15 GMT
                  Content-Type: application/xml
                  Content-Length: 244
                  Connection: close
                  x-amz-request-id: tx000005c160596e33b47b3-00679f01f7-9bc92673-default
                  Accept-Ranges: bytes
                  2025-02-02 05:26:15 UTC244INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 55 73 65 72 53 75 73 70 65 6e 64 65 64 3c 2f 43 6f 64 65 3e 3c 42 75 63 6b 65 74 4e 61 6d 65 3e 69 6f 70 6c 6b 61 75 77 2d 69 77 69 77 6b 6b 77 2d 32 39 32 38 32 77 6a 77 3c 2f 42 75 63 6b 65 74 4e 61 6d 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 74 78 30 30 30 30 30 35 63 31 36 30 35 39 36 65 33 33 62 34 37 62 33 2d 30 30 36 37 39 66 30 31 66 37 2d 39 62 63 39 32 36 37 33 2d 64 65 66 61 75 6c 74 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 39 62 63 39 32 36 37 33 2d 64 65 66 61 75 6c 74 2d 64 65 66 61 75 6c 74 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e
                  Data Ascii: <?xml version="1.0" encoding="UTF-8"?><Error><Code>UserSuspended</Code><BucketName>ioplkauw-iwiwkkw-29282wjw</BucketName><RequestId>tx000005c160596e33b47b3-00679f01f7-9bc92673-default</RequestId><HostId>9bc92673-default-default</HostId></Error>


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:00:25:55
                  Start date:02/02/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:00:25:57
                  Start date:02/02/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,8152583084134761886,11834052594652706973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:00:26:06
                  Start date:02/02/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f6p4fxqv.r.us-east-1.awstrack.me/L0/https:%2F%2Fwww.penguinrandomhouse.com%2Fsinglepref%2Funsubscribe%3FSubscriptionGuid=69F89BE7D7330CE7E0534FD66B0AEF04%26PreferenceId=85001%26PreferenceKey=26961%26target=https:%2F%2Fioplkauw-iwiwkkw-29282wjw.us-lax-1.linodeobjects.com%2Fb4.html%23dmFoaWQubWFsZWtpQGFyeWFzYXNvbC5jb20=/1/01000194a92e94f2-f7288fec-a96c-42b8-bfff-ff55db5a5f1d-000000/_CWT2U-lHFJ9BiK4LN4DTLctxc0=410"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly