Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://v1.bgmi-event.freewebhostmost.com/

Overview

General Information

Sample URL:https://v1.bgmi-event.freewebhostmost.com/
Analysis ID:1611556
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 1904 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2348,i,10480359245007881032,14150339800404167770,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://v1.bgmi-event.freewebhostmost.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://v1.bgmi-event.freewebhostmost.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://v1.bgmi-event.freewebhostmost.com/favicon.icoAvira URL Cloud: Label: phishing
Source: https://v1.bgmi-event.freewebhostmost.com/HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: v1.bgmi-event.freewebhostmost.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: v1.bgmi-event.freewebhostmost.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://v1.bgmi-event.freewebhostmost.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: v1.bgmi-event.freewebhostmost.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 787date: Mon, 10 Feb 2025 23:32:24 GMTserver: LiteSpeedvary: User-Agentx-content-type-options: nosniffalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 796date: Mon, 10 Feb 2025 23:32:24 GMTserver: LiteSpeedvary: User-Agentx-content-type-options: nosniffalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: mal56.win@16/0@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2348,i,10480359245007881032,14150339800404167770,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://v1.bgmi-event.freewebhostmost.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2348,i,10480359245007881032,14150339800404167770,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://v1.bgmi-event.freewebhostmost.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://v1.bgmi-event.freewebhostmost.com/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.181.228
truefalse
    high
    v1.bgmi-event.freewebhostmost.com
    66.78.59.15
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://v1.bgmi-event.freewebhostmost.com/true
        unknown
        https://v1.bgmi-event.freewebhostmost.com/favicon.icotrue
        • Avira URL Cloud: phishing
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.181.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        66.78.59.15
        v1.bgmi-event.freewebhostmost.comUnited States
        46261QUICKPACKETUSfalse
        IP
        192.168.2.4
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1611556
        Start date and time:2025-02-11 00:31:23 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 54s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://v1.bgmi-event.freewebhostmost.com/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@16/0@4/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.16.131, 64.233.167.84, 142.250.185.238, 172.217.16.206, 142.250.185.174, 142.250.181.238, 199.232.210.172, 184.30.131.245, 2.22.50.136, 216.58.206.78, 142.250.186.46, 142.250.186.142, 142.250.186.78, 142.250.185.131, 172.217.18.14, 184.28.90.27, 52.149.20.212, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://v1.bgmi-event.freewebhostmost.com/
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Feb 11, 2025 00:32:08.817054033 CET49675443192.168.2.4173.222.162.32
        Feb 11, 2025 00:32:18.426599979 CET49675443192.168.2.4173.222.162.32
        Feb 11, 2025 00:32:21.092896938 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.092922926 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.092993021 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.093220949 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.093236923 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.738014936 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.738481045 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.738507986 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.739506006 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.739572048 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.740695953 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.740761995 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.786572933 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:21.786592960 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:21.832839012 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:22.752144098 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.752187967 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:22.752245903 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.752779007 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.752830029 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:22.752880096 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.753012896 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.753038883 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:22.753314018 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:22.753331900 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.711925983 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.712323904 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.712353945 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.712357998 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.712593079 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.712615967 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.713449955 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.713510036 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.713649035 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.713747025 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.718641996 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.718763113 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.718797922 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.718894005 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.718936920 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.718950033 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.759660959 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.759726048 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:23.759740114 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:23.800044060 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.343668938 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.343745947 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.343796968 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.344814062 CET49742443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.344830990 CET4434974266.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.414025068 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.459323883 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.763076067 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.763147116 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:24.763211966 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.794469118 CET49741443192.168.2.466.78.59.15
        Feb 11, 2025 00:32:24.794502974 CET4434974166.78.59.15192.168.2.4
        Feb 11, 2025 00:32:31.681818008 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:31.681889057 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:32:31.681973934 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:33.490911961 CET49739443192.168.2.4142.250.181.228
        Feb 11, 2025 00:32:33.490955114 CET44349739142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.146565914 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:21.146625042 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.146733999 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:21.147049904 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:21.147073030 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.787811041 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.788176060 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:21.788199902 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.788491964 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.788824081 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:21.788875103 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:21.832182884 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:31.732887030 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:31.732933998 CET44349798142.250.181.228192.168.2.4
        Feb 11, 2025 00:33:31.733272076 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:33.490598917 CET49798443192.168.2.4142.250.181.228
        Feb 11, 2025 00:33:33.490624905 CET44349798142.250.181.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Feb 11, 2025 00:32:17.205084085 CET53505181.1.1.1192.168.2.4
        Feb 11, 2025 00:32:18.446872950 CET53600101.1.1.1192.168.2.4
        Feb 11, 2025 00:32:21.082848072 CET5134353192.168.2.41.1.1.1
        Feb 11, 2025 00:32:21.083050013 CET6289153192.168.2.41.1.1.1
        Feb 11, 2025 00:32:21.091212034 CET53513431.1.1.1192.168.2.4
        Feb 11, 2025 00:32:21.091959953 CET53628911.1.1.1192.168.2.4
        Feb 11, 2025 00:32:22.739278078 CET5669153192.168.2.41.1.1.1
        Feb 11, 2025 00:32:22.739531040 CET5425853192.168.2.41.1.1.1
        Feb 11, 2025 00:32:22.750360012 CET53566911.1.1.1192.168.2.4
        Feb 11, 2025 00:32:22.751282930 CET53542581.1.1.1192.168.2.4
        Feb 11, 2025 00:32:35.546375036 CET53607871.1.1.1192.168.2.4
        Feb 11, 2025 00:32:37.481707096 CET138138192.168.2.4192.168.2.255
        Feb 11, 2025 00:32:54.575711966 CET53533991.1.1.1192.168.2.4
        Feb 11, 2025 00:33:16.795429945 CET53580031.1.1.1192.168.2.4
        Feb 11, 2025 00:33:17.434794903 CET53653541.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Feb 11, 2025 00:32:21.082848072 CET192.168.2.41.1.1.10x6608Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Feb 11, 2025 00:32:21.083050013 CET192.168.2.41.1.1.10x897cStandard query (0)www.google.com65IN (0x0001)false
        Feb 11, 2025 00:32:22.739278078 CET192.168.2.41.1.1.10xbcd6Standard query (0)v1.bgmi-event.freewebhostmost.comA (IP address)IN (0x0001)false
        Feb 11, 2025 00:32:22.739531040 CET192.168.2.41.1.1.10x37ffStandard query (0)v1.bgmi-event.freewebhostmost.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Feb 11, 2025 00:32:21.091212034 CET1.1.1.1192.168.2.40x6608No error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
        Feb 11, 2025 00:32:21.091959953 CET1.1.1.1192.168.2.40x897cNo error (0)www.google.com65IN (0x0001)false
        Feb 11, 2025 00:32:22.750360012 CET1.1.1.1192.168.2.40xbcd6No error (0)v1.bgmi-event.freewebhostmost.com66.78.59.15A (IP address)IN (0x0001)false
        • v1.bgmi-event.freewebhostmost.com
        • https:
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44974266.78.59.154432484C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-02-10 23:32:23 UTC676OUTGET / HTTP/1.1
        Host: v1.bgmi-event.freewebhostmost.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-02-10 23:32:24 UTC466INHTTP/1.1 403 Forbidden
        Connection: close
        cache-control: private, no-cache, no-store, must-revalidate, max-age=0
        pragma: no-cache
        content-type: text/html
        content-length: 787
        date: Mon, 10 Feb 2025 23:32:24 GMT
        server: LiteSpeed
        vary: User-Agent
        x-content-type-options: nosniff
        alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
        2025-02-10 23:32:24 UTC787INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79
        Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 403 Forbidden</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</sty


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974166.78.59.154432484C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-02-10 23:32:24 UTC622OUTGET /favicon.ico HTTP/1.1
        Host: v1.bgmi-event.freewebhostmost.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://v1.bgmi-event.freewebhostmost.com/
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-02-10 23:32:24 UTC466INHTTP/1.1 404 Not Found
        Connection: close
        cache-control: private, no-cache, no-store, must-revalidate, max-age=0
        pragma: no-cache
        content-type: text/html
        content-length: 796
        date: Mon, 10 Feb 2025 23:32:24 GMT
        server: LiteSpeed
        vary: User-Agent
        x-content-type-options: nosniff
        alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
        2025-02-10 23:32:24 UTC796INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79
        Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</sty


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:18:32:12
        Start date:10/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:18:32:15
        Start date:10/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2348,i,10480359245007881032,14150339800404167770,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:18:32:21
        Start date:10/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://v1.bgmi-event.freewebhostmost.com/"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly