Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://d1xkzbyjtghizd.cloudfront.net

Overview

General Information

Sample URL:http://d1xkzbyjtghizd.cloudfront.net
Analysis ID:1612334
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 1620 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5868 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1884,i,17978635091843049264,1584695684076393443,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1xkzbyjtghizd.cloudfront.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://d1xkzbyjtghizd.cloudfront.netAvira URL Cloud: detection malicious, Label: malware
Source: http://d1xkzbyjtghizd.cloudfront.net/favicon.icoAvira URL Cloud: Label: malware
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: d1xkzbyjtghizd.cloudfront.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: d1xkzbyjtghizd.cloudfront.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://d1xkzbyjtghizd.cloudfront.net/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: d1xkzbyjtghizd.cloudfront.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlContent-Length: 564Connection: keep-aliveServer: nginx/1.18.0 (Ubuntu)Date: Tue, 11 Feb 2025 17:21:30 GMTX-Cache: Error from cloudfrontVia: 1.1 cba0902b20d884568adf673bab9438e6.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P6X-Amz-Cf-Id: sxq9BHVvjYAuoTXC2i4OY3wJOZeQxGP4-qmwWyLi9LEHsJuMzFA-ng==Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: mal56.win@16/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1884,i,17978635091843049264,1584695684076393443,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1xkzbyjtghizd.cloudfront.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1884,i,17978635091843049264,1584695684076393443,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://d1xkzbyjtghizd.cloudfront.net100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://d1xkzbyjtghizd.cloudfront.net/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.68
truefalse
    high
    d1xkzbyjtghizd.cloudfront.net
    18.245.78.138
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://d1xkzbyjtghizd.cloudfront.net/favicon.icotrue
      • Avira URL Cloud: malware
      unknown
      http://d1xkzbyjtghizd.cloudfront.net/true
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.68
        www.google.comUnited States
        15169GOOGLEUSfalse
        18.245.78.138
        d1xkzbyjtghizd.cloudfront.netUnited States
        16509AMAZON-02USfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.4
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1612334
        Start date and time:2025-02-11 18:20:28 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 56s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://d1xkzbyjtghizd.cloudfront.net
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@16/4@4/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.16.131, 142.250.186.110, 66.102.1.84, 142.250.185.142, 216.58.206.78, 199.232.210.172, 2.17.190.73, 142.250.186.142, 142.250.185.206, 142.250.185.78, 142.250.186.99, 142.250.186.174, 142.250.74.206, 2.19.244.127, 4.175.87.197, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: http://d1xkzbyjtghizd.cloudfront.net
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):564
        Entropy (8bit):4.775290370533887
        Encrypted:false
        SSDEEP:12:TjeRHVIdtklI5rRCNGlTF5TF5TF5TF5TF5TFK:neRH688lTPTPTPTPTPTc
        MD5:5DA4C1420F84EC727D1B6BDD0D46E62E
        SHA1:280D08D142F7386283F420444EC48E1CDBFD61BB
        SHA-256:3C8CC37A98346BD0123B35E5CCD87BD07D69914DAE04F8B49F61C150D96E9D1F
        SHA-512:7C51A628831D0236E8D314C71732B8A62E06334431D10F7C293C49B23665B2A6A1DDBC4772009010955B5228EA4A5CD97FB93581CE391EE1792E8A198B76111A
        Malicious:false
        Reputation:low
        URL:http://d1xkzbyjtghizd.cloudfront.net/favicon.ico
        Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.18.0 (Ubuntu)</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):1633
        Entropy (8bit):4.690917644642244
        Encrypted:false
        SSDEEP:24:hYMCdMdvncO0tW9MvuWsYuQaKE1+w7HicXNgzhKNzhkvFAzEid4NW:Zdvn6BGrXKE1+w7LXNgFyFvIiCNW
        MD5:B072997324223E5D0FA9D1037A887D57
        SHA1:8CA47A2DD530BDC0DA798F3233684212F7E4C03F
        SHA-256:EBB3274227B416D181466BD19F6A5E16281F0E78878AC982B8F7AD5D47AA1E99
        SHA-512:481C44BC497A2D7EB1B4368EBCF7FD9B08704E0968139BF15ACA1678A43883A92C80E732D11958096D21EC96E9239F8E8EA791A202DD9EB7272CEB2198CB3651
        Malicious:false
        Reputation:low
        URL:http://d1xkzbyjtghizd.cloudfront.net/
        Preview:<!DOCTYPE html>.<html lang="en">.<head>.. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>Detection</title>. <script>. function getQueryParam(param) {. const urlParams = new URLSearchParams(window.location.search);. return urlParams.get(param);. }. function checkosSystemForScna() {. const userAgent = navigator.userAgent;. let os = "Unknown";. if (userAgent.indexOf("Win") !== -1) {. os = "Windows";. }else if (userAgent.indexOf("iPhone") !== -1) {. os = "iOS";. }else if (userAgent.indexOf("Mac") !== -1) {. os = "MacOS";. } else if (userAgent.indexOf("Android") !== -1) {. os = "Android";. } else if (userAgent.indexOf("Linux") !== -1) {. os = "Linux";. } . return os;. }. let operatingSystem = chec
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Feb 11, 2025 18:21:13.303031921 CET49675443192.168.2.4173.222.162.32
        Feb 11, 2025 18:21:22.912415028 CET49675443192.168.2.4173.222.162.32
        Feb 11, 2025 18:21:27.327275991 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.327308893 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:27.327373028 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.327625036 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.327636003 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:27.979217052 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:27.979485989 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.979511023 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:27.980524063 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:27.980626106 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.981956959 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:27.982011080 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:28.022955894 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:28.022967100 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:28.069989920 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:29.208632946 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:29.208913088 CET4974280192.168.2.418.245.78.138
        Feb 11, 2025 18:21:29.213423014 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:29.213495970 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:29.213656902 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:29.213710070 CET804974218.245.78.138192.168.2.4
        Feb 11, 2025 18:21:29.213758945 CET4974280192.168.2.418.245.78.138
        Feb 11, 2025 18:21:29.218390942 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:30.185384035 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:30.185405016 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:30.185450077 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:30.235049009 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:30.239934921 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:30.725986958 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:21:30.768387079 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:21:37.879178047 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:37.879239082 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:37.879829884 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:39.794431925 CET4972380192.168.2.4199.232.214.172
        Feb 11, 2025 18:21:39.795907021 CET49738443192.168.2.4142.250.185.68
        Feb 11, 2025 18:21:39.795927048 CET44349738142.250.185.68192.168.2.4
        Feb 11, 2025 18:21:39.799468994 CET8049723199.232.214.172192.168.2.4
        Feb 11, 2025 18:21:39.799526930 CET4972380192.168.2.4199.232.214.172
        Feb 11, 2025 18:21:59.744666100 CET804974218.245.78.138192.168.2.4
        Feb 11, 2025 18:21:59.744766951 CET4974280192.168.2.418.245.78.138
        Feb 11, 2025 18:21:59.788352966 CET4974280192.168.2.418.245.78.138
        Feb 11, 2025 18:21:59.793123007 CET804974218.245.78.138192.168.2.4
        Feb 11, 2025 18:22:15.739136934 CET4974180192.168.2.418.245.78.138
        Feb 11, 2025 18:22:15.744036913 CET804974118.245.78.138192.168.2.4
        Feb 11, 2025 18:22:27.381678104 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:27.381721973 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:27.381932974 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:27.382121086 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:27.382144928 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:28.009788036 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:28.010504007 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:28.010536909 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:28.010811090 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:28.011154890 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:28.011204004 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:28.051827908 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:29.209393978 CET4972480192.168.2.4199.232.214.172
        Feb 11, 2025 18:22:29.214474916 CET8049724199.232.214.172192.168.2.4
        Feb 11, 2025 18:22:29.214530945 CET4972480192.168.2.4199.232.214.172
        Feb 11, 2025 18:22:37.935630083 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:37.935681105 CET44349808142.250.185.68192.168.2.4
        Feb 11, 2025 18:22:37.935924053 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:39.788868904 CET49808443192.168.2.4142.250.185.68
        Feb 11, 2025 18:22:39.788901091 CET44349808142.250.185.68192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Feb 11, 2025 18:21:23.489772081 CET53635821.1.1.1192.168.2.4
        Feb 11, 2025 18:21:23.562638998 CET53570851.1.1.1192.168.2.4
        Feb 11, 2025 18:21:24.538682938 CET53650971.1.1.1192.168.2.4
        Feb 11, 2025 18:21:27.319261074 CET5248853192.168.2.41.1.1.1
        Feb 11, 2025 18:21:27.319399118 CET5263453192.168.2.41.1.1.1
        Feb 11, 2025 18:21:27.326061010 CET53524881.1.1.1192.168.2.4
        Feb 11, 2025 18:21:27.326081991 CET53526341.1.1.1192.168.2.4
        Feb 11, 2025 18:21:29.181801081 CET5535853192.168.2.41.1.1.1
        Feb 11, 2025 18:21:29.181953907 CET4988353192.168.2.41.1.1.1
        Feb 11, 2025 18:21:29.205866098 CET53498831.1.1.1192.168.2.4
        Feb 11, 2025 18:21:29.208159924 CET53553581.1.1.1192.168.2.4
        Feb 11, 2025 18:21:40.792793036 CET138138192.168.2.4192.168.2.255
        Feb 11, 2025 18:21:41.467341900 CET53619011.1.1.1192.168.2.4
        Feb 11, 2025 18:22:00.482492924 CET53520611.1.1.1192.168.2.4
        Feb 11, 2025 18:22:23.048141003 CET53567171.1.1.1192.168.2.4
        Feb 11, 2025 18:22:23.389027119 CET53592411.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Feb 11, 2025 18:21:27.319261074 CET192.168.2.41.1.1.10x2f35Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:27.319399118 CET192.168.2.41.1.1.10x31e7Standard query (0)www.google.com65IN (0x0001)false
        Feb 11, 2025 18:21:29.181801081 CET192.168.2.41.1.1.10xd577Standard query (0)d1xkzbyjtghizd.cloudfront.netA (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:29.181953907 CET192.168.2.41.1.1.10xbff3Standard query (0)d1xkzbyjtghizd.cloudfront.net65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Feb 11, 2025 18:21:27.326061010 CET1.1.1.1192.168.2.40x2f35No error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:27.326081991 CET1.1.1.1192.168.2.40x31e7No error (0)www.google.com65IN (0x0001)false
        Feb 11, 2025 18:21:29.208159924 CET1.1.1.1192.168.2.40xd577No error (0)d1xkzbyjtghizd.cloudfront.net18.245.78.138A (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:29.208159924 CET1.1.1.1192.168.2.40xd577No error (0)d1xkzbyjtghizd.cloudfront.net18.245.78.71A (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:29.208159924 CET1.1.1.1192.168.2.40xd577No error (0)d1xkzbyjtghizd.cloudfront.net18.245.78.64A (IP address)IN (0x0001)false
        Feb 11, 2025 18:21:29.208159924 CET1.1.1.1192.168.2.40xd577No error (0)d1xkzbyjtghizd.cloudfront.net18.245.78.146A (IP address)IN (0x0001)false
        • d1xkzbyjtghizd.cloudfront.net
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44974118.245.78.138805868C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Feb 11, 2025 18:21:29.213656902 CET444OUTGET / HTTP/1.1
        Host: d1xkzbyjtghizd.cloudfront.net
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Feb 11, 2025 18:21:30.185384035 CET1236INHTTP/1.1 200 OK
        Content-Type: text/html; charset=UTF-8
        Transfer-Encoding: chunked
        Connection: keep-alive
        Server: nginx/1.18.0 (Ubuntu)
        Date: Tue, 11 Feb 2025 17:21:30 GMT
        X-Cache: Miss from cloudfront
        Via: 1.1 cba0902b20d884568adf673bab9438e6.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: FRA60-P6
        X-Amz-Cf-Id: JFHde0DnSSGkAokImAjvxHc6jHI5tvWcKJeELP1yJ0lsbPkXODLtDw==
        Data Raw: 36 36 31 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 44 65 74 65 63 74 69 6f 6e 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 0a 20 20 20 20 20 20 20 20 66 75 6e 63 74 69 6f 6e 20 67 65 74 51 75 65 72 79 50 61 72 61 6d 28 70 61 72 61 6d 29 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6e 73 74 20 75 72 6c 50 61 72 61 6d 73 20 3d 20 6e 65 77 20 55 52 4c 53 65 61 72 63 68 50 61 72 61 6d 73 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 73 65 61 72 63 68 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 72 65 74 75 72 6e 20 75 72 6c 50 61 72 61 6d 73 2e 67 65 74 28 [TRUNCATED]
        Data Ascii: 661<!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Detection</title> <script> function getQueryParam(param) { const urlParams = new URLSearchParams(window.location.search); return urlParams.get(param); } function checkosSystemForScna() { const userAgent = navigator.userAgent; let os = "Unknown"; if (userAgent.indexOf("Win") !== -1) { os = "Windows"; }else if (userAgent.indexOf("iPhone") !== -1) { os = "iOS"; }else if (userAgent.indexOf("Mac") !== -1) { os = "MacOS"; } else if (userAgent.indexOf("Android") !== -1) { os = "Android"; } else if (user
        Feb 11, 2025 18:21:30.185405016 CET785INData Raw: 41 67 65 6e 74 2e 69 6e 64 65 78 4f 66 28 22 4c 69 6e 75 78 22 29 20 21 3d 3d 20 2d 31 29 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6f 73 20 3d 20 22 4c 69 6e 75 78 22 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 20 0a 20 20 20 20
        Data Ascii: Agent.indexOf("Linux") !== -1) { os = "Linux"; } return os; } let operatingSystem = checkosSystemForScna(); localStorage.setItem('alpha',getQueryParam('alpha')); if(opera
        Feb 11, 2025 18:21:30.235049009 CET402OUTGET /favicon.ico HTTP/1.1
        Host: d1xkzbyjtghizd.cloudfront.net
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://d1xkzbyjtghizd.cloudfront.net/
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Feb 11, 2025 18:21:30.725986958 CET926INHTTP/1.1 404 Not Found
        Content-Type: text/html
        Content-Length: 564
        Connection: keep-alive
        Server: nginx/1.18.0 (Ubuntu)
        Date: Tue, 11 Feb 2025 17:21:30 GMT
        X-Cache: Error from cloudfront
        Via: 1.1 cba0902b20d884568adf673bab9438e6.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: FRA60-P6
        X-Amz-Cf-Id: sxq9BHVvjYAuoTXC2i4OY3wJOZeQxGP4-qmwWyLi9LEHsJuMzFA-ng==
        Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 [TRUNCATED]
        Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
        Feb 11, 2025 18:22:15.739136934 CET6OUTData Raw: 00
        Data Ascii:


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:12:21:17
        Start date:11/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:12:21:21
        Start date:11/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1884,i,17978635091843049264,1584695684076393443,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:12:21:28
        Start date:11/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1xkzbyjtghizd.cloudfront.net"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly