Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://morlune.com/

Overview

General Information

Sample URL:https://morlune.com/
Analysis ID:1619056
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4616 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2216,i,12503085410712527917,4584024601569044925,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://morlune.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://morlune.com/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: morlune.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: morlune.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://morlune.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: morlune.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: morlune.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: classification engineClassification label: mal48.win@16/9@6/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2216,i,12503085410712527917,4584024601569044925,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://morlune.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2216,i,12503085410712527917,4584024601569044925,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://morlune.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
morlune.com
104.21.33.223
truefalse
    high
    www.google.com
    142.250.186.164
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://morlune.com/false
        high
        https://morlune.com/favicon.icofalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          104.21.33.223
          morlune.comUnited States
          13335CLOUDFLARENETUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.186.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.5
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1619056
          Start date and time:2025-02-19 14:46:24 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 51s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://morlune.com/
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal48.win@16/9@6/4
          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.185.78, 66.102.1.84, 142.250.181.238, 172.217.16.206, 199.232.214.172, 2.23.77.188, 142.250.186.78, 142.250.185.238, 142.250.74.206, 216.58.212.142, 142.250.185.142, 216.58.206.67, 2.19.106.160, 4.245.163.56, 13.107.246.45
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: https://morlune.com/
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 19 12:47:17 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.978108942410873
          Encrypted:false
          SSDEEP:48:8/dETosoHXidAKZdA19ehwiZUklqehAy+3:86nM/y
          MD5:06F438144DD9FDFEAA3C7AE3ED99BB6E
          SHA1:DA79E34513704194735792E9C6639C0901363972
          SHA-256:6173015DC5BE728A7479A6F64CB41193E84A7C1FA23C679AC4F5C3BA87CF283C
          SHA-512:1F049174F987ABD0CC040B94244130F41BB5A8C99298B84CB84EA899F6714D82729102573CC93FDB220E93942E40EAD510185CBCA5F3BEA61A5B36592190E5A0
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....q.#....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VSZ.m...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 19 12:47:17 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.9918526786891197
          Encrypted:false
          SSDEEP:48:8bdETosoHXidAKZdA1weh/iZUkAQkqehvy+2:8Gn+9Q+y
          MD5:A72D4EAC33F662EE59BF7253F60D8C12
          SHA1:31D77E7914F320DB6151AF43D8BC2438F2F186B2
          SHA-256:A2A92EE5A56CBB382E5C4D18F80887992293BBFBD0DA9E6907545FBEC74D31B1
          SHA-512:F346C83425E086172BBCA0AA16F597D567AA3C45A62CEE6A9895CA08C8F6BBA50831CE181657BBF19712A169E49454C8282F0333D79CA1317596A955889D8219
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,...........N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VSZ.m...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2693
          Entropy (8bit):4.00555015643214
          Encrypted:false
          SSDEEP:48:8xFdETossHXidAKZdA14tseh7sFiZUkmgqeh7sVy+BX:8xsninLy
          MD5:1D16922DF0FBBBF9F71BB3C6709920B4
          SHA1:53E17439752F4EFD48F5BFFAB5A87E21C2C81A6B
          SHA-256:093E75200155A630B761359B944506A79C885F710D574AC19D4536AEEADA3601
          SHA-512:5448398B13B15B5E36C50E1EA74446EEDDBC3F44AB0ACD7A115EDEF99BC9561409CC5A0DC4B7E64454B15E793DFBDB0CD4F263F694873930C870AEE89318C111
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 19 12:47:17 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.9906235104534282
          Encrypted:false
          SSDEEP:48:8idETosoHXidAKZdA1vehDiZUkwqehjy+R:8dnlty
          MD5:72C6F0312EBDC5E1A2318FD66664682D
          SHA1:0D90F8D63001211B4720CDDF99C43920F54AD071
          SHA-256:079424CE43AD83D7F75D5B81005273729599AF48EF8F6CC51E5792077FFF0621
          SHA-512:D3E4E060ABF31DE452BA6808E19C4698D2E836DED18F01C7DC3EBE43FA48C078CEE5D8A80A5A0D280FFA9D3C559FC98B72CCFE6DBC83B6A4A21F07D047B9745A
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....Z.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VSZ.m...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 19 12:47:17 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.981445473132113
          Encrypted:false
          SSDEEP:48:8sdETosoHXidAKZdA1hehBiZUk1W1qehBy+C:8rn19hy
          MD5:29D586C286BC8233E5310320E5E68E13
          SHA1:24322F2D726F1A66A6A7EAD41B23814906F158EC
          SHA-256:5952CF6EE57E9DB2CA80E55A4DFC1DC0496FA5051569A0BC256D505564F86B7C
          SHA-512:93168D6D712CC80E829EB8892361F8FFCAB9622AAD18C3AEB16F9666E2F3ADFB5CFD25BAF2072C6417CE2974E11982BD67A01ECB5CE88C5A8D535B0B0E9280B4
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....F.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VSZ.m...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 19 12:47:17 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2683
          Entropy (8bit):3.9914743261819137
          Encrypted:false
          SSDEEP:48:8/dETosoHXidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:86nJT/TbxWOvTbLy7T
          MD5:07A2A39A04A45ABE8A459892A2E8694C
          SHA1:2ED11A8174991B01179CC6B96B5343238802330A
          SHA-256:3376D5EF6E382E408F2499633C350B11E8646F2C97C8DB1D53BAAB3084612F1D
          SHA-512:B5EEAED3265EBF4FA9681C74B18C0CB66B342B86C1FD4A3A273F4FA715468A9188F30D0D1441E1A6145AF07FAA854C81DB1F0FA85A0E2967B6FAEA4DA91E3853
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....<4.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ISZ.m....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VSZ.m....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VSZ.m....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VSZ.m..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VSZ.m...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........^........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
          Category:downloaded
          Size (bytes):198
          Entropy (8bit):1.27079017683323
          Encrypted:false
          SSDEEP:3:3+RXllvlNl/FXl1ll1l/lBe/h/555555555555555n:Ox10J555555555555555n
          MD5:BC891CFAA28AB9CD92768BCA6314E9BD
          SHA1:37F47249E7A197E341C9FE8A32C219BA85E6BDAA
          SHA-256:494BA8D3C00B77AF26FECF278BB198C012BB45860BD870E28AB469DAFA8F3301
          SHA-512:70DB97696915B23887B9831C8525099DF4B045D643F681AA997C3CF620BAAC95E695B67AB7F91213DB34785A7000B1A2D90965FA7CA00ED68EDE703A26BF5E1B
          Malicious:false
          Reputation:low
          URL:https://morlune.com/favicon.ico
          Preview:......................(....... ...........@...........................................................................................................................................................
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
          Category:dropped
          Size (bytes):198
          Entropy (8bit):1.27079017683323
          Encrypted:false
          SSDEEP:3:3+RXllvlNl/FXl1ll1l/lBe/h/555555555555555n:Ox10J555555555555555n
          MD5:BC891CFAA28AB9CD92768BCA6314E9BD
          SHA1:37F47249E7A197E341C9FE8A32C219BA85E6BDAA
          SHA-256:494BA8D3C00B77AF26FECF278BB198C012BB45860BD870E28AB469DAFA8F3301
          SHA-512:70DB97696915B23887B9831C8525099DF4B045D643F681AA997C3CF620BAAC95E695B67AB7F91213DB34785A7000B1A2D90965FA7CA00ED68EDE703A26BF5E1B
          Malicious:false
          Reputation:low
          Preview:......................(....... ...........@...........................................................................................................................................................
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Feb 19, 2025 14:47:09.485773087 CET49675443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:09.485871077 CET49674443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:09.581630945 CET49673443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:19.088584900 CET49675443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:19.088597059 CET49674443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:19.182914019 CET49673443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:20.695558071 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:20.695653915 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:20.695741892 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:20.695923090 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:20.695944071 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:20.841676950 CET4434970323.1.237.91192.168.2.5
          Feb 19, 2025 14:47:20.841794968 CET49703443192.168.2.523.1.237.91
          Feb 19, 2025 14:47:21.338326931 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:21.338596106 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:21.338661909 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:21.340142012 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:21.340219021 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:21.341156960 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:21.341258049 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:21.386857033 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:21.386918068 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:21.433110952 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:21.749941111 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750032902 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:21.750251055 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750284910 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:21.750299931 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750330925 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750566959 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750591993 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:21.750727892 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:21.750745058 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.218074083 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.233896017 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.239759922 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.239782095 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.240056992 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.240123987 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.241267920 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.241344929 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.241717100 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.241796970 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251049042 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251110077 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251146078 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.251254082 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251266956 CET44349715104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.251277924 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251499891 CET49715443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.251986027 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252080917 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.252177000 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252372026 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252372026 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252485991 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.252572060 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252572060 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.252599001 CET44349714104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.252660990 CET49714443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.253030062 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.253060102 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.253236055 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.253364086 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.253405094 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.253586054 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.253599882 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.713763952 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.714168072 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.714235067 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.715125084 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.715200901 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.716094971 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.716191053 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.716293097 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.716314077 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.732811928 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.733004093 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.733016014 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.736350060 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.736418009 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.736737013 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.736813068 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.765909910 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.781877041 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.781883001 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.828681946 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.948599100 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.948668957 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.948889017 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.949311972 CET49717443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:22.949353933 CET44349717104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:22.991482973 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.035332918 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.209898949 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.210020065 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.210072994 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.210959911 CET49718443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.210973978 CET44349718104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.228400946 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.228494883 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.228734016 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.228851080 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.228883028 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.695207119 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.695466995 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.695537090 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.696428061 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.696506977 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.696801901 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.696801901 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.696842909 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.696875095 CET44349719104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.696943998 CET49719443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.697159052 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.697190046 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:23.697866917 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.697866917 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:23.697897911 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.159732103 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.160195112 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.160222054 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.160967112 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.161029100 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.161458969 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.161511898 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.161582947 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.161592007 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.213674068 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.311711073 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.311769009 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:24.311873913 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.313674927 CET49720443192.168.2.5104.21.33.223
          Feb 19, 2025 14:47:24.313693047 CET44349720104.21.33.223192.168.2.5
          Feb 19, 2025 14:47:31.229557991 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:31.229652882 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:47:31.229837894 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:32.684792995 CET49712443192.168.2.5142.250.186.164
          Feb 19, 2025 14:47:32.684865952 CET44349712142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:20.747173071 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:20.747278929 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:20.747411966 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:20.747749090 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:20.747793913 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:21.387650967 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:21.388065100 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:21.388133049 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:21.388477087 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:21.388801098 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:21.388885975 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:21.433077097 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:31.334584951 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:31.334749937 CET44349995142.250.186.164192.168.2.5
          Feb 19, 2025 14:48:31.334865093 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:32.686419964 CET49995443192.168.2.5142.250.186.164
          Feb 19, 2025 14:48:32.686455011 CET44349995142.250.186.164192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Feb 19, 2025 14:47:16.434202909 CET53571521.1.1.1192.168.2.5
          Feb 19, 2025 14:47:16.554610968 CET53513571.1.1.1192.168.2.5
          Feb 19, 2025 14:47:17.518177032 CET53623661.1.1.1192.168.2.5
          Feb 19, 2025 14:47:20.687443972 CET6119253192.168.2.51.1.1.1
          Feb 19, 2025 14:47:20.687568903 CET5938353192.168.2.51.1.1.1
          Feb 19, 2025 14:47:20.694730043 CET53611921.1.1.1192.168.2.5
          Feb 19, 2025 14:47:20.694921970 CET53593831.1.1.1192.168.2.5
          Feb 19, 2025 14:47:21.737325907 CET5712453192.168.2.51.1.1.1
          Feb 19, 2025 14:47:21.737325907 CET6001653192.168.2.51.1.1.1
          Feb 19, 2025 14:47:21.747234106 CET53600161.1.1.1192.168.2.5
          Feb 19, 2025 14:47:21.748044968 CET53571241.1.1.1192.168.2.5
          Feb 19, 2025 14:47:23.215841055 CET6373653192.168.2.51.1.1.1
          Feb 19, 2025 14:47:23.215965986 CET5335553192.168.2.51.1.1.1
          Feb 19, 2025 14:47:23.226310015 CET53637361.1.1.1192.168.2.5
          Feb 19, 2025 14:47:23.228013992 CET53533551.1.1.1192.168.2.5
          Feb 19, 2025 14:47:34.456768990 CET53598751.1.1.1192.168.2.5
          Feb 19, 2025 14:47:53.426112890 CET53496381.1.1.1192.168.2.5
          Feb 19, 2025 14:48:16.068989992 CET53604101.1.1.1192.168.2.5
          Feb 19, 2025 14:48:16.148605108 CET53568921.1.1.1192.168.2.5
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Feb 19, 2025 14:47:20.687443972 CET192.168.2.51.1.1.10xa3a4Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:20.687568903 CET192.168.2.51.1.1.10xe23Standard query (0)www.google.com65IN (0x0001)false
          Feb 19, 2025 14:47:21.737325907 CET192.168.2.51.1.1.10x68e1Standard query (0)morlune.comA (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:21.737325907 CET192.168.2.51.1.1.10xa49Standard query (0)morlune.com65IN (0x0001)false
          Feb 19, 2025 14:47:23.215841055 CET192.168.2.51.1.1.10x657dStandard query (0)morlune.comA (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:23.215965986 CET192.168.2.51.1.1.10xfa4fStandard query (0)morlune.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Feb 19, 2025 14:47:20.694730043 CET1.1.1.1192.168.2.50xa3a4No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:20.694921970 CET1.1.1.1192.168.2.50xe23No error (0)www.google.com65IN (0x0001)false
          Feb 19, 2025 14:47:21.747234106 CET1.1.1.1192.168.2.50xa49No error (0)morlune.com65IN (0x0001)false
          Feb 19, 2025 14:47:21.748044968 CET1.1.1.1192.168.2.50x68e1No error (0)morlune.com104.21.33.223A (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:21.748044968 CET1.1.1.1192.168.2.50x68e1No error (0)morlune.com172.67.151.21A (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:23.226310015 CET1.1.1.1192.168.2.50x657dNo error (0)morlune.com104.21.33.223A (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:23.226310015 CET1.1.1.1192.168.2.50x657dNo error (0)morlune.com172.67.151.21A (IP address)IN (0x0001)false
          Feb 19, 2025 14:47:23.228013992 CET1.1.1.1192.168.2.50xfa4fNo error (0)morlune.com65IN (0x0001)false
          • morlune.com
          • https:
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.549717104.21.33.2234434616C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-02-19 13:47:22 UTC654OUTGET / HTTP/1.1
          Host: morlune.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2025-02-19 13:47:22 UTC811INHTTP/1.1 200 OK
          Date: Wed, 19 Feb 2025 13:47:22 GMT
          Content-Type: text/html; charset=UTF-8
          Transfer-Encoding: chunked
          Connection: close
          vary: accept-encoding
          cf-cache-status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=SVlS8bBsGYBgB%2Fib0IkXG3iyXqRzyquBFNAQH5ikssF2qgGJT%2FtMygQxsjhTtc5OpYYpk%2FJ04iDIrM7b0vGbU1BFlNUe1xWE49yg6QakZ6zQYB%2BHZdRqonx57VqkWQ%3D%3D"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 9146b55b8a9041e1-EWR
          alt-svc: h3=":443"; ma=86400
          server-timing: cfL4;desc="?proto=TCP&rtt=1602&min_rtt=1581&rtt_var=608&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2824&recv_bytes=1232&delivery_rate=1846932&cwnd=246&unsent_bytes=0&cid=b9029015bed1e3a6&ts=244&x=0"
          2025-02-19 13:47:22 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.549718104.21.33.2234434616C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-02-19 13:47:22 UTC578OUTGET /favicon.ico HTTP/1.1
          Host: morlune.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://morlune.com/
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2025-02-19 13:47:23 UTC848INHTTP/1.1 200 OK
          Date: Wed, 19 Feb 2025 13:47:23 GMT
          Content-Type: image/x-icon
          Transfer-Encoding: chunked
          Connection: close
          Last-Modified: Wed, 19 Feb 2025 13:14:01 GMT
          Cache-Control: max-age=14400
          CF-Cache-Status: HIT
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Oo%2F1I%2FWsPcvnOBvQZyufbCWRiG7J0sUqOjmdS5HtGcPdjf4Q98bNXFoPJcEEPJYuwvOQ2m6gjKaMBGQihvdy%2FyCQ9SQD%2F7XtGkyS5NuonOW6bq21Z8j5DQWkZiOkHw%3D%3D"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 9146b55d0febc336-EWR
          alt-svc: h3=":443"; ma=86400
          server-timing: cfL4;desc="?proto=TCP&rtt=1611&min_rtt=1590&rtt_var=612&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2825&recv_bytes=1156&delivery_rate=1836477&cwnd=246&unsent_bytes=0&cid=9baccdd0a537d675&ts=486&x=0"
          2025-02-19 13:47:23 UTC204INData Raw: 63 36 0d 0a 00 00 01 00 01 00 10 10 02 00 00 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 0d 0a
          Data Ascii: c6( @
          2025-02-19 13:47:23 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.549720104.21.33.2234434616C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-02-19 13:47:24 UTC346OUTGET /favicon.ico HTTP/1.1
          Host: morlune.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: */*
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: cors
          Sec-Fetch-Dest: empty
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2025-02-19 13:47:24 UTC855INHTTP/1.1 200 OK
          Date: Wed, 19 Feb 2025 13:47:24 GMT
          Content-Type: image/x-icon
          Transfer-Encoding: chunked
          Connection: close
          Last-Modified: Wed, 19 Feb 2025 13:14:01 GMT
          Cache-Control: max-age=14400
          CF-Cache-Status: HIT
          Age: 1
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AywPTSLSu%2FdDQ35lJDOsRO3gElRRAIqo811LSxMZqN20cSsV0gijDKLuN9SQNL9yiTXlwqnRP%2BCpEqDWTUWZKIkGG%2FAxU1uCD4aEV6Vq%2BYxCGh8AwI6ETE31yUuQwQ%3D%3D"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 9146b5649f2841e1-EWR
          alt-svc: h3=":443"; ma=86400
          server-timing: cfL4;desc="?proto=TCP&rtt=1604&min_rtt=1599&rtt_var=611&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2824&recv_bytes=924&delivery_rate=1775075&cwnd=246&unsent_bytes=0&cid=8090c501e69ba098&ts=155&x=0"
          2025-02-19 13:47:24 UTC204INData Raw: 63 36 0d 0a 00 00 01 00 01 00 10 10 02 00 00 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 0d 0a
          Data Ascii: c6( @
          2025-02-19 13:47:24 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:08:47:11
          Start date:19/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:08:47:14
          Start date:19/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2216,i,12503085410712527917,4584024601569044925,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:08:47:20
          Start date:19/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://morlune.com/"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly