Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://7a.ithuupvudv.ru

Overview

General Information

Sample URL:http://7a.ithuupvudv.ru
Analysis ID:1624007
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 5924 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 736 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1916,i,12398275484777526456,2618049248626192716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://7a.ithuupvudv.ru" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://7a.ithuupvudv.ruAvira URL Cloud: detection malicious, Label: phishing
Source: http://7a.ithuupvudv.ru/favicon.icoAvira URL Cloud: Label: phishing
Source: http://7a.ithuupvudv.ru/HTTP Parser: No favicon
Source: global trafficTCP traffic: 192.168.2.4:52565 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 7a.ithuupvudv.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 7a.ithuupvudv.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://7a.ithuupvudv.ru/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: 7a.ithuupvudv.ru
Source: global trafficDNS traffic detected: DNS query: 198.187.3.20.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 25 Feb 2025 17:50:08 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-alivecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=O%2FJ5vbQEqjIdjSQSrJX9sFYQFbad4iNWRIO8DHSJIqkijC7Qw2NyOmBwMOj%2BUSBXPOZF%2Fbvgy1AUuriGVSQ8k9Nqde5pto1hAAjPOaWj5heCPgZDueKtHbWv4TiO"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}server-timing: cfL4;desc="?proto=TCP&rtt=5585&min_rtt=5565&rtt_var=1605&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1352&delivery_rate=498337&cwnd=165&unsent_bytes=0&cid=27dcd7189aac7d80&ts=84&x=0"Server: cloudflareCF-RAY: 917989334fc81895-EWRContent-Encoding: gzipalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=12899&min_rtt=12899&rtt_var=6449&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=431&delivery_rate=0&cwnd=201&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 61 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 8e 4d 0a c2 30 10 85 f7 85 de 61 3c 40 88 85 2e 87 6c 44 c1 85 6e 3c 41 ea 8c 4d 20 9d 94 31 82 bd bd 54 2d 88 6b 97 ae 1e bc 9f 8f 87 a1 0c c9 d5 15 06 f6 e4 b0 c4 92 d8 b5 eb 16 8e b9 c0 2e df 84 d0 be 4c b4 cf 4a 5d 61 97 69 9a f5 cc 52 58 1d 86 e6 7b 11 1a 87 f6 1d cf 6c 75 4b 59 fa 28 f7 cf cc 2e 34 bb 3c 59 19 03 1e 46 4f 14 a5 87 92 81 e2 d5 77 89 e1 70 da 6f c1 0b c1 26 68 1e 18 2e 1a 59 28 4d c0 aa 59 61 f4 3d 83 31 7f c4 af 11 0f 27 a7 bf a8 24 02 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: a7M0a<@.lDn<AM 1T-k.LJ]aiRX{luKY(.4<YFOwpo&h.Y(MYa=1'$0
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 25 Feb 2025 17:50:08 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TXTPu0JgF1mCfCpfkTiURKK0fgl%2B7nrtO2DRnCK9yFAxor2%2BDl758o3p9E9JbCYvMd9F0Omem%2BtzDJBkhYD4auzcFv5sOL5FU2IreI60m5eHJ1HyHajw5dh5DhtU"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Vary: Accept-Encodingserver-timing: cfL4;desc="?proto=TCP&rtt=5587&min_rtt=5565&rtt_var=1599&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1289&delivery_rate=500263&cwnd=91&unsent_bytes=0&cid=91e717f9cac6e2fe&ts=172&x=0"Cache-Control: max-age=14400CF-Cache-Status: EXPIREDServer: cloudflareCF-RAY: 91798936dc591895-EWRContent-Encoding: gzipalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=13188&min_rtt=12899&rtt_var=5415&sent=4&recv=5&lost=0&retrans=0&sent_bytes=1204&recv_bytes=807&delivery_rate=191966&cwnd=203&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: 140
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52632
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 52632 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: mal56.win@16/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1916,i,12398275484777526456,2618049248626192716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://7a.ithuupvudv.ru"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1916,i,12398275484777526456,2618049248626192716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://7a.ithuupvudv.ru100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://7a.ithuupvudv.ru/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.100
truefalse
    high
    7a.ithuupvudv.ru
    104.21.80.1
    truefalse
      unknown
      198.187.3.20.in-addr.arpa
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://7a.ithuupvudv.ru/favicon.icotrue
        • Avira URL Cloud: phishing
        unknown
        http://7a.ithuupvudv.ru/true
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.181.228
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.186.100
          www.google.comUnited States
          15169GOOGLEUSfalse
          104.21.80.1
          7a.ithuupvudv.ruUnited States
          13335CLOUDFLARENETUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1624007
          Start date and time:2025-02-25 18:49:05 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 59s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://7a.ithuupvudv.ru
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal56.win@16/4@6/5
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 216.58.206.67, 172.217.18.14, 74.125.206.84, 216.58.206.78, 216.58.206.46, 142.250.186.46, 2.23.77.188, 2.16.100.168, 142.250.184.238, 142.250.186.174, 216.58.212.142, 142.250.185.142, 142.250.185.163, 172.217.23.110, 23.60.203.209, 172.202.163.200, 20.3.187.198, 4.175.87.197, 13.107.246.60
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: http://7a.ithuupvudv.ru
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, original size modulo 2^32 548
          Category:downloaded
          Size (bytes):167
          Entropy (8bit):6.661971807366373
          Encrypted:false
          SSDEEP:3:FttNovfX+w9xtSxUsOwkNVh9JhEKpN41zjG88M2Hs/Kq0NohK05Vlln:XtN+9LXzHh9vEKpq1zjr8MiVq0Nbaln
          MD5:4E93325CBD7D0A1BD9182C50A87EE855
          SHA1:4761E9470180E0A73BA9DF2773318DAB945E33BE
          SHA-256:C9741CD73B587F99806CA15AE0BF08CA7E78D0A805FC0258394B757107395C96
          SHA-512:5790E2FE525ED8202C44778EC449EF9110873DDC160B29058AD816C18E6E512385405B2AAD0719B1859A93FE6DE2560906EE08F56FC629FEDBDB74854AAC17D4
          Malicious:false
          Reputation:low
          URL:http://7a.ithuupvudv.ru/
          Preview:...........M..0.....a<@....lD..n<A.M ..1...T-.k.........................L..J]a.i...RX...{......luKY.(....4.<Y...FO.......w..p.o...&h....Y(M..Ya.=.1....'...$...
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, truncated
          Category:downloaded
          Size (bytes):20
          Entropy (8bit):1.2917601481809733
          Encrypted:false
          SSDEEP:3:Ftt:Xt
          MD5:7029066C27AC6F5EF18D660D5741979A
          SHA1:46C6643F07AA7F6BFE7118DE926B86DEFC5087C4
          SHA-256:59869DB34853933B239F1E2219CF7D431DA006AA919635478511FABBFC8849D2
          SHA-512:7E8E93F4A89CE7FAE011403E14A1D53544C6E6F6B6010D61129DC27937806D2B03802610D7999EAB33A4C36B0F9E001D9D76001B8354087634C1AA9C740C536F
          Malicious:false
          Reputation:low
          URL:http://7a.ithuupvudv.ru/favicon.ico
          Preview:....................
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Feb 25, 2025 18:50:01.039280891 CET49675443192.168.2.4173.222.162.32
          Feb 25, 2025 18:50:05.531805038 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:05.531917095 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:05.532170057 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:05.532371044 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:05.532399893 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.165904045 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.170634985 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:06.170671940 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.171904087 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.171978951 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:06.173233986 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:06.173326969 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.225682020 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:06.225724936 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:06.272521019 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:07.320723057 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:07.322879076 CET4974280192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:07.325712919 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:07.325783014 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:07.325967073 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:07.327820063 CET8049742104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:07.327888966 CET4974280192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:07.330832005 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:08.219131947 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:08.266057968 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:08.399678946 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:08.404712915 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:08.759231091 CET44349731173.222.162.32192.168.2.4
          Feb 25, 2025 18:50:08.759357929 CET49731443192.168.2.4173.222.162.32
          Feb 25, 2025 18:50:08.852763891 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:08.898430109 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:16.088416100 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:16.088485956 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:16.088531017 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:18.010694981 CET49739443192.168.2.4142.250.186.100
          Feb 25, 2025 18:50:18.010735989 CET44349739142.250.186.100192.168.2.4
          Feb 25, 2025 18:50:18.419347048 CET4972380192.168.2.4199.232.210.172
          Feb 25, 2025 18:50:18.424530029 CET8049723199.232.210.172192.168.2.4
          Feb 25, 2025 18:50:18.424602032 CET4972380192.168.2.4199.232.210.172
          Feb 25, 2025 18:50:22.781209946 CET8049742104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:22.781487942 CET4974280192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:24.009854078 CET4974280192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:24.014914036 CET8049742104.21.80.1192.168.2.4
          Feb 25, 2025 18:50:30.780797005 CET5256553192.168.2.4162.159.36.2
          Feb 25, 2025 18:50:30.785722017 CET5352565162.159.36.2192.168.2.4
          Feb 25, 2025 18:50:30.785928965 CET5256553192.168.2.4162.159.36.2
          Feb 25, 2025 18:50:30.790913105 CET5352565162.159.36.2192.168.2.4
          Feb 25, 2025 18:50:31.247957945 CET5256553192.168.2.4162.159.36.2
          Feb 25, 2025 18:50:31.253123045 CET5352565162.159.36.2192.168.2.4
          Feb 25, 2025 18:50:31.253185034 CET5256553192.168.2.4162.159.36.2
          Feb 25, 2025 18:50:53.866354942 CET4974180192.168.2.4104.21.80.1
          Feb 25, 2025 18:50:53.871428967 CET8049741104.21.80.1192.168.2.4
          Feb 25, 2025 18:51:05.595347881 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:05.595401049 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:05.595485926 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:05.595751047 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:05.595762968 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:06.336256027 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:06.336687088 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:06.336714029 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:06.337276936 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:06.337611914 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:06.337753057 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:06.382055998 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:07.210190058 CET4972480192.168.2.4199.232.210.172
          Feb 25, 2025 18:51:07.216095924 CET8049724199.232.210.172192.168.2.4
          Feb 25, 2025 18:51:07.216160059 CET4972480192.168.2.4199.232.210.172
          Feb 25, 2025 18:51:16.249309063 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:16.249373913 CET44352632142.250.181.228192.168.2.4
          Feb 25, 2025 18:51:16.249461889 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:18.010076046 CET52632443192.168.2.4142.250.181.228
          Feb 25, 2025 18:51:18.010099888 CET44352632142.250.181.228192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Feb 25, 2025 18:50:01.790623903 CET53568611.1.1.1192.168.2.4
          Feb 25, 2025 18:50:01.805725098 CET53630421.1.1.1192.168.2.4
          Feb 25, 2025 18:50:02.777318001 CET53611811.1.1.1192.168.2.4
          Feb 25, 2025 18:50:05.523535967 CET5590153192.168.2.41.1.1.1
          Feb 25, 2025 18:50:05.523649931 CET6269853192.168.2.41.1.1.1
          Feb 25, 2025 18:50:05.530618906 CET53559011.1.1.1192.168.2.4
          Feb 25, 2025 18:50:05.530852079 CET53626981.1.1.1192.168.2.4
          Feb 25, 2025 18:50:07.201185942 CET6041453192.168.2.41.1.1.1
          Feb 25, 2025 18:50:07.201442957 CET5447153192.168.2.41.1.1.1
          Feb 25, 2025 18:50:07.298314095 CET53604141.1.1.1192.168.2.4
          Feb 25, 2025 18:50:07.340621948 CET53544711.1.1.1192.168.2.4
          Feb 25, 2025 18:50:18.798388958 CET138138192.168.2.4192.168.2.255
          Feb 25, 2025 18:50:19.674434900 CET53583561.1.1.1192.168.2.4
          Feb 25, 2025 18:50:30.780136108 CET5349503162.159.36.2192.168.2.4
          Feb 25, 2025 18:50:31.261056900 CET5508453192.168.2.41.1.1.1
          Feb 25, 2025 18:50:31.269232988 CET53550841.1.1.1192.168.2.4
          Feb 25, 2025 18:51:05.587013960 CET5752053192.168.2.41.1.1.1
          Feb 25, 2025 18:51:05.594269037 CET53575201.1.1.1192.168.2.4
          TimestampSource IPDest IPChecksumCodeType
          Feb 25, 2025 18:50:07.340682030 CET192.168.2.41.1.1.1c2de(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Feb 25, 2025 18:50:05.523535967 CET192.168.2.41.1.1.10xd644Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:05.523649931 CET192.168.2.41.1.1.10xa97cStandard query (0)www.google.com65IN (0x0001)false
          Feb 25, 2025 18:50:07.201185942 CET192.168.2.41.1.1.10x9d8Standard query (0)7a.ithuupvudv.ruA (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.201442957 CET192.168.2.41.1.1.10xde5bStandard query (0)7a.ithuupvudv.ru65IN (0x0001)false
          Feb 25, 2025 18:50:31.261056900 CET192.168.2.41.1.1.10x7959Standard query (0)198.187.3.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
          Feb 25, 2025 18:51:05.587013960 CET192.168.2.41.1.1.10xe38eStandard query (0)www.google.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Feb 25, 2025 18:50:05.530618906 CET1.1.1.1192.168.2.40xd644No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:05.530852079 CET1.1.1.1192.168.2.40xa97cNo error (0)www.google.com65IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.80.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.96.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.112.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.64.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.16.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.32.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.298314095 CET1.1.1.1192.168.2.40x9d8No error (0)7a.ithuupvudv.ru104.21.48.1A (IP address)IN (0x0001)false
          Feb 25, 2025 18:50:07.340621948 CET1.1.1.1192.168.2.40xde5bNo error (0)7a.ithuupvudv.ru65IN (0x0001)false
          Feb 25, 2025 18:50:31.269232988 CET1.1.1.1192.168.2.40x7959Name error (3)198.187.3.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
          Feb 25, 2025 18:51:05.594269037 CET1.1.1.1192.168.2.40xe38eNo error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
          • 7a.ithuupvudv.ru
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449741104.21.80.180736C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Feb 25, 2025 18:50:07.325967073 CET431OUTGET / HTTP/1.1
          Host: 7a.ithuupvudv.ru
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Feb 25, 2025 18:50:08.219131947 CET1204INHTTP/1.1 404 Not Found
          Date: Tue, 25 Feb 2025 17:50:08 GMT
          Content-Type: text/html
          Transfer-Encoding: chunked
          Connection: keep-alive
          cf-cache-status: DYNAMIC
          vary: accept-encoding
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=O%2FJ5vbQEqjIdjSQSrJX9sFYQFbad4iNWRIO8DHSJIqkijC7Qw2NyOmBwMOj%2BUSBXPOZF%2Fbvgy1AUuriGVSQ8k9Nqde5pto1hAAjPOaWj5heCPgZDueKtHbWv4TiO"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          server-timing: cfL4;desc="?proto=TCP&rtt=5585&min_rtt=5565&rtt_var=1605&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1352&delivery_rate=498337&cwnd=165&unsent_bytes=0&cid=27dcd7189aac7d80&ts=84&x=0"
          Server: cloudflare
          CF-RAY: 917989334fc81895-EWR
          Content-Encoding: gzip
          alt-svc: h3=":443"; ma=86400
          server-timing: cfL4;desc="?proto=TCP&rtt=12899&min_rtt=12899&rtt_var=6449&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=431&delivery_rate=0&cwnd=201&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
          Data Raw: 61 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 8e 4d 0a c2 30 10 85 f7 85 de 61 3c 40 88 85 2e 87 6c 44 c1 85 6e 3c 41 ea 8c 4d 20 9d 94 31 82 bd bd 54 2d 88 6b 97 ae 1e bc 9f 8f 87 a1 0c c9 d5 15 06 f6 e4 b0 c4 92 d8 b5 eb 16 8e b9 c0 2e df 84 d0 be 4c b4 cf 4a 5d 61 97 69 9a f5 cc 52 58 1d 86 e6 7b 11 1a 87 f6 1d cf 6c 75 4b 59 fa 28 f7 cf cc 2e 34 bb 3c 59 19 03 1e 46 4f 14 a5 87 92 81 e2 d5 77 89 e1 70 da 6f c1 0b c1 26 68 1e 18 2e 1a 59 28 4d c0 aa 59 61 f4 3d 83 31 7f c4 af 11 0f 27 a7 bf a8 24 02 00 00 0d 0a 30 0d 0a 0d 0a
          Data Ascii: a7M0a<@.lDn<AM 1T-k.LJ]aiRX{luKY(.4<YFOwpo&h.Y(MYa=1'$0
          Feb 25, 2025 18:50:08.399678946 CET376OUTGET /favicon.ico HTTP/1.1
          Host: 7a.ithuupvudv.ru
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://7a.ithuupvudv.ru/
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Feb 25, 2025 18:50:08.852763891 CET1110INHTTP/1.1 404 Not Found
          Date: Tue, 25 Feb 2025 17:50:08 GMT
          Content-Type: text/html; charset=UTF-8
          Transfer-Encoding: chunked
          Connection: keep-alive
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TXTPu0JgF1mCfCpfkTiURKK0fgl%2B7nrtO2DRnCK9yFAxor2%2BDl758o3p9E9JbCYvMd9F0Omem%2BtzDJBkhYD4auzcFv5sOL5FU2IreI60m5eHJ1HyHajw5dh5DhtU"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Vary: Accept-Encoding
          server-timing: cfL4;desc="?proto=TCP&rtt=5587&min_rtt=5565&rtt_var=1599&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1289&delivery_rate=500263&cwnd=91&unsent_bytes=0&cid=91e717f9cac6e2fe&ts=172&x=0"
          Cache-Control: max-age=14400
          CF-Cache-Status: EXPIRED
          Server: cloudflare
          CF-RAY: 91798936dc591895-EWR
          Content-Encoding: gzip
          alt-svc: h3=":443"; ma=86400
          server-timing: cfL4;desc="?proto=TCP&rtt=13188&min_rtt=12899&rtt_var=5415&sent=4&recv=5&lost=0&retrans=0&sent_bytes=1204&recv_bytes=807&delivery_rate=191966&cwnd=203&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
          Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a
          Data Ascii: 140
          Feb 25, 2025 18:50:53.866354942 CET6OUTData Raw: 00
          Data Ascii:


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:12:49:55
          Start date:25/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:12:50:00
          Start date:25/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1916,i,12398275484777526456,2618049248626192716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:12:50:06
          Start date:25/02/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://7a.ithuupvudv.ru"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly