Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion

Overview

General Information

Sample URL:http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Analysis ID:1631814
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Sigma detected: DNS Query Tor .Onion Address - Sysmon
Uses TOR for connection hidding

Classification

  • System is w10x64
  • chrome.exe (PID: 60 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3112 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2176,i,5256345546358794950,5354833833403800214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2264 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 4068 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: DNS queryAuthor: frack113: Data: Image: C:\Program Files\Google\Chrome\Application\chrome.exe, QueryName: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: unknownHTTPS traffic detected: 131.253.33.254:443 -> 192.168.2.4:49731 version: TLS 1.2

Networking

barindex
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownDNS query: name: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 131.253.33.254:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: classification engineClassification label: mal48.troj.win@22/0@24/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2176,i,5256345546358794950,5354833833403800214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2264 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2176,i,5256345546358794950,5354833833403800214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2264 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Multi-hop Proxy
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeylogging1
Proxy
Scheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.251.36.46
truefalse
    high
    www.google.com
    142.250.185.164
    truefalse
      high
      lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.164
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1631814
        Start date and time:2025-03-07 15:18:52 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 9s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:17
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.troj.win@22/0@24/2
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.181.238, 142.250.185.195, 142.250.185.238, 108.177.15.84, 142.250.181.227, 142.250.185.206, 172.217.23.110, 142.250.74.206, 142.250.186.46, 23.60.203.209
        • Excluded domains from analysis (whitelisted): a-ring-fallback.msedge.net, fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, clientservices.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Mar 7, 2025 15:19:50.957099915 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:19:51.258806944 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:19:51.868208885 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:19:53.071356058 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:19:55.524018049 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:19:59.525171041 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:19:59.836128950 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:19:59.937530041 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:19:59.937580109 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:19:59.937648058 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:19:59.939049006 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:19:59.939065933 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:00.336095095 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:20:00.445446968 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:20:01.649054050 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:20:02.170711994 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:02.171200037 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:02.171228886 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:02.172329903 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:02.172394991 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:02.173470020 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:02.173553944 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:02.227685928 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:02.227708101 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:02.274593115 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:04.055820942 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:20:05.177473068 CET49731443192.168.2.4131.253.33.254
        Mar 7, 2025 15:20:05.177519083 CET44349731131.253.33.254192.168.2.4
        Mar 7, 2025 15:20:05.177651882 CET49731443192.168.2.4131.253.33.254
        Mar 7, 2025 15:20:05.178036928 CET49731443192.168.2.4131.253.33.254
        Mar 7, 2025 15:20:05.178050041 CET44349731131.253.33.254192.168.2.4
        Mar 7, 2025 15:20:07.473248959 CET44349731131.253.33.254192.168.2.4
        Mar 7, 2025 15:20:07.473366022 CET49731443192.168.2.4131.253.33.254
        Mar 7, 2025 15:20:08.869128942 CET49678443192.168.2.420.189.173.27
        Mar 7, 2025 15:20:09.947288990 CET49671443192.168.2.4204.79.197.203
        Mar 7, 2025 15:20:11.790487051 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:11.790695906 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:11.790832043 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:11.910057068 CET49724443192.168.2.4142.250.185.164
        Mar 7, 2025 15:20:11.910087109 CET44349724142.250.185.164192.168.2.4
        Mar 7, 2025 15:20:18.484554052 CET49678443192.168.2.420.189.173.27
        TimestampSource PortDest PortSource IPDest IP
        Mar 7, 2025 15:19:55.802576065 CET53609661.1.1.1192.168.2.4
        Mar 7, 2025 15:19:56.646783113 CET53508761.1.1.1192.168.2.4
        Mar 7, 2025 15:19:59.497163057 CET53494331.1.1.1192.168.2.4
        Mar 7, 2025 15:19:59.915672064 CET6033653192.168.2.41.1.1.1
        Mar 7, 2025 15:19:59.915868998 CET6262853192.168.2.41.1.1.1
        Mar 7, 2025 15:19:59.923039913 CET53626281.1.1.1192.168.2.4
        Mar 7, 2025 15:19:59.923846006 CET53603361.1.1.1192.168.2.4
        Mar 7, 2025 15:20:00.979038000 CET5049153192.168.2.41.1.1.1
        Mar 7, 2025 15:20:00.979227066 CET5566253192.168.2.41.1.1.1
        Mar 7, 2025 15:20:00.989588022 CET53504911.1.1.1192.168.2.4
        Mar 7, 2025 15:20:00.990911007 CET53556621.1.1.1192.168.2.4
        Mar 7, 2025 15:20:00.998712063 CET5396553192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.001353025 CET5908553192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.001734972 CET5011053192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.008829117 CET53539651.1.1.1192.168.2.4
        Mar 7, 2025 15:20:01.012084961 CET53590851.1.1.1192.168.2.4
        Mar 7, 2025 15:20:01.012677908 CET53501101.1.1.1192.168.2.4
        Mar 7, 2025 15:20:01.024709940 CET5217053192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.025121927 CET5628753192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.033927917 CET53521701.1.1.1192.168.2.4
        Mar 7, 2025 15:20:01.033971071 CET53562871.1.1.1192.168.2.4
        Mar 7, 2025 15:20:01.065150023 CET6416553192.168.2.48.8.8.8
        Mar 7, 2025 15:20:01.065731049 CET5615753192.168.2.41.1.1.1
        Mar 7, 2025 15:20:01.072710991 CET53641658.8.8.8192.168.2.4
        Mar 7, 2025 15:20:01.072913885 CET53561571.1.1.1192.168.2.4
        Mar 7, 2025 15:20:02.105021954 CET5944853192.168.2.41.1.1.1
        Mar 7, 2025 15:20:02.111300945 CET6493153192.168.2.41.1.1.1
        Mar 7, 2025 15:20:02.113575935 CET53594481.1.1.1192.168.2.4
        Mar 7, 2025 15:20:02.119956017 CET53649311.1.1.1192.168.2.4
        Mar 7, 2025 15:20:07.150234938 CET5947353192.168.2.41.1.1.1
        Mar 7, 2025 15:20:07.150557041 CET5507253192.168.2.41.1.1.1
        Mar 7, 2025 15:20:07.159162045 CET53550721.1.1.1192.168.2.4
        Mar 7, 2025 15:20:07.159179926 CET53594731.1.1.1192.168.2.4
        Mar 7, 2025 15:20:07.160152912 CET5873053192.168.2.41.1.1.1
        Mar 7, 2025 15:20:07.168100119 CET53587301.1.1.1192.168.2.4
        Mar 7, 2025 15:20:07.171986103 CET6210753192.168.2.41.1.1.1
        Mar 7, 2025 15:20:07.172163010 CET5359053192.168.2.41.1.1.1
        Mar 7, 2025 15:20:07.180867910 CET53621071.1.1.1192.168.2.4
        Mar 7, 2025 15:20:07.181365967 CET53535901.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.373200893 CET5138953192.168.2.41.1.1.1
        Mar 7, 2025 15:20:08.373402119 CET5767653192.168.2.41.1.1.1
        Mar 7, 2025 15:20:08.381524086 CET53576761.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.381865025 CET53513891.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.393034935 CET5805353192.168.2.41.1.1.1
        Mar 7, 2025 15:20:08.393307924 CET5667553192.168.2.41.1.1.1
        Mar 7, 2025 15:20:08.401837111 CET53580531.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.402306080 CET53566751.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.429476976 CET5754653192.168.2.41.1.1.1
        Mar 7, 2025 15:20:08.429838896 CET4958653192.168.2.48.8.8.8
        Mar 7, 2025 15:20:08.436484098 CET53575461.1.1.1192.168.2.4
        Mar 7, 2025 15:20:08.437170029 CET53495868.8.8.8192.168.2.4
        Mar 7, 2025 15:20:16.588171959 CET53590921.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 7, 2025 15:19:59.915672064 CET192.168.2.41.1.1.10xe490Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 7, 2025 15:19:59.915868998 CET192.168.2.41.1.1.10x3a8Standard query (0)www.google.com65IN (0x0001)false
        Mar 7, 2025 15:20:00.979038000 CET192.168.2.41.1.1.10x3dddStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:00.979227066 CET192.168.2.41.1.1.10x2deeStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:00.998712063 CET192.168.2.41.1.1.10x1b0fStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.001353025 CET192.168.2.41.1.1.10x3745Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.001734972 CET192.168.2.41.1.1.10xe02bStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:01.024709940 CET192.168.2.41.1.1.10xc55dStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.025121927 CET192.168.2.41.1.1.10xc02cStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:01.065150023 CET192.168.2.48.8.8.80x5a16Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.065731049 CET192.168.2.41.1.1.10x7ed1Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:02.105021954 CET192.168.2.41.1.1.10x99d8Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:02.111300945 CET192.168.2.41.1.1.10x9ccdStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:07.150234938 CET192.168.2.41.1.1.10x997fStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.150557041 CET192.168.2.41.1.1.10xd2b7Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:07.160152912 CET192.168.2.41.1.1.10x8880Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.171986103 CET192.168.2.41.1.1.10x4c0fStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.172163010 CET192.168.2.41.1.1.10x3f62Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:08.373200893 CET192.168.2.41.1.1.10x56ffStandard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.373402119 CET192.168.2.41.1.1.10xb428Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:08.393034935 CET192.168.2.41.1.1.10x8e62Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.393307924 CET192.168.2.41.1.1.10x25e7Standard query (0)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion65IN (0x0001)false
        Mar 7, 2025 15:20:08.429476976 CET192.168.2.41.1.1.10x3768Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.429838896 CET192.168.2.48.8.8.80x1dd2Standard query (0)google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 7, 2025 15:19:59.923039913 CET1.1.1.1192.168.2.40x3a8No error (0)www.google.com65IN (0x0001)false
        Mar 7, 2025 15:19:59.923846006 CET1.1.1.1192.168.2.40xe490No error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:00.989588022 CET1.1.1.1192.168.2.40x3dddName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:00.990911007 CET1.1.1.1192.168.2.40x2deeName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:01.008829117 CET1.1.1.1192.168.2.40x1b0fName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.012084961 CET1.1.1.1192.168.2.40x3745Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.012677908 CET1.1.1.1192.168.2.40xe02bName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:01.033927917 CET1.1.1.1192.168.2.40xc55dName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.033971071 CET1.1.1.1192.168.2.40xc02cName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:01.072710991 CET8.8.8.8192.168.2.40x5a16No error (0)google.com142.251.36.46A (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:01.072913885 CET1.1.1.1192.168.2.40x7ed1No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:02.113575935 CET1.1.1.1192.168.2.40x99d8Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:02.119956017 CET1.1.1.1192.168.2.40x9ccdName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:07.159162045 CET1.1.1.1192.168.2.40xd2b7Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:07.159179926 CET1.1.1.1192.168.2.40x997fName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.168100119 CET1.1.1.1192.168.2.40x8880Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.180867910 CET1.1.1.1192.168.2.40x4c0fName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:07.181365967 CET1.1.1.1192.168.2.40x3f62Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:08.381524086 CET1.1.1.1192.168.2.40xb428Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:08.381865025 CET1.1.1.1192.168.2.40x56ffName error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.401837111 CET1.1.1.1192.168.2.40x8e62Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenoneA (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.402306080 CET1.1.1.1192.168.2.40x25e7Name error (3)lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onionnonenone65IN (0x0001)false
        Mar 7, 2025 15:20:08.436484098 CET1.1.1.1192.168.2.40x3768No error (0)google.com142.250.185.142A (IP address)IN (0x0001)false
        Mar 7, 2025 15:20:08.437170029 CET8.8.8.8192.168.2.40x1dd2No error (0)google.com142.251.36.46A (IP address)IN (0x0001)false

        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:1
        Start time:09:19:50
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:09:19:54
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2176,i,5256345546358794950,5354833833403800214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2264 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:9
        Start time:09:19:59
        Start date:07/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lockbitspyakyequybgwgwauhzqxx7ba2gh3lmlj3zyeuaknrexdzfid.onion"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly