Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://lketamaskloginn.webflow.io

Overview

General Information

Sample URL:https://lketamaskloginn.webflow.io
Analysis ID:1637102
Tags:tweetfeed
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
AI detected suspicious URL

Classification

  • System is w10x64
  • chrome.exe (PID: 5500 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,9236901982138310178,4772453064813575690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2120 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6800 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lketamaskloginn.webflow.io" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://lketamaskloginn.webflow.ioAvira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://lketamaskloginn.webflow.ioJoe Sandbox AI: The URL 'lketamaskloginn.webflow.io' appears to be a typosquatting attempt targeting the known brand MetaMask. The character 'l' is visually similar to 'i', and 'loginn' suggests a login page, which is a common phishing tactic. The use of 'webflow.io' as a domain extension is not inherently suspicious, but the combination of visual character substitution and the context of a login page increases the likelihood of user confusion. The structural similarity to the legitimate MetaMask URL and the context of a login page suggest a high likelihood of typosquatting.
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CO6MywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: lketamaskloginn.webflow.io
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: classification engineClassification label: mal52.win@22/2@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,9236901982138310178,4772453064813575690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2120 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lketamaskloginn.webflow.io"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,9236901982138310178,4772453064813575690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2120 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lketamaskloginn.webflow.io100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    high
    lketamaskloginn.webflow.io
    104.18.36.248
    truetrue
      unknown
      www.google.com
      142.250.186.100
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          104.18.36.248
          lketamaskloginn.webflow.ioUnited States
          13335CLOUDFLARENETUStrue
          142.250.186.100
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.6
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1637102
          Start date and time:2025-03-13 11:01:27 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 56s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://lketamaskloginn.webflow.io
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:15
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal52.win@22/2@4/3
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe, TextInputHost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.250.185.206, 64.233.166.84, 172.217.16.206, 142.250.184.206, 142.250.185.110, 142.250.186.78, 172.217.18.14, 52.149.20.212, 199.232.214.172, 40.69.42.241, 142.250.186.110, 23.199.214.10
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, redirector.gvt1.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: https://lketamaskloginn.webflow.io
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (3532)
          Category:downloaded
          Size (bytes):3537
          Entropy (8bit):5.872533001481223
          Encrypted:false
          SSDEEP:96:LFHz1vlzedR0Wo0IRUCYZTMLy19DC45PKXffQffo:jNzS0Wo0IfV2ZD5Pq
          MD5:94C1C1AE83A63F542ADC3B3744E86132
          SHA1:F125CEF371854294848886291ED5F28DA826C610
          SHA-256:AE556FB36CB1BB8EE411F11A5F34C48AF6D4B862BE6A67837BE9EF286324F7DE
          SHA-512:C95EE157EDB8738481A8CFBF9D3C26ED2F389051B8463CAA2059D023C1D759BAD5DBBEF5757B8C3500D716C655190A26B2B4CE88F655B84D6EE870C145A5ED5D
          Malicious:false
          Reputation:low
          URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
          Preview:)]}'.["",["$725 stimulus checks","gta 6 rockstar games","capricorn daily horoscope today","nba lakers","google pixel 10 pro","nasa spacex crew 10 launch","landman renewed","college basketball tournament bracket"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"google:entityinfo":"CggvbS8wam1rNxImTG9zIEFuZ2VsZXMgTGFrZXJzIOKAlCBCYXNrZXRiYWxsIHRlYW0yyg5kYXRhOmltYWdlL3BuZztiYXNlNjQsaVZCT1J3MEtHZ29BQUFBTlNVaEVVZ0FBQUVBQUFBQW9DQU1BQUFCNUVBemJBQUFCS1ZCTVZFWC8vLy85dVNmL3ZDai92U1AvdmlnQUFIUC92eUgvd1I4QUFGdi93eDBZQUhJZ0FISFN6dHpaMXVJWEFHUzZoRW93QUcrMWhSejV0aXIwc2kzNCtQcnE2TzhwQUhDd2ZFNjBmMHppcERmZjNPYVJocXZQbUNDS1pSVnlWQkxBalI3a3B5T2lkeG5ycGdEVW1UN25xRFRId3RSREhXeHZSbUtnYjFSMFNtRy9pRWpJajBTbWRGRyt1TTJZYUZhT1lWcFZMMmlFV0Z5aW1yamJuanVscUt1U2huU1Nka1JyVEFCY1JocWFucVRVMk4yMHVzS05kRXJCaGdDVFp3RFFrd0NBWmphbmRRQ0ppSVY5VWdCM1pVbGlTQTh3SHdCM
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Mar 13, 2025 11:02:19.371556044 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:19.682816029 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:20.292197943 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:21.495287895 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:23.902179956 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:26.662530899 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:26.662560940 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:26.662622929 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:26.662940025 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:26.662951946 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:27.407073975 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.407119036 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:27.407181025 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.407476902 CET49705443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.407505989 CET44349705104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:27.407572985 CET49705443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.407852888 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.407866001 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:27.408085108 CET49705443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:27.408099890 CET44349705104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:27.986108065 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:28.292649031 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:28.707676888 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:28.892481089 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:29.159018040 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:29.160296917 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:29.160331964 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:29.161323071 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:29.161372900 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:29.172621012 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:29.172795057 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:29.216020107 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:29.216042042 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:29.262562037 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:30.093219995 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:31.314546108 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.314610958 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.314625978 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.332130909 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.332220078 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.332353115 CET49704443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.332365036 CET44349704104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.332847118 CET49707443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.332892895 CET44349707104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.332963943 CET49707443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.333358049 CET49707443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.333384991 CET44349707104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.464337111 CET44349705104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.464420080 CET49705443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.464589119 CET49705443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.464615107 CET44349705104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.464982033 CET49708443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.465034962 CET44349708104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:31.465121031 CET49708443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.465439081 CET49708443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:31.465452909 CET44349708104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:32.497740030 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:34.491765976 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:34.536325932 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.009572029 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.009622097 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.009648085 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.009681940 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:35.009701014 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.009881973 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:35.011004925 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:35.011043072 CET44349701142.250.186.100192.168.2.6
          Mar 13, 2025 11:02:35.011096001 CET49701443192.168.2.6142.250.186.100
          Mar 13, 2025 11:02:35.066986084 CET44349707104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:35.067209959 CET49707443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:35.091025114 CET49707443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:35.091074944 CET44349707104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:35.121028900 CET44349708104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:35.121104956 CET49708443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:35.287189960 CET49708443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:35.287225962 CET44349708104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:36.302165985 CET49711443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.302225113 CET44349711104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:36.302289963 CET49711443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.302428007 CET49712443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.302468061 CET44349712104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:36.302520990 CET49712443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.302880049 CET49711443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.302901030 CET44349711104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:36.303145885 CET49712443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:36.303158045 CET44349712104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:37.311450005 CET49678443192.168.2.620.42.65.91
          Mar 13, 2025 11:02:38.312264919 CET49672443192.168.2.6204.79.197.203
          Mar 13, 2025 11:02:40.176888943 CET44349711104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.177036047 CET49711443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.177169085 CET49711443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.177187920 CET44349711104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.177783012 CET49714443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.177839994 CET44349714104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.177917957 CET49714443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.178204060 CET49714443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.178232908 CET44349714104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.264039993 CET44349712104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.264111996 CET49712443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.264266968 CET49712443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.264283895 CET44349712104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.264718056 CET49715443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.264755011 CET44349715104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:40.264803886 CET49715443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.265125036 CET49715443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:40.265140057 CET44349715104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:43.848236084 CET44349715104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:43.848321915 CET49715443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:43.848450899 CET49715443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:43.848469019 CET44349715104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:43.863925934 CET44349714104.18.36.248192.168.2.6
          Mar 13, 2025 11:02:43.867697001 CET49714443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:43.867784977 CET49714443192.168.2.6104.18.36.248
          Mar 13, 2025 11:02:43.867826939 CET44349714104.18.36.248192.168.2.6
          TimestampSource PortDest PortSource IPDest IP
          Mar 13, 2025 11:02:22.239342928 CET53622931.1.1.1192.168.2.6
          Mar 13, 2025 11:02:22.280915976 CET53531211.1.1.1192.168.2.6
          Mar 13, 2025 11:02:25.955914974 CET53630181.1.1.1192.168.2.6
          Mar 13, 2025 11:02:26.224616051 CET53528501.1.1.1192.168.2.6
          Mar 13, 2025 11:02:26.654906034 CET5529053192.168.2.61.1.1.1
          Mar 13, 2025 11:02:26.655081987 CET5635853192.168.2.61.1.1.1
          Mar 13, 2025 11:02:26.661537886 CET53552901.1.1.1192.168.2.6
          Mar 13, 2025 11:02:26.661689043 CET53563581.1.1.1192.168.2.6
          Mar 13, 2025 11:02:27.393435001 CET5907653192.168.2.61.1.1.1
          Mar 13, 2025 11:02:27.393649101 CET5057353192.168.2.61.1.1.1
          Mar 13, 2025 11:02:27.402452946 CET53590761.1.1.1192.168.2.6
          Mar 13, 2025 11:02:27.405708075 CET53505731.1.1.1192.168.2.6
          Mar 13, 2025 11:02:43.269864082 CET53556601.1.1.1192.168.2.6
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 13, 2025 11:02:26.654906034 CET192.168.2.61.1.1.10x5272Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:26.655081987 CET192.168.2.61.1.1.10x5cf5Standard query (0)www.google.com65IN (0x0001)false
          Mar 13, 2025 11:02:27.393435001 CET192.168.2.61.1.1.10x536eStandard query (0)lketamaskloginn.webflow.ioA (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:27.393649101 CET192.168.2.61.1.1.10xbf8cStandard query (0)lketamaskloginn.webflow.io65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 13, 2025 11:02:26.661537886 CET1.1.1.1192.168.2.60x5272No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:26.661689043 CET1.1.1.1192.168.2.60x5cf5No error (0)www.google.com65IN (0x0001)false
          Mar 13, 2025 11:02:27.402452946 CET1.1.1.1192.168.2.60x536eNo error (0)lketamaskloginn.webflow.io104.18.36.248A (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:27.402452946 CET1.1.1.1192.168.2.60x536eNo error (0)lketamaskloginn.webflow.io172.64.151.8A (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:27.405708075 CET1.1.1.1192.168.2.60xbf8cNo error (0)lketamaskloginn.webflow.io65IN (0x0001)false
          Mar 13, 2025 11:02:38.820199966 CET1.1.1.1192.168.2.60x7fd9No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
          Mar 13, 2025 11:02:38.820199966 CET1.1.1.1192.168.2.60x7fd9No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
          • www.google.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.649701142.250.186.100443992C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-13 10:02:34 UTC487OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
          Host: www.google.com
          Connection: keep-alive
          X-Client-Data: CO6MywE=
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: empty
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-13 10:02:35 UTC1303INHTTP/1.1 200 OK
          Date: Thu, 13 Mar 2025 10:02:34 GMT
          Pragma: no-cache
          Expires: -1
          Cache-Control: no-cache, must-revalidate
          Content-Type: text/javascript; charset=UTF-8
          Strict-Transport-Security: max-age=31536000
          Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-2YVk_wXnTRy1oBIIvWDEJg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
          Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
          Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
          Accept-CH: Sec-CH-Prefers-Color-Scheme
          Accept-CH: Downlink
          Accept-CH: RTT
          Accept-CH: Sec-CH-UA-Form-Factors
          Accept-CH: Sec-CH-UA-Platform
          Accept-CH: Sec-CH-UA-Platform-Version
          Accept-CH: Sec-CH-UA-Full-Version
          Accept-CH: Sec-CH-UA-Arch
          Accept-CH: Sec-CH-UA-Model
          Accept-CH: Sec-CH-UA-Bitness
          Accept-CH: Sec-CH-UA-Full-Version-List
          Accept-CH: Sec-CH-UA-WoW64
          Permissions-Policy: unload=()
          Content-Disposition: attachment; filename="f.txt"
          Server: gws
          X-XSS-Protection: 0
          X-Frame-Options: SAMEORIGIN
          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
          Accept-Ranges: none
          Vary: Accept-Encoding
          Connection: close
          Transfer-Encoding: chunked
          2025-03-13 10:02:35 UTC75INData Raw: 64 64 31 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 24 37 32 35 20 73 74 69 6d 75 6c 75 73 20 63 68 65 63 6b 73 22 2c 22 67 74 61 20 36 20 72 6f 63 6b 73 74 61 72 20 67 61 6d 65 73 22 2c 22 63 61 70 72 69 63 6f 72 6e 20 64 61 69
          Data Ascii: dd1)]}'["",["$725 stimulus checks","gta 6 rockstar games","capricorn dai
          2025-03-13 10:02:35 UTC1378INData Raw: 6c 79 20 68 6f 72 6f 73 63 6f 70 65 20 74 6f 64 61 79 22 2c 22 6e 62 61 20 6c 61 6b 65 72 73 22 2c 22 67 6f 6f 67 6c 65 20 70 69 78 65 6c 20 31 30 20 70 72 6f 22 2c 22 6e 61 73 61 20 73 70 61 63 65 78 20 63 72 65 77 20 31 30 20 6c 61 75 6e 63 68 22 2c 22 6c 61 6e 64 6d 61 6e 20 72 65 6e 65 77 65 64 22 2c 22 63 6f 6c 6c 65 67 65 20 62 61 73 6b 65 74 62 61 6c 6c 20 74 6f 75 72 6e 61 6d 65 6e 74 20 62 72 61 63 6b 65 74 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70 73 69 6e 66 6f 22 3a 22 43 68 6f 49 6b 6b 34 53 46 51 6f 52 56 48 4a
          Data Ascii: ly horoscope today","nba lakers","google pixel 10 pro","nasa spacex crew 10 launch","landman renewed","college basketball tournament bracket"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJ
          2025-03-13 10:02:35 UTC1378INData Raw: 44 4d 34 62 6c 64 6b 64 46 46 7a 53 56 46 34 55 48 46 6b 52 6b 56 48 51 7a 41 31 52 33 51 35 64 6d 46 50 57 54 63 77 63 57 70 45 4d 6e 70 49 51 33 52 52 61 43 74 6a 54 45 35 53 61 55 46 42 53 79 39 4e 54 6b 64 48 62 6a 56 7a 62 46 64 76 54 55 6c 6a 51 57 6c 30 62 31 56 4b 56 55 35 6e 52 6c 64 6a 52 57 63 76 4c 31 4a 6d 57 55 74 6c 63 30 4a 6c 4c 7a 6c 50 55 46 6c 34 62 6e 5a 79 52 55 35 6f 52 45 78 5a 5a 33 5a 56 53 6a 4a 53 63 55 6f 30 62 6e 5a 30 57 44 52 50 64 45 74 42 55 30 39 4b 53 56 52 68 53 6c 63 77 64 6b 63 31 63 6c 4a 53 63 32 39 4c 61 6c 64 42 5a 30 5a 42 4c 30 31 68 54 31 4a 55 56 30 39 69 4d 6b 34 30 53 46 42 71 4b 32 52 6c 62 54 41 33 4c 33 46 6f 57 46 56 72 4d 6c 4a 77 54 56 68 46 55 31 51 72 64 6b 56 33 52 44 4e 33 62 6c 49 7a 54 30 56 68
          Data Ascii: DM4bldkdFFzSVF4UHFkRkVHQzA1R3Q5dmFPWTcwcWpEMnpIQ3RRaCtjTE5SaUFBSy9NTkdHbjVzbFdvTUljQWl0b1VKVU5nRldjRWcvL1JmWUtlc0JlLzlPUFl4bnZyRU5oRExZZ3ZVSjJScUo0bnZ0WDRPdEtBU09KSVRhSlcwdkc1clJSc29LaldBZ0ZBL01hT1JUV09iMk40SFBqK2RlbTA3L3FoWFVrMlJwTVhFU1QrdkV3RDN3blIzT0Vh
          2025-03-13 10:02:35 UTC713INData Raw: 35 4e 6c 42 54 4e 46 6c 57 51 31 5a 6d 4e 57 78 47 62 32 35 48 4b 30 78 43 65 55 4a 73 59 30 70 51 57 6b 74 4c 56 55 56 44 54 7a 4e 35 65 45 31 53 4e 32 6b 31 53 6d 6c 57 52 32 68 48 4b 33 6c 56 52 6e 56 36 57 6a 63 30 62 47 4a 49 4c 7a 64 77 61 6b 46 30 59 6d 39 4e 64 32 38 31 62 57 30 35 62 44 4e 4b 4e 58 6b 35 64 44 4d 34 5a 6b 67 77 53 57 4d 33 57 6a 51 34 4e 6e 68 30 62 6c 4e 69 53 69 39 7a 55 44 6c 7a 4f 45 74 69 65 45 51 30 65 47 35 69 52 47 74 4b 54 45 64 36 5a 45 46 42 51 55 46 42 52 57 78 47 56 47 74 54 64 56 46 74 51 30 4d 36 43 6d 35 69 59 53 42 73 59 57 74 6c 63 6e 4e 4b 42 79 4d 35 4f 54 63 77 4d 54 68 53 4d 6d 64 7a 58 33 4e 7a 63 44 31 6c 53 6e 70 71 4e 48 52 45 55 44 46 55 5a 6b 6c 35 63 7a 41 79 54 6a 4a 45 4d 44 52 7a 63 45 78 54 62 46
          Data Ascii: 5NlBTNFlWQ1ZmNWxGb25HK0xCeUJsY0pQWktLVUVDTzN5eE1SN2k1SmlWR2hHK3lVRnV6Wjc0bGJILzdwakF0Ym9Nd281bW05bDNKNXk5dDM4ZkgwSWM3WjQ4Nnh0blNiSi9zUDlzOEtieEQ0eG5iRGtKTEd6ZEFBQUFBRWxGVGtTdVFtQ0M6Cm5iYSBsYWtlcnNKByM5OTcwMThSMmdzX3NzcD1lSnpqNHREUDFUZkl5czAyTjJEMDRzcExTbF
          2025-03-13 10:02:35 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:1
          Start time:06:02:17
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff63b000000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:06:02:21
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1968,i,9236901982138310178,4772453064813575690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2120 /prefetch:3
          Imagebase:0x7ff63b000000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:7
          Start time:06:02:26
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lketamaskloginn.webflow.io"
          Imagebase:0x7ff63b000000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly