Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://supportlope.com

Overview

General Information

Sample URL:http://supportlope.com
Analysis ID:1637284
Infos:
Errors
  • URL not reachable

Detection

Score:20
Range:0 - 100
Confidence:80%

Signatures

AI detected suspicious URL

Classification

  • System is w10x64
  • chrome.exe (PID: 6324 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6692 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,14157331331792984495,17620880303711187338,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2060 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 3792 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://supportlope.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: http://supportlope.comJoe Sandbox AI: The URL 'supportlope.com' appears to be a typosquatting attempt on 'support.paypal.com'. The word 'lope' is visually similar to 'paypal', with 'l' and 'p' being common visual substitutions. The structure of the URL mimics a support subdomain, which is commonly used by PayPal. The use of 'support' as a subdomain suggests an attempt to mislead users into thinking they are accessing a legitimate PayPal support page. The domain does not suggest a different legitimate purpose unrelated to PayPal, increasing the likelihood of it being a typosquatting attempt.
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJahywEInP7MAQiFoM0BCO2pzgEIvtXOAQiB1s4BCMDYzgEIyNzOAQiK4M4BCMnhzgEIruTOAQiL5c4BSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: supportlope.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: classification engineClassification label: sus20.win@21/2@18/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,14157331331792984495,17620880303711187338,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2060 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://supportlope.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,14157331331792984495,17620880303711187338,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2060 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1637284 URL: http://supportlope.com Startdate: 13/03/2025 Architecture: WINDOWS Score: 20 15 supportlope.com 2->15 25 AI detected suspicious URL 2->25 7 chrome.exe 2->7         started        10 chrome.exe 2->10         started        signatures3 process4 dnsIp5 17 192.168.2.4, 443, 49279, 49632 unknown unknown 7->17 12 chrome.exe 7->12         started        process6 dnsIp7 19 www.google.com 142.250.185.68, 443, 49736 GOOGLEUS United States 12->19 21 supportlope.com 12->21 23 google.com 12->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://supportlope.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.185.110
truefalse
    high
    www.google.com
    142.250.185.68
    truefalse
      high
      supportlope.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.185.68
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1637284
          Start date and time:2025-03-13 13:43:13 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 9s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://supportlope.com
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:17
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:SUS
          Classification:sus20.win@21/2@18/2
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.186.35, 216.58.212.142, 74.125.206.84, 142.250.185.78, 216.58.206.78, 142.250.185.110, 142.250.184.206, 142.250.186.110, 4.245.163.56, 13.95.31.18, 23.60.203.209
          • Excluded domains from analysis (whitelisted): fe3.delivery.mp.microsoft.com, fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: http://supportlope.com
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (896)
          Category:downloaded
          Size (bytes):901
          Entropy (8bit):5.15396193111741
          Encrypted:false
          SSDEEP:24:hpPM+laByRzumBHslgT1d1uawBAT/1uoBN2t2t2t2t2t2t2tomffffffo:hpPM+IfmKlgJXwBAT1uSNYYYYYYYomfg
          MD5:C7860853162182B722A563CE575B7E92
          SHA1:9C0075A6EE06E237EA2112D38FC1D7373A2EA689
          SHA-256:30B93EEBCD98F709DFFA9805B6A0A9FB11C9C0BFE58FCCAE3523E9F6EFA0D58C
          SHA-512:3238547FDDF8604BA862405720F2754EEACD2FE8D007532077E0B141180B64DF9733497A99EB03053590F1730564A218B9DCDE39EA56143617BFA290E2DFA628
          Malicious:false
          Reputation:low
          URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
          Preview:)]}'.["",["college basketball tournament bracket","st patrick day parade baton rouge","zodiac signs daily horoscope today","google android decision","stores closing","blood moon total lunar eclipse","minnesota timberwolves denver nuggets","playstation plus games"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggesteventid":"-5184363927911328712","google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Mar 13, 2025 13:44:12.401938915 CET49671443192.168.2.4204.79.197.203
          Mar 13, 2025 13:44:12.558339119 CET49680443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:13.605053902 CET49671443192.168.2.4204.79.197.203
          Mar 13, 2025 13:44:16.011307001 CET49671443192.168.2.4204.79.197.203
          Mar 13, 2025 13:44:20.823831081 CET49671443192.168.2.4204.79.197.203
          Mar 13, 2025 13:44:22.167546988 CET49680443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:22.430320024 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:22.730241060 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:23.480055094 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:24.776170969 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:27.182483912 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:27.895350933 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:27.895395994 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:27.895518064 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:27.895781040 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:27.895788908 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.869148970 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.876600027 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:29.876617908 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.877835035 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.878468037 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:29.879893064 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:29.879965067 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.924066067 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:29.924081087 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:29.970412016 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:30.441466093 CET49671443192.168.2.4204.79.197.203
          Mar 13, 2025 13:44:31.631423950 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.634176016 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.634200096 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.637012959 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.639765024 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.639775991 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.725552082 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.725616932 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.726202965 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.730895996 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.818315983 CET44349711204.79.197.222192.168.2.4
          Mar 13, 2025 13:44:31.819088936 CET49711443192.168.2.4204.79.197.222
          Mar 13, 2025 13:44:31.985616922 CET49678443192.168.2.420.189.173.27
          Mar 13, 2025 13:44:33.125869989 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:33.168327093 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:33.709783077 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:33.710012913 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:33.710110903 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:33.712330103 CET49736443192.168.2.4142.250.185.68
          Mar 13, 2025 13:44:33.712352037 CET44349736142.250.185.68192.168.2.4
          Mar 13, 2025 13:44:41.597863913 CET49678443192.168.2.420.189.173.27
          TimestampSource PortDest PortSource IPDest IP
          Mar 13, 2025 13:44:23.784295082 CET53627351.1.1.1192.168.2.4
          Mar 13, 2025 13:44:23.806910038 CET53621061.1.1.1192.168.2.4
          Mar 13, 2025 13:44:27.505810976 CET53614911.1.1.1192.168.2.4
          Mar 13, 2025 13:44:27.786335945 CET53605041.1.1.1192.168.2.4
          Mar 13, 2025 13:44:27.886810064 CET5040253192.168.2.41.1.1.1
          Mar 13, 2025 13:44:27.887170076 CET5058953192.168.2.41.1.1.1
          Mar 13, 2025 13:44:27.893424034 CET53504021.1.1.1192.168.2.4
          Mar 13, 2025 13:44:27.894378901 CET53505891.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.332084894 CET6147953192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.332252026 CET5772053192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.342437983 CET53614791.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.343319893 CET53577201.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.344270945 CET4963253192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.354036093 CET53496321.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.357034922 CET6328253192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.357192993 CET5417453192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.364487886 CET53632821.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.367121935 CET53541741.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.411293030 CET5245053192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.411700964 CET5418253192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.421783924 CET53524501.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.430039883 CET53541821.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.524897099 CET5642153192.168.2.48.8.8.8
          Mar 13, 2025 13:44:29.525194883 CET6465253192.168.2.41.1.1.1
          Mar 13, 2025 13:44:29.531744957 CET53646521.1.1.1192.168.2.4
          Mar 13, 2025 13:44:29.539946079 CET53564218.8.8.8192.168.2.4
          Mar 13, 2025 13:44:30.539386988 CET5976753192.168.2.41.1.1.1
          Mar 13, 2025 13:44:30.539618015 CET5131553192.168.2.41.1.1.1
          Mar 13, 2025 13:44:30.548661947 CET53597671.1.1.1192.168.2.4
          Mar 13, 2025 13:44:30.549149990 CET53513151.1.1.1192.168.2.4
          Mar 13, 2025 13:44:30.555067062 CET5273153192.168.2.41.1.1.1
          Mar 13, 2025 13:44:30.555203915 CET6221453192.168.2.41.1.1.1
          Mar 13, 2025 13:44:30.562112093 CET53527311.1.1.1192.168.2.4
          Mar 13, 2025 13:44:30.564366102 CET53622141.1.1.1192.168.2.4
          Mar 13, 2025 13:44:35.597347975 CET5637753192.168.2.41.1.1.1
          Mar 13, 2025 13:44:35.597783089 CET5419753192.168.2.41.1.1.1
          Mar 13, 2025 13:44:35.606760979 CET53563771.1.1.1192.168.2.4
          Mar 13, 2025 13:44:35.608526945 CET53541971.1.1.1192.168.2.4
          Mar 13, 2025 13:44:35.615536928 CET4927953192.168.2.41.1.1.1
          Mar 13, 2025 13:44:35.625214100 CET53492791.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 13, 2025 13:44:27.886810064 CET192.168.2.41.1.1.10xbcStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:27.887170076 CET192.168.2.41.1.1.10xd475Standard query (0)www.google.com65IN (0x0001)false
          Mar 13, 2025 13:44:29.332084894 CET192.168.2.41.1.1.10x3faStandard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.332252026 CET192.168.2.41.1.1.10xb702Standard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:29.344270945 CET192.168.2.41.1.1.10x2b81Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.357034922 CET192.168.2.41.1.1.10xddc8Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.357192993 CET192.168.2.41.1.1.10x939dStandard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:29.411293030 CET192.168.2.41.1.1.10x7333Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.411700964 CET192.168.2.41.1.1.10x352cStandard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:29.524897099 CET192.168.2.48.8.8.80xd0e9Standard query (0)google.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.525194883 CET192.168.2.41.1.1.10x132fStandard query (0)google.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.539386988 CET192.168.2.41.1.1.10x30c4Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.539618015 CET192.168.2.41.1.1.10xd619Standard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:30.555067062 CET192.168.2.41.1.1.10x37ffStandard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.555203915 CET192.168.2.41.1.1.10x3599Standard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:35.597347975 CET192.168.2.41.1.1.10xf2c3Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:35.597783089 CET192.168.2.41.1.1.10xcf56Standard query (0)supportlope.com65IN (0x0001)false
          Mar 13, 2025 13:44:35.615536928 CET192.168.2.41.1.1.10xccc9Standard query (0)supportlope.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 13, 2025 13:44:27.893424034 CET1.1.1.1192.168.2.40xbcNo error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:27.894378901 CET1.1.1.1192.168.2.40xd475No error (0)www.google.com65IN (0x0001)false
          Mar 13, 2025 13:44:29.342437983 CET1.1.1.1192.168.2.40x3faName error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.343319893 CET1.1.1.1192.168.2.40xb702Name error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:29.354036093 CET1.1.1.1192.168.2.40x2b81Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.364487886 CET1.1.1.1192.168.2.40xddc8Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.367121935 CET1.1.1.1192.168.2.40x939dName error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:29.421783924 CET1.1.1.1192.168.2.40x7333Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.430039883 CET1.1.1.1192.168.2.40x352cName error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:29.531744957 CET1.1.1.1192.168.2.40x132fNo error (0)google.com142.250.185.110A (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:29.539946079 CET8.8.8.8192.168.2.40xd0e9No error (0)google.com142.251.37.14A (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.548661947 CET1.1.1.1192.168.2.40x30c4Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.549149990 CET1.1.1.1192.168.2.40xd619Name error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:30.562112093 CET1.1.1.1192.168.2.40x37ffName error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:30.564366102 CET1.1.1.1192.168.2.40x3599Name error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:35.606760979 CET1.1.1.1192.168.2.40xf2c3Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          Mar 13, 2025 13:44:35.608526945 CET1.1.1.1192.168.2.40xcf56Name error (3)supportlope.comnonenone65IN (0x0001)false
          Mar 13, 2025 13:44:35.625214100 CET1.1.1.1192.168.2.40xccc9Name error (3)supportlope.comnonenoneA (IP address)IN (0x0001)false
          • www.google.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449736142.250.185.684436692C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-03-13 12:44:33 UTC599OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
          Host: www.google.com
          Connection: keep-alive
          X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJahywEInP7MAQiFoM0BCO2pzgEIvtXOAQiB1s4BCMDYzgEIyNzOAQiK4M4BCMnhzgEIruTOAQiL5c4B
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: empty
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-03-13 12:44:33 UTC1303INHTTP/1.1 200 OK
          Date: Thu, 13 Mar 2025 12:44:33 GMT
          Pragma: no-cache
          Expires: -1
          Cache-Control: no-cache, must-revalidate
          Content-Type: text/javascript; charset=UTF-8
          Strict-Transport-Security: max-age=31536000
          Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce--ax3uAVyiTdWC5FmPkzwsQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
          Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
          Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
          Accept-CH: Sec-CH-Prefers-Color-Scheme
          Accept-CH: Downlink
          Accept-CH: RTT
          Accept-CH: Sec-CH-UA-Form-Factors
          Accept-CH: Sec-CH-UA-Platform
          Accept-CH: Sec-CH-UA-Platform-Version
          Accept-CH: Sec-CH-UA-Full-Version
          Accept-CH: Sec-CH-UA-Arch
          Accept-CH: Sec-CH-UA-Model
          Accept-CH: Sec-CH-UA-Bitness
          Accept-CH: Sec-CH-UA-Full-Version-List
          Accept-CH: Sec-CH-UA-WoW64
          Permissions-Policy: unload=()
          Content-Disposition: attachment; filename="f.txt"
          Server: gws
          X-XSS-Protection: 0
          X-Frame-Options: SAMEORIGIN
          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
          Accept-Ranges: none
          Vary: Accept-Encoding
          Connection: close
          Transfer-Encoding: chunked
          2025-03-13 12:44:33 UTC39INData Raw: 33 38 35 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 63 6f 6c 6c 65 67 65 20 62 61 73 6b 65 74 62 61 6c 6c 20 74 6f 75 72
          Data Ascii: 385)]}'["",["college basketball tour
          2025-03-13 12:44:33 UTC869INData Raw: 6e 61 6d 65 6e 74 20 62 72 61 63 6b 65 74 22 2c 22 73 74 20 70 61 74 72 69 63 6b 20 64 61 79 20 70 61 72 61 64 65 20 62 61 74 6f 6e 20 72 6f 75 67 65 22 2c 22 7a 6f 64 69 61 63 20 73 69 67 6e 73 20 64 61 69 6c 79 20 68 6f 72 6f 73 63 6f 70 65 20 74 6f 64 61 79 22 2c 22 67 6f 6f 67 6c 65 20 61 6e 64 72 6f 69 64 20 64 65 63 69 73 69 6f 6e 22 2c 22 73 74 6f 72 65 73 20 63 6c 6f 73 69 6e 67 22 2c 22 62 6c 6f 6f 64 20 6d 6f 6f 6e 20 74 6f 74 61 6c 20 6c 75 6e 61 72 20 65 63 6c 69 70 73 65 22 2c 22 6d 69 6e 6e 65 73 6f 74 61 20 74 69 6d 62 65 72 77 6f 6c 76 65 73 20 64 65 6e 76 65 72 20 6e 75 67 67 65 74 73 22 2c 22 70 6c 61 79 73 74 61 74 69 6f 6e 20 70 6c 75 73 20 67 61 6d 65 73 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22
          Data Ascii: nament bracket","st patrick day parade baton rouge","zodiac signs daily horoscope today","google android decision","stores closing","blood moon total lunar eclipse","minnesota timberwolves denver nuggets","playstation plus games"],["","","","","","","",""
          2025-03-13 12:44:33 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:1
          Start time:08:44:16
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff786830000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:4
          Start time:08:44:21
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,14157331331792984495,17620880303711187338,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2060 /prefetch:3
          Imagebase:0x7ff786830000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:13
          Start time:08:44:28
          Start date:13/03/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://supportlope.com"
          Imagebase:0x7ff786830000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly