Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
ATT16342.html

Overview

General Information

Sample Name:ATT16342.html
Analysis ID:756272
MD5:9b3a5b0636ee04ffd5560c7bbeacc1e2
SHA1:2aa758ad0ea7a17fee0af1c0df392bc9b2984db4
SHA256:bc67d13fb61a853de8c5db8e552689f1a80d7d2c7ea08eb27a4c12821bc0e24a
Infos:

Detection

HTMLPhisher
Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish44
Performs DNS queries to domains with low reputation
IP address seen in connection with other malware
Internet Provider seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 2884 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4844 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1768 --field-trial-handle=1776,i,2414851685685751221,11507612187326661899,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6356 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\ATT16342.html MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
ATT16342.htmlJoeSecurity_HtmlPhish_44Yara detected HtmlPhish_44Joe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    Phishing

    barindex
    Source: Yara matchFile source: ATT16342.html, type: SAMPLE
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior

    Networking

    barindex
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: iwa3o928023892301012091209255453.xyz
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: iwa3o928023892301012091209255453.xyz
    Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
    Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
    Source: Joe Sandbox ViewASN Name: SOLARCOMCH SOLARCOMCH
    Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /toazure.js HTTP/1.1Host: interc0mpanyc0mmunications98749378430329083.azurefd.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: unknownDNS traffic detected: queries for: accounts.google.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
    Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
    Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
    Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
    Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
    Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
    Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
    Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
    Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
    Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
    Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
    Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: classification engineClassification label: mal52.phis.troj.winHTML@37/0@9/8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1768 --field-trial-handle=1776,i,2414851685685751221,11507612187326661899,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\ATT16342.html
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1768 --field-trial-handle=1776,i,2414851685685751221,11507612187326661899,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath Interception1
    Process Injection
    2
    Masquerading
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    Process Injection
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
    Non-Application Layer Protocol
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
    Ingress Tool Transfer
    SIM Card SwapCarrier Billing Fraud
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    ATT16342.html2%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    part-0032.t-0009.t-msedge.net0%VirustotalBrowse
    interc0mpanyc0mmunications98749378430329083.azurefd.net0%VirustotalBrowse
    SourceDetectionScannerLabelLink
    https://interc0mpanyc0mmunications98749378430329083.azurefd.net/toazure.js0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    accounts.google.com
    172.217.168.45
    truefalse
      high
      part-0032.t-0009.t-msedge.net
      13.107.246.60
      truefalseunknown
      www.google.com
      172.217.168.68
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          iwa3o928023892301012091209255453.xyz
          95.183.51.48
          truetrue
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              interc0mpanyc0mmunications98749378430329083.azurefd.net
              unknown
              unknownfalseunknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  https://interc0mpanyc0mmunications98749378430329083.azurefd.net/toazure.jsfalse
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  95.183.51.48
                  iwa3o928023892301012091209255453.xyzSwitzerland
                  197988SOLARCOMCHtrue
                  172.217.168.68
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  172.217.168.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.203.110
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  13.107.246.60
                  part-0032.t-0009.t-msedge.netUnited States
                  8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:756272
                  Start date and time:2022-11-29 22:46:57 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 48s
                  Hypervisor based Inspection enabled:false
                  Report type:light
                  Sample file name:ATT16342.html
                  Cookbook file name:defaultwindowshtmlcookbook.jbs
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal52.phis.troj.winHTML@37/0@9/8
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Found application associated with file extension: .html
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe, svchost.exe
                  • TCP Packets have been reduced to 100
                  • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): client.wns.windows.com, edgedl.me.gvt1.com, star-azurefd-prod.trafficmanager.net, update.googleapis.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  File type:HTML document, ASCII text, with very long lines (65536), with no line terminators
                  Entropy (8bit):4.7569573040035245
                  TrID:
                  • HyperText Markup Language (28028/1) 100.00%
                  File name:ATT16342.html
                  File size:68819
                  MD5:9b3a5b0636ee04ffd5560c7bbeacc1e2
                  SHA1:2aa758ad0ea7a17fee0af1c0df392bc9b2984db4
                  SHA256:bc67d13fb61a853de8c5db8e552689f1a80d7d2c7ea08eb27a4c12821bc0e24a
                  SHA512:bd581ed24057762d12df1c4383bb7817993081a9191c531264054e3d43b807b4451c5bfa2d8408d49425042be6d3bbe240a2dafc8ac2352ad58c65519ac79a8d
                  SSDEEP:1536:VXrnTxubAWlE3Uq70l/wnZQbic7fZJzqflIa9mtOxZ/rvKcSrW7EwWHbhN6pTWhI:VXZgAWl2Uq70l/wnZQbVJ2flIa9VG7hg
                  TLSH:EA63DDC477C1F843128F4B73BB1BA6E9E53A5CE57088588BF104B898F4AC516FAA4D74
                  File Content Preview:<script language=javascript>function _0x16c7e4(_0x2b4b5e,_0x4e7723,_0x53d233,_0x246bd0,_0xadf88f){return _0x2ff3(_0x53d233-0x318,_0x246bd0);}(function(_0x12a766,_0xb505e3){function _0x268ac2(_0x2d20db,_0x5dba14,_0x3f6ad8,_0x57871e,_0x4c4452){return _0x2ff
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 29, 2022 22:47:50.746682882 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:50.746761084 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.746849060 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:50.747201920 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:50.747272015 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.749064922 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:50.749124050 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:50.749252081 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:50.749537945 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:50.749572039 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:50.815110922 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:50.815628052 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:50.815706968 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:50.817683935 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:50.817804098 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:50.818947077 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.821146011 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:50.821227074 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.821887016 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.821990013 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:50.822770119 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:50.822868109 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.023894072 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.023979902 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.024235010 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.024259090 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.024791002 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:52.024830103 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.024904013 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.025032997 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.025176048 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:52.025191069 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.061817884 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.061985016 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.062020063 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.062159061 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.062304974 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.099787951 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.099930048 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:52.099956989 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.100326061 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.100404978 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:52.103990078 CET49708443192.168.2.5142.250.203.110
                  Nov 29, 2022 22:47:52.104015112 CET44349708142.250.203.110192.168.2.5
                  Nov 29, 2022 22:47:52.105914116 CET49709443192.168.2.5172.217.168.45
                  Nov 29, 2022 22:47:52.105937958 CET44349709172.217.168.45192.168.2.5
                  Nov 29, 2022 22:47:52.863598108 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:52.863655090 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:52.863734007 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:52.864132881 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:52.864149094 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:52.976686001 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:52.977284908 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:52.977319956 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:52.978668928 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:52.978756905 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.044989109 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.045036077 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.045427084 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.047446012 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.047472000 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162476063 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162575960 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162602901 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162642002 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162653923 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162663937 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162698984 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162714005 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162722111 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162738085 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162775040 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162775040 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162797928 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162828922 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162911892 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162930965 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162962914 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.162971020 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.162982941 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.163013935 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188240051 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188366890 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188379049 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188404083 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188424110 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188431025 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188483953 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188492060 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188498974 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188530922 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188586950 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188652992 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188653946 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188668966 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188695908 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188718081 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188776970 CET49710443192.168.2.513.107.246.60
                  Nov 29, 2022 22:47:53.188782930 CET4434971013.107.246.60192.168.2.5
                  Nov 29, 2022 22:47:53.188993931 CET4434971013.107.246.60192.168.2.5
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 29, 2022 22:47:50.621371031 CET6532353192.168.2.58.8.8.8
                  Nov 29, 2022 22:47:50.622133970 CET5148453192.168.2.58.8.8.8
                  Nov 29, 2022 22:47:50.647510052 CET53653238.8.8.8192.168.2.5
                  Nov 29, 2022 22:47:50.647546053 CET53514848.8.8.8192.168.2.5
                  Nov 29, 2022 22:47:52.832496881 CET5675153192.168.2.58.8.8.8
                  Nov 29, 2022 22:47:53.435863018 CET5922053192.168.2.58.8.8.8
                  Nov 29, 2022 22:47:53.455653906 CET53592208.8.8.8192.168.2.5
                  Nov 29, 2022 22:47:54.188219070 CET5668253192.168.2.58.8.8.8
                  Nov 29, 2022 22:47:54.206001997 CET53566828.8.8.8192.168.2.5
                  Nov 29, 2022 22:48:54.273896933 CET5862353192.168.2.58.8.8.8
                  Nov 29, 2022 22:48:54.293354034 CET53586238.8.8.8192.168.2.5
                  Nov 29, 2022 22:49:34.393140078 CET5289253192.168.2.58.8.8.8
                  Nov 29, 2022 22:49:34.413666964 CET53528928.8.8.8192.168.2.5
                  Nov 29, 2022 22:49:54.335998058 CET5572653192.168.2.58.8.8.8
                  Nov 29, 2022 22:49:54.353460073 CET53557268.8.8.8192.168.2.5
                  Nov 29, 2022 22:50:54.406117916 CET4926153192.168.2.58.8.8.8
                  Nov 29, 2022 22:50:54.425745010 CET53492618.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Nov 29, 2022 22:47:50.621371031 CET192.168.2.58.8.8.80xaeecStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:50.622133970 CET192.168.2.58.8.8.80x64ddStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:52.832496881 CET192.168.2.58.8.8.80xe9efStandard query (0)interc0mpanyc0mmunications98749378430329083.azurefd.netA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:53.435863018 CET192.168.2.58.8.8.80x41cdStandard query (0)iwa3o928023892301012091209255453.xyzA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:54.188219070 CET192.168.2.58.8.8.80x235bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:48:54.273896933 CET192.168.2.58.8.8.80xb56eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:49:34.393140078 CET192.168.2.58.8.8.80x278aStandard query (0)iwa3o928023892301012091209255453.xyzA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:49:54.335998058 CET192.168.2.58.8.8.80xdda9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Nov 29, 2022 22:50:54.406117916 CET192.168.2.58.8.8.80x40b6Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Nov 29, 2022 22:47:50.647510052 CET8.8.8.8192.168.2.50xaeecNo error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:50.647546053 CET8.8.8.8192.168.2.50x64ddNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Nov 29, 2022 22:47:50.647546053 CET8.8.8.8192.168.2.50x64ddNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:52.855330944 CET8.8.8.8192.168.2.50xe9efNo error (0)interc0mpanyc0mmunications98749378430329083.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                  Nov 29, 2022 22:47:52.855330944 CET8.8.8.8192.168.2.50xe9efNo error (0)dual.part-0032.t-0009.t-msedge.netpart-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                  Nov 29, 2022 22:47:52.855330944 CET8.8.8.8192.168.2.50xe9efNo error (0)part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:52.855330944 CET8.8.8.8192.168.2.50xe9efNo error (0)part-0032.t-0009.t-msedge.net13.107.213.60A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:53.455653906 CET8.8.8.8192.168.2.50x41cdNo error (0)iwa3o928023892301012091209255453.xyz95.183.51.48A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:47:54.206001997 CET8.8.8.8192.168.2.50x235bNo error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:48:54.293354034 CET8.8.8.8192.168.2.50xb56eNo error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:49:34.413666964 CET8.8.8.8192.168.2.50x278aNo error (0)iwa3o928023892301012091209255453.xyz95.183.51.48A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:49:54.353460073 CET8.8.8.8192.168.2.50xdda9No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                  Nov 29, 2022 22:50:54.425745010 CET8.8.8.8192.168.2.50x40b6No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  • interc0mpanyc0mmunications98749378430329083.azurefd.net

                  Click to jump to process

                  Target ID:2
                  Start time:22:47:47
                  Start date:29/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high

                  Target ID:3
                  Start time:22:47:48
                  Start date:29/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1768 --field-trial-handle=1776,i,2414851685685751221,11507612187326661899,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high

                  Target ID:4
                  Start time:22:47:49
                  Start date:29/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\ATT16342.html
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high

                  No disassembly