Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://lcattertonpe.com

Overview

General Information

Sample URL:http://lcattertonpe.com
Analysis ID:800682
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2888 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,823529605349688411,4145770639965686966,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1724 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lcattertonpe.com MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap/3.3.7/css/bootstrap.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: http://lcattertonpe.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap/3.3.7/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://lcattertonpe.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/5.15.3/css/all.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: http://lcattertonpe.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/5.15.3/webfonts/fa-solid-900.woff2 HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://lcattertonpe.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/5.15.3/webfonts/fa-brands-400.woff2 HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://lcattertonpe.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEIlaHLAQiBvMwBCPG8zAEIs8HMAQjFwcwBCNbBzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://lcattertonpe.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849 HTTP/1.1Host: www.google.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEIlaHLAQiBvMwBCPG8zAEIs8HMAQjFwcwBCNbBzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://lcattertonpe.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: lcattertonpe.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lcattertonpe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://lcattertonpe.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.2.315444834.1675822043; _gid=GA1.2.1283538996.1675822043; _gat_gtag_UA_26575989_44=1
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 07 Feb 2023 17:07:23 GMTContent-Type: text/htmlContent-Length: 548Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@25/0@13/11
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,823529605349688411,4145770639965686966,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lcattertonpe.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,823529605349688411,4145770639965686966,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://lcattertonpe.com0%VirustotalBrowse
http://lcattertonpe.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://lcattertonpe.com/favicon.ico0%Avira URL Cloudsafe
https://www.google.co.uk/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=4814558490%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    lcattertonpe.com
    2.57.90.16
    truefalse
      unknown
      cdnjs.cloudflare.com
      104.17.24.14
      truefalse
        high
        www.google.co.uk
        142.251.209.3
        truefalse
          unknown
          maxcdn.bootstrapcdn.com
          104.18.10.207
          truefalse
            high
            www.google.com
            142.250.184.100
            truefalse
              high
              clients.l.google.com
              142.250.180.174
              truefalse
                high
                stats.g.doubleclick.net
                142.251.31.155
                truefalse
                  high
                  cpanel.hostinger.com
                  unknown
                  unknownfalse
                    high
                    clients2.google.com
                    unknown
                    unknownfalse
                      high
                      cdn.hostinger.com
                      unknown
                      unknownfalse
                        high
                        support.hostinger.com
                        unknown
                        unknownfalse
                          high
                          www.hostinger.com
                          unknown
                          unknownfalse
                            high
                            NameMaliciousAntivirus DetectionReputation
                            https://stats.g.doubleclick.net/j/collect?t=dc&aip=1&_r=3&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&gjid=1286070036&_gid=1283538996.1675822043&_u=YEBAAUAAAAAAACAAI~&z=612317697false
                              high
                              https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-brands-400.woff2false
                                high
                                http://lcattertonpe.com/false
                                  unknown
                                  https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.cssfalse
                                    high
                                    https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-solid-900.woff2false
                                      high
                                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                        high
                                        https://www.google.com/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849false
                                          high
                                          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                            high
                                            https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.cssfalse
                                              high
                                              https://www.google.co.uk/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849false
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://lcattertonpe.com/false
                                                unknown
                                                https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.jsfalse
                                                  high
                                                  http://lcattertonpe.com/favicon.icofalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  • No. of IPs < 25%
                                                  • 25% < No. of IPs < 50%
                                                  • 50% < No. of IPs < 75%
                                                  • 75% < No. of IPs
                                                  IPDomainCountryFlagASNASN NameMalicious
                                                  104.17.24.14
                                                  cdnjs.cloudflare.comUnited States
                                                  13335CLOUDFLARENETUSfalse
                                                  104.18.10.207
                                                  maxcdn.bootstrapcdn.comUnited States
                                                  13335CLOUDFLARENETUSfalse
                                                  142.251.31.155
                                                  stats.g.doubleclick.netUnited States
                                                  15169GOOGLEUSfalse
                                                  142.251.209.3
                                                  www.google.co.ukUnited States
                                                  15169GOOGLEUSfalse
                                                  216.58.209.45
                                                  accounts.google.comUnited States
                                                  15169GOOGLEUSfalse
                                                  239.255.255.250
                                                  unknownReserved
                                                  unknownunknownfalse
                                                  142.250.184.100
                                                  www.google.comUnited States
                                                  15169GOOGLEUSfalse
                                                  142.250.180.174
                                                  clients.l.google.comUnited States
                                                  15169GOOGLEUSfalse
                                                  2.57.90.16
                                                  lcattertonpe.comLithuania
                                                  47583AS-HOSTINGERLTfalse
                                                  IP
                                                  192.168.2.1
                                                  127.0.0.1
                                                  Joe Sandbox Version:36.0.0 Rainbow Opal
                                                  Analysis ID:800682
                                                  Start date and time:2023-02-07 18:06:08 +01:00
                                                  Joe Sandbox Product:CloudBasic
                                                  Overall analysis duration:0h 5m 3s
                                                  Hypervisor based Inspection enabled:false
                                                  Report type:light
                                                  Cookbook file name:browseurl.jbs
                                                  Sample URL:http://lcattertonpe.com
                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                  Number of analysed new started processes analysed:13
                                                  Number of new started drivers analysed:0
                                                  Number of existing processes analysed:0
                                                  Number of existing drivers analysed:0
                                                  Number of injected processes analysed:0
                                                  Technologies:
                                                  • HCA enabled
                                                  • EGA enabled
                                                  • HDC enabled
                                                  • AMSI enabled
                                                  Analysis Mode:default
                                                  Analysis stop reason:Timeout
                                                  Detection:CLEAN
                                                  Classification:clean0.win@25/0@13/11
                                                  EGA Information:Failed
                                                  HDC Information:Failed
                                                  HCA Information:
                                                  • Successful, ratio: 100%
                                                  • Number of executed functions: 0
                                                  • Number of non-executed functions: 0
                                                  Cookbook Comments:
                                                  • Browse: https://www.hostinger.com/
                                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                                                  • TCP Packets have been reduced to 100
                                                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 142.250.180.170, 142.250.180.138, 142.250.184.67, 104.18.114.100, 104.18.113.100, 142.250.180.168, 34.104.35.123, 142.250.184.110, 142.250.180.163
                                                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fonts.googleapis.com, fs.microsoft.com, ajax.googleapis.com, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, edgedl.me.gvt1.com, login.live.com, www.googletagmanager.com, support.hostinger.com.cdn.cloudflare.net, update.googleapis.com, cdn.hostinger.com.cdn.cloudflare.net, cpanel.hostinger.com.cdn.cloudflare.net, www.hostinger.com.cdn.cloudflare.net, www.google-analytics.com
                                                  • Not all processes where analyzed, report is missing behavior information
                                                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                  No simulations
                                                  No context
                                                  No context
                                                  No context
                                                  No context
                                                  No context
                                                  No created / dropped files found
                                                  No static file info
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Feb 7, 2023 18:07:20.517294884 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.517353058 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.517474890 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.518132925 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:20.518177032 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:20.518269062 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:20.518743038 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:20.518783092 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:20.518851995 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:20.519408941 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.522578001 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.522620916 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.523626089 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:20.523653030 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:20.524456978 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:20.524486065 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:20.525861025 CET4971980192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.556240082 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.556421041 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.557173014 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.562509060 CET80497192.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.562674046 CET4971980192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.593693972 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593740940 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593831062 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593858957 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593885899 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593915939 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593918085 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.593941927 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.593956947 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.593970060 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.594002962 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.594007015 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.594033957 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.594059944 CET80497172.57.90.16192.168.2.7
                                                  Feb 7, 2023 18:07:20.594063997 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.594120026 CET4971780192.168.2.72.57.90.16
                                                  Feb 7, 2023 18:07:20.648267984 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:20.648864985 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:20.648900032 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:20.651115894 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:20.651268959 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:20.662743092 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.675905943 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:20.695622921 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:20.695655107 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:20.696300030 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.696336985 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.697024107 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.697155952 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.697957039 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:20.697988987 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:20.698043108 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:20.698113918 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:20.835581064 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.835623980 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.835696936 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.836308956 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.836343050 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.836409092 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.837413073 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.837440968 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.839257002 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.839283943 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.887265921 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.908435106 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.908485889 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.911061049 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.911190987 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:20.911334991 CET49724443192.168.2.7104.17.24.14
                                                  Feb 7, 2023 18:07:20.911380053 CET44349724104.17.24.14192.168.2.7
                                                  Feb 7, 2023 18:07:20.911472082 CET49724443192.168.2.7104.17.24.14
                                                  Feb 7, 2023 18:07:20.914211988 CET49724443192.168.2.7104.17.24.14
                                                  Feb 7, 2023 18:07:20.914236069 CET44349724104.17.24.14192.168.2.7
                                                  Feb 7, 2023 18:07:20.946104050 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:20.967922926 CET44349724104.17.24.14192.168.2.7
                                                  Feb 7, 2023 18:07:21.002819061 CET49724443192.168.2.7104.17.24.14
                                                  Feb 7, 2023 18:07:21.002856970 CET44349724104.17.24.14192.168.2.7
                                                  Feb 7, 2023 18:07:21.003135920 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:21.003154039 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:21.004911900 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:21.004971027 CET44349722104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:21.005013943 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:21.005345106 CET44349724104.17.24.14192.168.2.7
                                                  Feb 7, 2023 18:07:21.005415916 CET49724443192.168.2.7104.17.24.14
                                                  Feb 7, 2023 18:07:21.142049074 CET49722443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:21.145241022 CET49716443192.168.2.7142.250.184.100
                                                  Feb 7, 2023 18:07:21.145260096 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:21.145422935 CET44349716142.250.184.100192.168.2.7
                                                  Feb 7, 2023 18:07:21.145725965 CET49714443192.168.2.7142.250.180.174
                                                  Feb 7, 2023 18:07:21.145756960 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:21.145991087 CET44349714142.250.180.174192.168.2.7
                                                  Feb 7, 2023 18:07:21.146218061 CET49721443192.168.2.7104.18.10.207
                                                  Feb 7, 2023 18:07:21.146254063 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:21.146464109 CET44349721104.18.10.207192.168.2.7
                                                  Feb 7, 2023 18:07:21.146814108 CET49715443192.168.2.7216.58.209.45
                                                  Feb 7, 2023 18:07:21.146840096 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:21.147001982 CET44349715216.58.209.45192.168.2.7
                                                  Feb 7, 2023 18:07:21.147140980 CET49722443192.168.2.7104.18.10.207
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Feb 7, 2023 18:07:20.453223944 CET5100753192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.457696915 CET5051353192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.465583086 CET6076553192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.469629049 CET5828353192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.481324911 CET53510078.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:20.487155914 CET53582838.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:20.493951082 CET53607658.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:20.505382061 CET53505138.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:20.723437071 CET5002453192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.744332075 CET53500248.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:20.820439100 CET6139253192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:20.844157934 CET53613928.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:22.005989075 CET5152653192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:22.196577072 CET5878453192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:22.209849119 CET5797053192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:22.211728096 CET6460853192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:23.276364088 CET5275053192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:23.302983046 CET53527508.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:23.474646091 CET6407853192.168.2.78.8.8.8
                                                  Feb 7, 2023 18:07:23.501009941 CET53640788.8.8.8192.168.2.7
                                                  Feb 7, 2023 18:07:27.207098961 CET5851453192.168.2.78.8.8.8
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Feb 7, 2023 18:07:20.453223944 CET192.168.2.78.8.8.80xe4a6Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.457696915 CET192.168.2.78.8.8.80xa587Standard query (0)lcattertonpe.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.465583086 CET192.168.2.78.8.8.80x8a08Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.469629049 CET192.168.2.78.8.8.80x6b1bStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.723437071 CET192.168.2.78.8.8.80x8a04Standard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.820439100 CET192.168.2.78.8.8.80x782fStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.005989075 CET192.168.2.78.8.8.80x460aStandard query (0)cdn.hostinger.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.196577072 CET192.168.2.78.8.8.80x5bd9Standard query (0)www.hostinger.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.209849119 CET192.168.2.78.8.8.80xd893Standard query (0)support.hostinger.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.211728096 CET192.168.2.78.8.8.80x14cStandard query (0)cpanel.hostinger.comA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.276364088 CET192.168.2.78.8.8.80x8852Standard query (0)stats.g.doubleclick.netA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.474646091 CET192.168.2.78.8.8.80xba73Standard query (0)www.google.co.ukA (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:27.207098961 CET192.168.2.78.8.8.80x3e3aStandard query (0)cdn.hostinger.comA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Feb 7, 2023 18:07:20.481324911 CET8.8.8.8192.168.2.70xe4a6No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.487155914 CET8.8.8.8192.168.2.70x6b1bNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.487155914 CET8.8.8.8192.168.2.70x6b1bNo error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.493951082 CET8.8.8.8192.168.2.70x8a08No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.505382061 CET8.8.8.8192.168.2.70xa587No error (0)lcattertonpe.com2.57.90.16A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.744332075 CET8.8.8.8192.168.2.70x8a04No error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.744332075 CET8.8.8.8192.168.2.70x8a04No error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.844157934 CET8.8.8.8192.168.2.70x782fNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:20.844157934 CET8.8.8.8192.168.2.70x782fNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.028316975 CET8.8.8.8192.168.2.70x460aNo error (0)cdn.hostinger.comcdn.hostinger.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.220026016 CET8.8.8.8192.168.2.70x5bd9No error (0)www.hostinger.comwww.hostinger.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.251935959 CET8.8.8.8192.168.2.70x14cNo error (0)cpanel.hostinger.comcpanel.hostinger.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  Feb 7, 2023 18:07:22.252708912 CET8.8.8.8192.168.2.70xd893No error (0)support.hostinger.comsupport.hostinger.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.302983046 CET8.8.8.8192.168.2.70x8852No error (0)stats.g.doubleclick.net142.251.31.155A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.302983046 CET8.8.8.8192.168.2.70x8852No error (0)stats.g.doubleclick.net142.251.31.154A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.302983046 CET8.8.8.8192.168.2.70x8852No error (0)stats.g.doubleclick.net142.251.31.156A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.302983046 CET8.8.8.8192.168.2.70x8852No error (0)stats.g.doubleclick.net142.251.31.157A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:23.501009941 CET8.8.8.8192.168.2.70xba73No error (0)www.google.co.uk142.251.209.3A (IP address)IN (0x0001)false
                                                  Feb 7, 2023 18:07:27.227603912 CET8.8.8.8192.168.2.70x3e3aNo error (0)cdn.hostinger.comcdn.hostinger.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  • clients2.google.com
                                                  • lcattertonpe.com
                                                    • maxcdn.bootstrapcdn.com
                                                    • cdnjs.cloudflare.com
                                                    • stats.g.doubleclick.net
                                                    • www.google.com
                                                    • www.google.co.uk
                                                  • accounts.google.com
                                                  • https:

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:18:07:13
                                                  Start date:07/02/2023
                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                                  Imagebase:0x7ff7c2920000
                                                  File size:2851656 bytes
                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low

                                                  Target ID:1
                                                  Start time:18:07:14
                                                  Start date:07/02/2023
                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,823529605349688411,4145770639965686966,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                  Imagebase:0x7ff7c2920000
                                                  File size:2851656 bytes
                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low

                                                  Target ID:2
                                                  Start time:18:07:15
                                                  Start date:07/02/2023
                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lcattertonpe.com
                                                  Imagebase:0x7ff7c2920000
                                                  File size:2851656 bytes
                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low

                                                  No disassembly