Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Remittance.htm

Overview

General Information

Sample Name:Remittance.htm
Analysis ID:800698
MD5:39bb32548e89f58ceb6960e84791979e
SHA1:e70af8a69f739dc0501013a1a9ebb5f4cef552e2
SHA256:bf0f39c7f991c76bbd138e4d74dc9cc402aca673c5edd8b6005dc41faf739208
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Performs DNS queries to domains with low reputation
HTML document with suspicious name
IP address seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 5676 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1712,i,1373269792511892383,14833017251772175095,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 2040 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: hhid829389.xyz
Source: Joe Sandbox ViewIP Address: 192.0.46.8 192.0.46.8
Source: Joe Sandbox ViewIP Address: 192.0.46.8 192.0.46.8
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 15:13:38 GMTServer: ApacheVary: Accept-EncodingLast-Modified: Sun, 18 Jul 2021 22:53:53 GMTX-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: same-originExpires: Tue, 07 Feb 2023 16:53:53 GMTX-Content-Type-Options: nosniffAge: 8939Content-Encoding: gzipCache-Control: public, max-age=21603Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;Content-Length: 3177Keep-Alive: timeout=2, max=358Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 cd 1a db 4e e3 48 f6 19 be a2 c6 33 6a 81 44 70 ee 90 25 44 0a 81 86 6e 7a 18 04 cc ce 74 bf a0 b2 5d 89 0b 1c db 5d 55 0e 9d 5e ad b4 bf b1 bf b7 5f b2 e7 54 d9 8e 93 38 21 d9 41 33 9b 87 b8 ae e7 5e e7 52 76 f7 07 2f 72 d5 34 66 c4 57 e3 a0 b7 db cd 1e 8c 7a bd dd 9d ae e2 2a 60 bd 0f fd 9b 7e 65 4c 43 3a 62 1e b9 63 92 89 09 34 ce a3 31 e5 a1 ec da 66 d1 2e 2c 1f 33 45 89 eb 53 21 99 3a b5 12 35 ac 1c 5b c4 ee 65 33 be 52 71 85 7d 4d f8 e4 d4 1a 44 a1 62 a1 aa 20 72 8b b8 a6 77 6a 29 f6 4d d9 48 c4 49 0e 67 09 4c 48 c7 ec d4 9a 70 f6 12 47 42 15 36 bf 70 4f f9 a7 1e 9b 70 97 55 74 e7 80 f0 90 2b 4e 83 8a 74 69 c0 4e 6b 06 0e 40 0a 78 f8 4c 04 0b 4e 2d a9 a6 01 93 3e 63 00 ca 17 6c 78 6a d9 8f ae 94 Data Ascii: NH3jDp%Dnzt]]U^_T8!A3^Rv/r4fWz*`~eLC:bc41f.,3ES!:5[e3Rq}MDb rwj)MHIgLHpGB6pOpUt+NtiNk@xLN->clxj
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 17:23:42 GMTServer: ApacheLast-Modified: Sun, 18 Jul 2021 22:53:53 GMTContent-Encoding: gzipX-Content-Type-Options: nosniffVary: Accept-EncodingX-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: same-originExpires: Tue, 07 Feb 2023 18:01:15 GMTX-Content-Type-Options: nosniffAge: 4946Cache-Control: public, max-age=21603Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;Content-Length: 2466Keep-Alive: timeout=2, max=358Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 cd 5a db 6e e3 b8 19 be 5e 3f 05 57 5d 0c 12 20 b6 ba 73 55 74 6c 03 69 66 b6 13 2c 36 1b 4c 32 58 a0 37 01 2d d1 16 27 94 a8 21 29 3b de a2 c0 bc 46 81 f6 e5 e6 49 fa fd a4 64 2b b6 e4 d8 2d b0 db dc 58 e2 e1 3f 1f 3e 52 19 8c bf 4d 75 e2 d6 a5 60 99 cb d5 74 30 6e 7e 04 4f a7 83 6f c6 4e 3a 25 a6 6f 75 ce 65 c1 6e 78 2e d8 9d 30 4b 99 08 3b 8e c3 dc 00 ab 72 e1 38 4b 32 6e ac 70 93 a8 72 f3 e1 9f 22 16 4f 9b 99 cc b9 72 28 3e 57 72 39 89 ae 74 e1 44 e1 86 c4 33 62 49 78 9b 44 4e 3c b9 98 78 bf d9 d0 d9 23 53 80 fd 24 5a 4a b1 2a b5 71 ad cd 2b 99 ba 6c 92 0a 92 6b e8 5f 2e 98 2c a4 93 5c 0d 6d c2 95 98 Data Ascii: Zn^?W] sUtlif,6L2X7-'!);FId+-X?>RMu`t0n~OoN:%ouenx.0K;r8K2npr"Or(>Wr9tD3bIxDN<x#S$ZJ*q+lk_.,\m
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49687
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49686
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49687 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /?aoul&qrc=glenn.walker@cra-arc.gc.ca HTTP/1.1Host: hhid829389.xyzConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /?https://example.com HTTP/1.1Host: href.liConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: example.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: example.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://example.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /domains/example HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_css/2022/iana_website.css HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_js/jquery.js HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_js/iana.js HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/iana-logo-header.svg HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/SourceCodePro-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Bold.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/bookmark_icon.ico HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Bold.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /domains/reserved HTTP/1.1Host: www.iana.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /_img/bookmark_icon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.iana.org
Source: global trafficHTTP traffic detected: GET /_img/2022/iana-logo-header.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.iana.org
Source: global trafficHTTP traffic detected: GET /domains HTTP/1.1Host: www.iana.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundAge: 144599Cache-Control: max-age=604800Content-Type: text/html; charset=UTF-8Date: Tue, 07 Feb 2023 17:22:40 GMTExpires: Tue, 14 Feb 2023 17:22:40 GMTLast-Modified: Mon, 06 Feb 2023 01:12:41 GMTServer: ECS (bsa/EB21)Vary: Accept-EncodingX-Cache: 404-HITContent-Length: 1256Connection: close
Source: Remittance.htmString found in binary or memory: https://hhid829389.xyz/?aoul&qrc=glenn.walker
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8

System Summary

barindex
Source: Name includes: Remittance.htmInitial sample: remit
Source: classification engineClassification label: mal48.troj.winHTM@35/0@19/10
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1712,i,1373269792511892383,14833017251772175095,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1712,i,1373269792511892383,14833017251772175095,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth5
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration6
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer4
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
hhid829389.xyz2%VirustotalBrowse
SourceDetectionScannerLabelLink
https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.ca0%Avira URL Cloudsafe
https://hhid829389.xyz/?aoul&qrc=glenn.walker0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    hhid829389.xyz
    108.174.197.216
    truetrueunknown
    www.google.com
    142.250.184.100
    truefalse
      high
      clients.l.google.com
      142.250.180.174
      truefalse
        high
        example.com
        93.184.216.34
        truefalse
          high
          ianawww.vip.icann.org
          192.0.46.8
          truefalse
            high
            href.li
            192.0.78.26
            truefalse
              high
              www.vip.icann.org
              192.0.47.7
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  www.iana.org
                  unknown
                  unknownfalse
                    high
                    pti.icann.org
                    unknown
                    unknownfalse
                      high
                      www.icann.org
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        http://www.iana.org/domains/reservedfalse
                          high
                          https://www.iana.org/_img/2022/fonts/SourceCodePro-Regular.wofffalse
                            high
                            https://example.com/false
                              high
                              https://href.li/?https://example.comfalse
                                high
                                https://www.iana.org/_js/iana.jsfalse
                                  high
                                  https://www.iana.org/_img/2022/iana-logo-header.svgfalse
                                    high
                                    https://www.iana.org/_img/2022/fonts/NotoSans-Regular.wofffalse
                                      high
                                      https://example.com/favicon.icofalse
                                        high
                                        https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                          high
                                          http://www.iana.org/domains/reservedfalse
                                            high
                                            https://www.iana.org/_img/bookmark_icon.icofalse
                                              high
                                              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                                high
                                                https://www.iana.org/_css/2022/iana_website.cssfalse
                                                  high
                                                  http://www.iana.org/_img/2022/iana-logo-header.svgfalse
                                                    high
                                                    https://www.iana.org/domains/examplefalse
                                                      high
                                                      http://www.iana.org/_img/bookmark_icon.icofalse
                                                        high
                                                        https://www.iana.org/_js/jquery.jsfalse
                                                          high
                                                          https://example.com/false
                                                            high
                                                            https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.cafalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://www.iana.org/domainsfalse
                                                              high
                                                              http://www.iana.org/domainsfalse
                                                                high
                                                                https://www.iana.org/_img/2022/fonts/NotoSans-Bold.wofffalse
                                                                  high
                                                                  NameSourceMaliciousAntivirus DetectionReputation
                                                                  https://hhid829389.xyz/?aoul&qrc=glenn.walkerRemittance.htmfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  • No. of IPs < 25%
                                                                  • 25% < No. of IPs < 50%
                                                                  • 50% < No. of IPs < 75%
                                                                  • 75% < No. of IPs
                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                  192.0.46.8
                                                                  ianawww.vip.icann.orgUnited States
                                                                  16876ICANN-DCUSfalse
                                                                  93.184.216.34
                                                                  example.comEuropean Union
                                                                  15133EDGECASTUSfalse
                                                                  108.174.197.216
                                                                  hhid829389.xyzUnited States
                                                                  54290HOSTWINDSUStrue
                                                                  216.58.209.45
                                                                  accounts.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  192.0.78.26
                                                                  href.liUnited States
                                                                  2635AUTOMATTICUSfalse
                                                                  239.255.255.250
                                                                  unknownReserved
                                                                  unknownunknownfalse
                                                                  142.250.184.100
                                                                  www.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  142.250.180.174
                                                                  clients.l.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  IP
                                                                  192.168.2.1
                                                                  127.0.0.1
                                                                  Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                  Analysis ID:800698
                                                                  Start date and time:2023-02-07 18:21:34 +01:00
                                                                  Joe Sandbox Product:CloudBasic
                                                                  Overall analysis duration:0h 7m 35s
                                                                  Hypervisor based Inspection enabled:false
                                                                  Report type:light
                                                                  Cookbook file name:defaultwindowshtmlcookbook.jbs
                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                  Number of analysed new started processes analysed:8
                                                                  Number of new started drivers analysed:0
                                                                  Number of existing processes analysed:0
                                                                  Number of existing drivers analysed:0
                                                                  Number of injected processes analysed:0
                                                                  Technologies:
                                                                  • HCA enabled
                                                                  • EGA enabled
                                                                  • HDC enabled
                                                                  • AMSI enabled
                                                                  Analysis Mode:default
                                                                  Analysis stop reason:Timeout
                                                                  Sample file name:Remittance.htm
                                                                  Detection:MAL
                                                                  Classification:mal48.troj.winHTM@35/0@19/10
                                                                  EGA Information:Failed
                                                                  HDC Information:Failed
                                                                  HCA Information:
                                                                  • Successful, ratio: 100%
                                                                  • Number of executed functions: 0
                                                                  • Number of non-executed functions: 0
                                                                  Cookbook Comments:
                                                                  • Found application associated with file extension: .htm
                                                                  • Browse: https://www.iana.org/domains/example
                                                                  • Browse: http://www.iana.org/
                                                                  • Browse: http://www.iana.org/domains
                                                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, WMIADAP.exe, conhost.exe, backgroundTaskHost.exe
                                                                  • TCP Packets have been reduced to 100
                                                                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163
                                                                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                  No simulations
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:HTML document, ASCII text, with CRLF line terminators
                                                                  Entropy (8bit):5.255051358476731
                                                                  TrID:
                                                                  • HyperText Markup Language (15015/1) 100.00%
                                                                  File name:Remittance.htm
                                                                  File size:225
                                                                  MD5:39bb32548e89f58ceb6960e84791979e
                                                                  SHA1:e70af8a69f739dc0501013a1a9ebb5f4cef552e2
                                                                  SHA256:bf0f39c7f991c76bbd138e4d74dc9cc402aca673c5edd8b6005dc41faf739208
                                                                  SHA512:18764d29c900701e18f6d7b0cf3c9fd59c0cd1a0baab510062a28e91755b5503f1bd979e720d00524ffb0d1c213b30a36a89b22e152cdf9005f925fac4c621b4
                                                                  SSDEEP:6:h4QWqqMzSKcAIK7UK+oSPNKDVjgnEzcTi/MWXfGb:hPlzSb1K0NwVsEzcu/MWPGb
                                                                  TLSH:7AD0A7EB3C50DD056971ACF45C75E22C94B7B2C45E96E217D4C4792B15203B89D471CE
                                                                  File Content Preview:<!DOCTYPE html>..<html>..<body>..<script>..// Javascript URL redirection - generated by www.rapidtables.com..window.location.replace("https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.ca");..</script>..</body>..</html>
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Feb 7, 2023 18:22:35.514782906 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:35.514828920 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.514906883 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:35.515350103 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:35.515362024 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.516421080 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:35.516468048 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:35.516552925 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:35.516911983 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:35.516928911 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:35.597213984 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:35.600869894 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.603200912 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:35.603229046 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:35.603496075 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:35.603521109 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.604312897 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.604425907 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:35.605714083 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:35.605828047 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:35.605948925 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:35.606060982 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.213845968 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.213895082 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.214107037 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.214555979 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:36.214592934 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.214812994 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.214847088 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.214968920 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.215183973 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:36.215209007 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.261046886 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.261260033 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.261344910 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.261404037 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.261482000 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.281936884 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:36.282457113 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.282661915 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.282980919 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:36.308343887 CET49687443192.168.2.4216.58.209.45
                                                                  Feb 7, 2023 18:22:36.308389902 CET44349687216.58.209.45192.168.2.4
                                                                  Feb 7, 2023 18:22:36.309290886 CET49686443192.168.2.4142.250.180.174
                                                                  Feb 7, 2023 18:22:36.309329987 CET44349686142.250.180.174192.168.2.4
                                                                  Feb 7, 2023 18:22:36.487548113 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.487634897 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.487763882 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.488193989 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.488240004 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.788575888 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.788919926 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.788960934 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.790175915 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.790792942 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.818490982 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.818530083 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.818741083 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.818754911 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.818949938 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:36.984761000 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:36.984795094 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:37.085900068 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:38.763835907 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.763922930 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.764024973 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.810707092 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.810787916 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.880678892 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.917392015 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.917450905 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.921080112 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.921307087 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.924998999 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.925035000 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.925301075 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:38.997092009 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:38.997138023 CET44349690142.250.184.100192.168.2.4
                                                                  Feb 7, 2023 18:22:39.097035885 CET49690443192.168.2.4142.250.184.100
                                                                  Feb 7, 2023 18:22:39.372406006 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:39.372523069 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:39.372613907 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:39.373567104 CET49688443192.168.2.4108.174.197.216
                                                                  Feb 7, 2023 18:22:39.373591900 CET44349688108.174.197.216192.168.2.4
                                                                  Feb 7, 2023 18:22:39.432368040 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.432426929 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.432523012 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.432948112 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.432964087 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.485980988 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.488847971 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.488930941 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.489515066 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.489671946 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.490298033 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.490406036 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.492759943 CET49694443192.168.2.4192.0.78.26
                                                                  Feb 7, 2023 18:22:39.492789030 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.492934942 CET44349694192.0.78.26192.168.2.4
                                                                  Feb 7, 2023 18:22:39.493001938 CET49694443192.168.2.4192.0.78.26
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Feb 7, 2023 18:22:35.359690905 CET5160053192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:35.359971046 CET5741753192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:35.377711058 CET53574178.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:35.377994061 CET53516008.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:36.376741886 CET6110553192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:36.408771038 CET53611058.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:38.675455093 CET5968353192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:38.696670055 CET53596838.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:38.731987953 CET6416753192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:38.751524925 CET53641678.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:39.377855062 CET5856553192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:39.398554087 CET53585658.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:39.848314047 CET5680753192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:39.866036892 CET53568078.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:52.922415972 CET5557053192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:52.941468954 CET53555708.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:53.447417021 CET6490653192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:53.467806101 CET53649068.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:57.577347994 CET6470053192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:57.581682920 CET5602253192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:22:57.594928980 CET53647008.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:57.773257971 CET53560228.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:22:59.932573080 CET4975053192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:23:00.099409103 CET53497508.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:23:38.747319937 CET5337053192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:23:38.765232086 CET53533708.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:23:59.240793943 CET5176653192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:23:59.241426945 CET6152253192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:23:59.258929968 CET53517668.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:23:59.588109016 CET53615228.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:24:03.115114927 CET5362253192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:24:03.133151054 CET53536228.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:24:39.241616011 CET5006553192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:24:39.262686968 CET53500658.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:24:39.385073900 CET5357353192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:24:39.403084040 CET53535738.8.8.8192.168.2.4
                                                                  Feb 7, 2023 18:25:28.937002897 CET6136653192.168.2.48.8.8.8
                                                                  Feb 7, 2023 18:25:28.954996109 CET53613668.8.8.8192.168.2.4
                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                  Feb 7, 2023 18:22:35.359690905 CET192.168.2.48.8.8.80xa045Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:35.359971046 CET192.168.2.48.8.8.80x4c48Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:36.376741886 CET192.168.2.48.8.8.80xf521Standard query (0)hhid829389.xyzA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:38.675455093 CET192.168.2.48.8.8.80xdb35Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:38.731987953 CET192.168.2.48.8.8.80x109eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:39.377855062 CET192.168.2.48.8.8.80xd64bStandard query (0)href.liA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:39.848314047 CET192.168.2.48.8.8.80x6456Standard query (0)example.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:52.922415972 CET192.168.2.48.8.8.80x6141Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:53.447417021 CET192.168.2.48.8.8.80x43bbStandard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.577347994 CET192.168.2.48.8.8.80xafb5Standard query (0)www.icann.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.581682920 CET192.168.2.48.8.8.80xe24dStandard query (0)pti.icann.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:59.932573080 CET192.168.2.48.8.8.80xb596Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:38.747319937 CET192.168.2.48.8.8.80x7297Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.240793943 CET192.168.2.48.8.8.80x4850Standard query (0)www.icann.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.241426945 CET192.168.2.48.8.8.80x1decStandard query (0)pti.icann.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:03.115114927 CET192.168.2.48.8.8.80x89fdStandard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:39.241616011 CET192.168.2.48.8.8.80x7109Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:39.385073900 CET192.168.2.48.8.8.80x37ceStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:25:28.937002897 CET192.168.2.48.8.8.80x779bStandard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                  Feb 7, 2023 18:22:35.377711058 CET8.8.8.8192.168.2.40x4c48No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:35.377711058 CET8.8.8.8192.168.2.40x4c48No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:35.377994061 CET8.8.8.8192.168.2.40xa045No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:36.408771038 CET8.8.8.8192.168.2.40xf521No error (0)hhid829389.xyz108.174.197.216A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:38.696670055 CET8.8.8.8192.168.2.40xdb35No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:38.751524925 CET8.8.8.8192.168.2.40x109eNo error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:39.398554087 CET8.8.8.8192.168.2.40xd64bNo error (0)href.li192.0.78.26A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:39.398554087 CET8.8.8.8192.168.2.40xd64bNo error (0)href.li192.0.78.27A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:39.866036892 CET8.8.8.8192.168.2.40x6456No error (0)example.com93.184.216.34A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:52.941468954 CET8.8.8.8192.168.2.40x6141No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:52.941468954 CET8.8.8.8192.168.2.40x6141No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:53.467806101 CET8.8.8.8192.168.2.40x43bbNo error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:53.467806101 CET8.8.8.8192.168.2.40x43bbNo error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.594928980 CET8.8.8.8192.168.2.40xafb5No error (0)www.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.594928980 CET8.8.8.8192.168.2.40xafb5No error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.773257971 CET8.8.8.8192.168.2.40xe24dNo error (0)pti.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:22:57.773257971 CET8.8.8.8192.168.2.40xe24dNo error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:00.099409103 CET8.8.8.8192.168.2.40xb596No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:00.099409103 CET8.8.8.8192.168.2.40xb596No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:38.765232086 CET8.8.8.8192.168.2.40x7297No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.258929968 CET8.8.8.8192.168.2.40x4850No error (0)www.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.258929968 CET8.8.8.8192.168.2.40x4850No error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.588109016 CET8.8.8.8192.168.2.40x1decNo error (0)pti.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:23:59.588109016 CET8.8.8.8192.168.2.40x1decNo error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:03.133151054 CET8.8.8.8192.168.2.40x89fdNo error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:03.133151054 CET8.8.8.8192.168.2.40x89fdNo error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:39.262686968 CET8.8.8.8192.168.2.40x7109No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:24:39.403084040 CET8.8.8.8192.168.2.40x37ceNo error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                  Feb 7, 2023 18:25:28.954996109 CET8.8.8.8192.168.2.40x779bNo error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                  Feb 7, 2023 18:25:28.954996109 CET8.8.8.8192.168.2.40x779bNo error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                  • clients2.google.com
                                                                  • accounts.google.com
                                                                  • hhid829389.xyz
                                                                  • href.li
                                                                  • example.com
                                                                  • https:
                                                                    • www.iana.org

                                                                  Click to jump to process

                                                                  Target ID:0
                                                                  Start time:18:22:31
                                                                  Start date:07/02/2023
                                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                                                  Imagebase:0x7ff683680000
                                                                  File size:2851656 bytes
                                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  Target ID:1
                                                                  Start time:18:22:33
                                                                  Start date:07/02/2023
                                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1712,i,1373269792511892383,14833017251772175095,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                  Imagebase:0x7ff683680000
                                                                  File size:2851656 bytes
                                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  Target ID:2
                                                                  Start time:18:22:35
                                                                  Start date:07/02/2023
                                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                  Wow64 process (32bit):false
                                                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm
                                                                  Imagebase:0x7ff683680000
                                                                  File size:2851656 bytes
                                                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                  Has elevated privileges:true
                                                                  Has administrator privileges:true
                                                                  Programmed in:C, C++ or other language
                                                                  Reputation:high

                                                                  No disassembly