Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
login.html

Overview

General Information

Sample Name:login.html
Analysis ID:876181
MD5:daccb43d7df16a5b00d0db1340b979ab
SHA1:ef1e463b2cff4c9b8e5487422ae63ec15083bcbc
SHA256:f0a3bb756492268062c421579e4115d2764a713e5b7cd2fc95a89c94814e6fc2
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Suspicious Javascript code found in HTML file
HTML document with suspicious name
HTML body contains password input but no form action
HTML body with high number of large embedded background images detected
IP address seen in connection with other malware

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6556 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 1584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1772,i,15227930420298686886,3054010558266752575,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: login.htmlHTTP Parser: new blob(
Source: login.htmlHTTP Parser: url.createobjecturl
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: <input type="password" .../> found but no <form action="...
Source: login.htmlHTTP Parser: Total embedded background img size: 475993
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: Total embedded background img size: 861218
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: <input type="password" .../> found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: chrome.exeMemory has grown: Private usage: 1MB later: 50MB
Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: login.htmlString found in binary or memory: http://underscorejs.org/LICENSE
Source: login.htmlString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: login.htmlString found in binary or memory: http://www.broofa.com
Source: login.htmlString found in binary or memory: https://angular.io/
Source: login.htmlString found in binary or memory: https://angular.io/api/core/Component#animations).
Source: login.htmlString found in binary or memory: https://angular.io/errors/$
Source: login.htmlString found in binary or memory: https://angular.io/license
Source: login.htmlString found in binary or memory: https://g.co/ng/security#xss)
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/bytebuffer.js
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/long.js
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/protobuf.js
Source: login.htmlString found in binary or memory: https://jquery.com/
Source: login.htmlString found in binary or memory: https://jquery.org/license
Source: login.htmlString found in binary or memory: https://js.foundation/
Source: login.htmlString found in binary or memory: https://lodash.com/
Source: login.htmlString found in binary or memory: https://lodash.com/license
Source: login.htmlString found in binary or memory: https://openjsf.org/
Source: login.htmlString found in binary or memory: https://sizzlejs.com/
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E

System Summary

barindex
Source: Name includes: login.htmlInitial sample: login
Source: classification engineClassification label: mal48.phis.winHTML@24/0@6/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1772,i,15227930420298686886,3054010558266752575,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1772,i,15227930420298686886,3054010558266752575,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: login.htmlStatic file information: File size 5877035 > 1048576
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.broofa.com0%URL Reputationsafe
http://www.broofa.com0%URL Reputationsafe
https://openjsf.org/0%URL Reputationsafe
https://js.foundation/0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.186.45
truefalse
    high
    www.google.com
    142.250.184.196
    truefalse
      high
      clients.l.google.com
      216.58.212.174
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          file:///C:/Users/user/Desktop/login.htmltrue
            low
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                NameSourceMaliciousAntivirus DetectionReputation
                http://underscorejs.org/LICENSElogin.htmlfalse
                  high
                  http://www.apache.org/licenses/LICENSE-2.0login.htmlfalse
                    high
                    https://jquery.org/licenselogin.htmlfalse
                      high
                      https://g.co/ng/security#xss)login.htmlfalse
                        high
                        http://www.broofa.comlogin.htmlfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://github.com/dcodeIO/long.jslogin.htmlfalse
                          high
                          https://github.com/dcodeIO/protobuf.jslogin.htmlfalse
                            high
                            https://jquery.com/login.htmlfalse
                              high
                              https://angular.io/api/core/Component#animations).login.htmlfalse
                                high
                                https://angular.io/errors/$login.htmlfalse
                                  high
                                  https://angular.io/login.htmlfalse
                                    high
                                    https://lodash.com/login.htmlfalse
                                      high
                                      https://github.com/dcodeIO/bytebuffer.jslogin.htmlfalse
                                        high
                                        https://lodash.com/licenselogin.htmlfalse
                                          high
                                          https://angular.io/licenselogin.htmlfalse
                                            high
                                            https://openjsf.org/login.htmlfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://sizzlejs.com/login.htmlfalse
                                              high
                                              https://js.foundation/login.htmlfalse
                                              • URL Reputation: safe
                                              unknown
                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs
                                              IPDomainCountryFlagASNASN NameMalicious
                                              142.250.186.45
                                              accounts.google.comUnited States
                                              15169GOOGLEUSfalse
                                              239.255.255.250
                                              unknownReserved
                                              unknownunknownfalse
                                              216.58.212.164
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              216.58.212.174
                                              clients.l.google.comUnited States
                                              15169GOOGLEUSfalse
                                              172.217.16.196
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              IP
                                              192.168.2.2
                                              192.168.2.1
                                              192.168.8.1
                                              Joe Sandbox Version:37.1.0 Beryl
                                              Analysis ID:876181
                                              Start date and time:2023-05-26 13:17:50 +02:00
                                              Joe Sandbox Product:CloudBasic
                                              Overall analysis duration:0h 4m 19s
                                              Hypervisor based Inspection enabled:false
                                              Report type:full
                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                              Number of analysed new started processes analysed:5
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:0
                                              Technologies:
                                              • HCA enabled
                                              • EGA enabled
                                              • HDC enabled
                                              • AMSI enabled
                                              Analysis Mode:default
                                              Analysis stop reason:Timeout
                                              Sample file name:login.html
                                              Detection:MAL
                                              Classification:mal48.phis.winHTML@24/0@6/8
                                              EGA Information:Failed
                                              HDC Information:Failed
                                              HCA Information:
                                              • Successful, ratio: 100%
                                              • Number of executed functions: 0
                                              • Number of non-executed functions: 0
                                              Cookbook Comments:
                                              • Found application associated with file extension: .html
                                              • Exclude process from analysis (whitelisted): HxTsr.exe, RuntimeBroker.exe, svchost.exe
                                              • Excluded IPs from analysis (whitelisted): 142.250.181.227, 34.104.35.123, 142.250.185.227
                                              • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, login.live.com, update.googleapis.com, clientservices.googleapis.com, cdn.onenote.net
                                              • Not all processes where analyzed, report is missing behavior information
                                              No simulations
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              239.255.255.250login.htmlGet hashmaliciousUnknownBrowse
                                                https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fstn7ny.codesandbox.io?pop=someone.else%40somewhere.comGet hashmaliciousHTMLPhisherBrowse
                                                  iata-25May2023.shtmlGet hashmaliciousUnknownBrowse
                                                    https://s3.amazonaws.com/v5c323s5fg7hnj-794372450934/tv.htmlGet hashmaliciousUnknownBrowse
                                                      25 May 2023-9706 PM-GTT4FIWVGZ.htmGet hashmaliciousHTMLPhisherBrowse
                                                        https://269.bowwordon.live/fxddhqsm/?u=3w8p605&o=pn1kfzq&f=1&sid=t2~hckuzwxtbpsvmcpf30ztc331&fp=FvEsrkTArOgrxzhB2zExAA2IZuNTD8%2Fd9njv3jvDDOYnVROoSzmzg9nW12cfMdaHPT88q85r2inPkFCSbWgnzkfJFZZA3Mrzk%2F75MnETRxlcbvcR%2BeCurFnWMWd%2Fga7euAPm2FuOzEEhPFPKB9BvYYMpUxFP0z7K9pb7kfgbNf7SPRnAgQYfnloabfpuR%2BvXfyPOArMa%2B%2FuoZCunaXhl0et9vEushY7p%2FHvZJdO3bDfSLkShHDI5ukbNxghFhqsVSdcuoNPFbXVxUMFSYBPgTzlZOfrmXROiGBlvljFG6fsmagUS%2FcuqeVrqE60PwBTm3%2Fi07AuZFW5fp%2FVgaJ6PbiRsnFEiC40thM192GKHQmbP7RKplWwBB8%2B8V9R2MWg%2FLK44BnmLVLfMpK%2FaPUB4ZbPCt%2B1mkosN9tSoNyEbMODuLao0Z7nZzXzxHsVCzILD9XrGiz4%2BbS2yy4q2xExA%2FoVYHMdITtz12kRrUwM13QZcFjcbuNxO6UPZKT9ClRRrlg0lIkw74ioZ2xrB9aRabwONkY0LAtlodraoxsFw%2Frjld227l0ZlFzSfF7ItEflen4OWRtOFW9Wrsiz2kpJPf5oRAHrdZUkN3qG%2F15O3V44Vu5%2BpENw113oXAb%2B5jOBgRRW6I1X0bf8cLxhowerhiMxt50rO8mBdxAQdPHCn0gH0ebxDhuaS%2FLYgUGT1lau3HqE%2F1rCwqxjZHIo6t3aqvc2Hjj%2FENuGU9F8qLn%2F4HSsiaC3Sukth29CJ%2FIfm0DoG%2FPOpXcim37L%2BRGwafmRwN%2B34IPmlvf26KZfI8wQs9UXMmntP2FJP%2FEplJo%2FEuXUDDhLf4tdAg9dU6tbD8htpv%2FZ56%2BEYQ04G6xmNAeWyyYRYW%2BqH6QVG4vuesnwHsUFVE4r7Q4bD2AxRlxgBllMZb9xzCLFetaycJDSQe4RdWGHJtZe55ya806yBuHB3UEIOGCumNPnid8l%2BBkBxT47OXgjG0nQdZNEGlEbG8iU48EiFS%2BfynKs4mEnSwTUQwhNu%2BWoLCLWmr%2BaOWmLkzxkAF6DlCu5U4PEwv0kXLndfcSaUEdYFF1tSL6RjTjR%2F4%2FserlCJRcSC0A70S6zmMbbOJuTCTkFyZCbqppDwf3nbJIzemAl%2FNrhVTetxsOmVhtlYVIdWuIJsMR7pYLYn5O%2BJmmh84Qc78kaOcsh9IKStCc4s7wELskCRSZWlSlVcYTDe1y3u0Azm2jzKUoABLHZ9Gayot1pMs7Ezn44LtE0hIh6os5pialL6zko4EYcZwfFiJSo0zoKsO7C11hQRmWGjq9ZhzS17zVB68Uew11CRT2etioyLsWm0CulA60Qgl1Q3FhL2R0KGQ%2BVqJEQkT54SLGekGCD7A5m%2FAvJh2LOBlQo9XASyku5u4rhmSkHKP7PsYZvvAU38BIRQiJ%2FsNWG97AjUQfgHYLSFjuf9WfC6MGAL3akp5hbpczWPA5%2F0Kqh0QufsQ3FKt8oJHOgjavhW377FPwjPWPquNEQqJfXXFzbCLuu5Fo9dMm97xDMH9KJJNgJOg9VKpdhs0QZHZcHCZgzxR2RTrOotCmAA8xftgXFNd9%2BWk5tunEAteh6V5ByAox3YaUW4P%2FsPW2zAZ5eIXD7IFBnSN%2Bh1mwjkvV0iOw1pqDjahnAaTIBcM75Gcrjj5BZxbXdLsLKiEkjv30wyXvFmgAvISyDbT1JhfC7vxYw9wbQjxQte1G0Z0jdM3wY4NkW2GxS%2F0Yz5hdfDx8oVuW4axhzLyucNXmnWtXmSEilV7dOPCPAD%2BY%2B2Gb1jSwmVdZJy3ND9Get hashmaliciousUnknownBrowse
                                                          _V2.HtMLGet hashmaliciousHTMLPhisherBrowse
                                                            https://www.pdfhubonline.com/install-appGet hashmaliciousUnknownBrowse
                                                              https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fnorthcape.com.au.CBS4.ya2.design?anVsaWUua29yb3dlQG5vcnRoY2FwZS5jb20uYXU=Get hashmaliciousUnknownBrowse
                                                                https://download.zotero.org/client/release/6.0.26/Zotero-6.0.26_setup.exeGet hashmaliciousUnknownBrowse
                                                                  https://bs.serving-sys.com/Serving/adServer.bs?cn=brd&PluID=0&Pos=20&EyeblasterID=1086486580&clk=1&ctick=00484900&rtu=https%3A%2F%2F4bdp40.codesandbox.io?pop=kkronberg%40whitehouseleisure.co.ukGet hashmaliciousHTMLPhisherBrowse
                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fpaul-lueftung.de.N9bB.dedelices.fr?dGhvbWFzLmxpbmtAcGF1bC1sdWVmdHVuZy5kZQ==Get hashmaliciousUnknownBrowse
                                                                      https://fukutex.net/uqe/Get hashmaliciousUnknownBrowse
                                                                        https://dweb.link/ipfs/Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt?filename=Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt#reservation@anaintercontinental-tokyo.jpGet hashmaliciousUnknownBrowse
                                                                          https://www.bing.com/ck/a?!&&p=3b853cb72f7f4f36JmltdHM9MTY4MjU1MzYwMCZpZ3VpZD0wNDVjZTI0Ny0wZGFkLTY5YTktMmI1ZS1mMGI0MGMyNjY4YjEmaW5zaWQ9NTIyNQ&ptn=3&hsh=3&fclid=045ce247-0dad-69a9-2b5e-f0b40c2668b1&u=a1aHR0cHM6Ly90cGFhZHZpc29ycy5jb20vMjAyMS8xMS8wNS9sZXNzb25zLWxlYXJuZWQtZnJvbS10aGUtcGFuZGVtaWMtaXMtaXQtdGltZS10by1jb25zaWRlci1vdXRzb3VyY2luZy8Get hashmaliciousUnknownBrowse
                                                                            https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fintertecqatar.com%2Fcss%2Fjs%2Fsiasia%2Fgemseducation.com%2F%2F%2F%2F%2Fa3Jpc2huYW4uZ29waUBnZW1zZWR1Y2F0aW9uLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                              https://Microsoft.at-au.therelayservice.com/service/7LUXeQqjd17vo49IsAc8GADu_LekAgG1aVTFnqdMYtDLfTFLPvQWEMt9fDjvKVni5W-yJnMqg27g4rC600BfcvzHAEaiihjRriLQjI7UwaqQvp1964V5aKS3r9aGzZAPDiMEAL5ibWWjdYuQrqgUReb0tFbGH12RdE489hF5B5lgWuSsYmPxEa1BqLD4DeccCctAmlkNy_e9FeaEDvviF5_6-mZPj_iRBX6S_SoW9a-bl2y76_62J07NSaQ8CitaBgct_1DnkFMpMPCjyhAzRxiWVI7P3gROldun_tl39TrpJb2gX9x03zaHCRGAV1kSo8TjC8uFQtvPIMW08902PAsSJpNQgPXnGuB3cjfKaPXaHCOyE6hfhsesk0pmRkF8j7o4bK2fhpiYihPnRnJ3tgGet hashmaliciousUnknownBrowse
                                                                                https://slickdeals.net/?adobeRef=4796c816dd6211edbcf236987a0a01ff0000&sdtid=16572596&sdpid=162856616&sdfid=30&lno=3&trd=https%20go%20redirectinga%20wbr%20t%20com%20&pv&au&u2=https%3A%2F%2F3byx7k.codesandbox.io%2F%3Fmandate=YWVsbHN3b3J0aEBiaWdnZS5jb20=Get hashmaliciousHTMLPhisherBrowse
                                                                                  https://slickdeals.net/?adobeRef=4796c816dd6211edbcf236987a0a01ff0000&sdtid=16572596&sdpid=162856616&sdfid=30&lno=3&trd=https%20go%20redirectinga%20wbr%20t%20com%20&pv&au&u2=https%3A%2F%2F3byx7k.codesandbox.io%2F%3Fmandate=dGhhcnR1bmdAZW5uZWFkLmNvbQ==Get hashmaliciousUnknownBrowse
                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                    www.google.comlogin.htmlGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.186.132
                                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fstn7ny.codesandbox.io?pop=someone.else%40somewhere.comGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 172.217.16.196
                                                                                    iata-25May2023.shtmlGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://s3.amazonaws.com/v5c323s5fg7hnj-794372450934/tv.htmlGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    06472899.jsGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    file.jsGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    25 May 2023-9706 PM-GTT4FIWVGZ.htmGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 142.250.185.68
                                                                                    https://269.bowwordon.live/fxddhqsm/?u=3w8p605&o=pn1kfzq&f=1&sid=t2~hckuzwxtbpsvmcpf30ztc331&fp=FvEsrkTArOgrxzhB2zExAA2IZuNTD8%2Fd9njv3jvDDOYnVROoSzmzg9nW12cfMdaHPT88q85r2inPkFCSbWgnzkfJFZZA3Mrzk%2F75MnETRxlcbvcR%2BeCurFnWMWd%2Fga7euAPm2FuOzEEhPFPKB9BvYYMpUxFP0z7K9pb7kfgbNf7SPRnAgQYfnloabfpuR%2BvXfyPOArMa%2B%2FuoZCunaXhl0et9vEushY7p%2FHvZJdO3bDfSLkShHDI5ukbNxghFhqsVSdcuoNPFbXVxUMFSYBPgTzlZOfrmXROiGBlvljFG6fsmagUS%2FcuqeVrqE60PwBTm3%2Fi07AuZFW5fp%2FVgaJ6PbiRsnFEiC40thM192GKHQmbP7RKplWwBB8%2B8V9R2MWg%2FLK44BnmLVLfMpK%2FaPUB4ZbPCt%2B1mkosN9tSoNyEbMODuLao0Z7nZzXzxHsVCzILD9XrGiz4%2BbS2yy4q2xExA%2FoVYHMdITtz12kRrUwM13QZcFjcbuNxO6UPZKT9ClRRrlg0lIkw74ioZ2xrB9aRabwONkY0LAtlodraoxsFw%2Frjld227l0ZlFzSfF7ItEflen4OWRtOFW9Wrsiz2kpJPf5oRAHrdZUkN3qG%2F15O3V44Vu5%2BpENw113oXAb%2B5jOBgRRW6I1X0bf8cLxhowerhiMxt50rO8mBdxAQdPHCn0gH0ebxDhuaS%2FLYgUGT1lau3HqE%2F1rCwqxjZHIo6t3aqvc2Hjj%2FENuGU9F8qLn%2F4HSsiaC3Sukth29CJ%2FIfm0DoG%2FPOpXcim37L%2BRGwafmRwN%2B34IPmlvf26KZfI8wQs9UXMmntP2FJP%2FEplJo%2FEuXUDDhLf4tdAg9dU6tbD8htpv%2FZ56%2BEYQ04G6xmNAeWyyYRYW%2BqH6QVG4vuesnwHsUFVE4r7Q4bD2AxRlxgBllMZb9xzCLFetaycJDSQe4RdWGHJtZe55ya806yBuHB3UEIOGCumNPnid8l%2BBkBxT47OXgjG0nQdZNEGlEbG8iU48EiFS%2BfynKs4mEnSwTUQwhNu%2BWoLCLWmr%2BaOWmLkzxkAF6DlCu5U4PEwv0kXLndfcSaUEdYFF1tSL6RjTjR%2F4%2FserlCJRcSC0A70S6zmMbbOJuTCTkFyZCbqppDwf3nbJIzemAl%2FNrhVTetxsOmVhtlYVIdWuIJsMR7pYLYn5O%2BJmmh84Qc78kaOcsh9IKStCc4s7wELskCRSZWlSlVcYTDe1y3u0Azm2jzKUoABLHZ9Gayot1pMs7Ezn44LtE0hIh6os5pialL6zko4EYcZwfFiJSo0zoKsO7C11hQRmWGjq9ZhzS17zVB68Uew11CRT2etioyLsWm0CulA60Qgl1Q3FhL2R0KGQ%2BVqJEQkT54SLGekGCD7A5m%2FAvJh2LOBlQo9XASyku5u4rhmSkHKP7PsYZvvAU38BIRQiJ%2FsNWG97AjUQfgHYLSFjuf9WfC6MGAL3akp5hbpczWPA5%2F0Kqh0QufsQ3FKt8oJHOgjavhW377FPwjPWPquNEQqJfXXFzbCLuu5Fo9dMm97xDMH9KJJNgJOg9VKpdhs0QZHZcHCZgzxR2RTrOotCmAA8xftgXFNd9%2BWk5tunEAteh6V5ByAox3YaUW4P%2FsPW2zAZ5eIXD7IFBnSN%2Bh1mwjkvV0iOw1pqDjahnAaTIBcM75Gcrjj5BZxbXdLsLKiEkjv30wyXvFmgAvISyDbT1JhfC7vxYw9wbQjxQte1G0Z0jdM3wY4NkW2GxS%2F0Yz5hdfDx8oVuW4axhzLyucNXmnWtXmSEilV7dOPCPAD%2BY%2B2Gb1jSwmVdZJy3ND9Get hashmaliciousUnknownBrowse
                                                                                    • 142.250.186.68
                                                                                    _V2.HtMLGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 142.250.184.228
                                                                                    https://www.pdfhubonline.com/install-appGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fnorthcape.com.au.CBS4.ya2.design?anVsaWUua29yb3dlQG5vcnRoY2FwZS5jb20uYXU=Get hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://download.zotero.org/client/release/6.0.26/Zotero-6.0.26_setup.exeGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://bs.serving-sys.com/Serving/adServer.bs?cn=brd&PluID=0&Pos=20&EyeblasterID=1086486580&clk=1&ctick=00484900&rtu=https%3A%2F%2F4bdp40.codesandbox.io?pop=kkronberg%40whitehouseleisure.co.ukGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 142.250.184.228
                                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fpaul-lueftung.de.N9bB.dedelices.fr?dGhvbWFzLmxpbmtAcGF1bC1sdWVmdHVuZy5kZQ==Get hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://fukutex.net/uqe/Get hashmaliciousUnknownBrowse
                                                                                    • 142.250.184.228
                                                                                    https://dweb.link/ipfs/Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt?filename=Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt#reservation@anaintercontinental-tokyo.jpGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://www.bing.com/ck/a?!&&p=3b853cb72f7f4f36JmltdHM9MTY4MjU1MzYwMCZpZ3VpZD0wNDVjZTI0Ny0wZGFkLTY5YTktMmI1ZS1mMGI0MGMyNjY4YjEmaW5zaWQ9NTIyNQ&ptn=3&hsh=3&fclid=045ce247-0dad-69a9-2b5e-f0b40c2668b1&u=a1aHR0cHM6Ly90cGFhZHZpc29ycy5jb20vMjAyMS8xMS8wNS9sZXNzb25zLWxlYXJuZWQtZnJvbS10aGUtcGFuZGVtaWMtaXMtaXQtdGltZS10by1jb25zaWRlci1vdXRzb3VyY2luZy8Get hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fintertecqatar.com%2Fcss%2Fjs%2Fsiasia%2Fgemseducation.com%2F%2F%2F%2F%2Fa3Jpc2huYW4uZ29waUBnZW1zZWR1Y2F0aW9uLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                    • 142.250.203.100
                                                                                    https://Microsoft.at-au.therelayservice.com/service/7LUXeQqjd17vo49IsAc8GADu_LekAgG1aVTFnqdMYtDLfTFLPvQWEMt9fDjvKVni5W-yJnMqg27g4rC600BfcvzHAEaiihjRriLQjI7UwaqQvp1964V5aKS3r9aGzZAPDiMEAL5ibWWjdYuQrqgUReb0tFbGH12RdE489hF5B5lgWuSsYmPxEa1BqLD4DeccCctAmlkNy_e9FeaEDvviF5_6-mZPj_iRBX6S_SoW9a-bl2y76_62J07NSaQ8CitaBgct_1DnkFMpMPCjyhAzRxiWVI7P3gROldun_tl39TrpJb2gX9x03zaHCRGAV1kSo8TjC8uFQtvPIMW08902PAsSJpNQgPXnGuB3cjfKaPXaHCOyE6hfhsesk0pmRkF8j7o4bK2fhpiYihPnRnJ3tgGet hashmaliciousUnknownBrowse
                                                                                    • 142.250.203.100
                                                                                    No context
                                                                                    No context
                                                                                    No context
                                                                                    No created / dropped files found
                                                                                    File type:HTML document, Unicode text, UTF-8 text, with very long lines (7825)
                                                                                    Entropy (8bit):5.840089611320105
                                                                                    TrID:
                                                                                    • Atom web feed (35501/1) 20.76%
                                                                                    • HyperText Markup Language XML (18501/1) 10.82%
                                                                                    • Scalable Vector Graphics (18501/1) 10.82%
                                                                                    • Artificial Intelligence Markup Language (14501/1) 8.48%
                                                                                    • Mathematical Markup Language (13501/1) 7.89%
                                                                                    File name:login.html
                                                                                    File size:5877035
                                                                                    MD5:daccb43d7df16a5b00d0db1340b979ab
                                                                                    SHA1:ef1e463b2cff4c9b8e5487422ae63ec15083bcbc
                                                                                    SHA256:f0a3bb756492268062c421579e4115d2764a713e5b7cd2fc95a89c94814e6fc2
                                                                                    SHA512:c310eee3cab573e728387b3a7a698e36e36ae3ba26c37d85961cd0d7dd96e1e312eb88a9fb014b8099e821b14c0b3b51653e5aed269503f00f261d05b8fe14a0
                                                                                    SSDEEP:49152:2brAJ6aVxCVUuabZ2LTR17ATlxqiCLX8tfMEvCewKyZlUX7+dZdabAhawsKpg6za:JwwrctOT
                                                                                    TLSH:1F466B737981247243A686E990EF1285BF3C3347D0054628F36CD9EE5BE9984D1A7BBC
                                                                                    File Content Preview:<!doctype html> [if lt IE 7]>.<html class="no-js lt-ie9 lt-ie8 lt-ie7" lang="en"> <![endif]--> [if IE 7]>.<html class="no-js lt-ie9 lt-ie8" lang="en"> <![endif]--> [if IE 8]>.<html class="no-js lt-ie9" lang="en"> <![endif]--> [if gt IE 8]>
                                                                                    Icon Hash:0f3149cc4c490307
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    May 26, 2023 13:18:19.049274921 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.049443960 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.049551964 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.053368092 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.053436995 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.103064060 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.103144884 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.103257895 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.103584051 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.103621006 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.150820017 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.167960882 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.168047905 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.170989990 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.171118975 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.172354937 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.186816931 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.186856031 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.188234091 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.188468933 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.190368891 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.190493107 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.505518913 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.505951881 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.506926060 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.507004023 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.507209063 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.507611036 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.507841110 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.507882118 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.538070917 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.538244009 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.538295984 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.538394928 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.538547039 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.539030075 CEST49750443192.168.2.3216.58.212.174
                                                                                    May 26, 2023 13:18:19.539067984 CEST44349750216.58.212.174192.168.2.3
                                                                                    May 26, 2023 13:18:19.567183971 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.591365099 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.591702938 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:19.591830969 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.593846083 CEST49749443192.168.2.3142.250.186.45
                                                                                    May 26, 2023 13:18:19.593898058 CEST44349749142.250.186.45192.168.2.3
                                                                                    May 26, 2023 13:18:22.844258070 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.844336033 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.844451904 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.845412970 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.845443010 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.914408922 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.914860010 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.914885998 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.916234016 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.916428089 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.919033051 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.919131994 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:22.979422092 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:22.979477882 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:23.177371025 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:32.902923107 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:32.903064013 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:32.903162003 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:33.457587957 CEST49752443192.168.2.3216.58.212.164
                                                                                    May 26, 2023 13:18:33.457644939 CEST44349752216.58.212.164192.168.2.3
                                                                                    May 26, 2023 13:18:49.135298014 CEST49755443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:18:49.135365963 CEST44349755192.168.8.1192.168.2.3
                                                                                    May 26, 2023 13:18:49.135622978 CEST49755443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:18:49.136478901 CEST49755443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:18:49.136503935 CEST44349755192.168.8.1192.168.2.3
                                                                                    May 26, 2023 13:19:19.140274048 CEST49755443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:19:19.186825037 CEST44349755192.168.8.1192.168.2.3
                                                                                    May 26, 2023 13:19:22.894849062 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:22.894946098 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:22.895067930 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:22.895514011 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:22.895553112 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:22.956020117 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:22.962094069 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:22.962141037 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:22.963306904 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:22.963895082 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:22.964273930 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:23.004708052 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:32.976198912 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:32.976371050 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:32.976562977 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:33.808655024 CEST49759443192.168.2.3172.217.16.196
                                                                                    May 26, 2023 13:19:33.808713913 CEST44349759172.217.16.196192.168.2.3
                                                                                    May 26, 2023 13:19:56.780175924 CEST49761443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:19:56.780307055 CEST44349761192.168.8.1192.168.2.3
                                                                                    May 26, 2023 13:19:56.780524969 CEST49761443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:19:56.781084061 CEST49761443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:19:56.781121016 CEST44349761192.168.8.1192.168.2.3
                                                                                    May 26, 2023 13:20:04.193053961 CEST49755443192.168.2.3192.168.8.1
                                                                                    May 26, 2023 13:20:04.193088055 CEST44349755192.168.8.1192.168.2.3
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    May 26, 2023 13:18:18.913467884 CEST5861553192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:18:18.914005995 CEST5202653192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:18:18.930218935 CEST53586151.1.1.1192.168.2.3
                                                                                    May 26, 2023 13:18:18.930712938 CEST53520261.1.1.1192.168.2.3
                                                                                    May 26, 2023 13:18:22.794048071 CEST5931853192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:18:22.810914993 CEST53593181.1.1.1192.168.2.3
                                                                                    May 26, 2023 13:18:22.820312977 CEST5952053192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:18:22.836958885 CEST53595201.1.1.1192.168.2.3
                                                                                    May 26, 2023 13:19:22.854386091 CEST6055653192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:19:22.871488094 CEST53605561.1.1.1192.168.2.3
                                                                                    May 26, 2023 13:19:22.876698971 CEST5513153192.168.2.31.1.1.1
                                                                                    May 26, 2023 13:19:22.893430948 CEST53551311.1.1.1192.168.2.3
                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                    May 26, 2023 13:18:18.913467884 CEST192.168.2.31.1.1.10xd5c9Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:18.914005995 CEST192.168.2.31.1.1.10x75b8Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:22.794048071 CEST192.168.2.31.1.1.10x367fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:22.820312977 CEST192.168.2.31.1.1.10x58f4Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:19:22.854386091 CEST192.168.2.31.1.1.10xae09Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:19:22.876698971 CEST192.168.2.31.1.1.10x2807Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                    May 26, 2023 13:18:18.930218935 CEST1.1.1.1192.168.2.30xd5c9No error (0)accounts.google.com142.250.186.45A (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:18.930712938 CEST1.1.1.1192.168.2.30x75b8No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                    May 26, 2023 13:18:18.930712938 CEST1.1.1.1192.168.2.30x75b8No error (0)clients.l.google.com216.58.212.174A (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:22.810914993 CEST1.1.1.1192.168.2.30x367fNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:18:22.836958885 CEST1.1.1.1192.168.2.30x58f4No error (0)www.google.com216.58.212.164A (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:19:22.871488094 CEST1.1.1.1192.168.2.30xae09No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
                                                                                    May 26, 2023 13:19:22.893430948 CEST1.1.1.1192.168.2.30x2807No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                                                                                    • clients2.google.com
                                                                                    • accounts.google.com
                                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                    0192.168.2.349750216.58.212.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    TimestampkBytes transferredDirectionData
                                                                                    2023-05-26 11:18:19 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                                                                    Host: clients2.google.com
                                                                                    Connection: keep-alive
                                                                                    X-Goog-Update-Interactivity: fg
                                                                                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                                                                    X-Goog-Update-Updater: chromecrx-104.0.5112.102
                                                                                    Sec-Fetch-Site: none
                                                                                    Sec-Fetch-Mode: no-cors
                                                                                    Sec-Fetch-Dest: empty
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                    2023-05-26 11:18:19 UTC1INHTTP/1.1 200 OK
                                                                                    Content-Security-Policy: script-src 'report-sample' 'nonce-ai4fktZxvrgG-tHW-wnYdw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                    Date: Fri, 26 May 2023 11:18:19 GMT
                                                                                    Content-Type: text/xml; charset=UTF-8
                                                                                    X-Daynum: 5989
                                                                                    X-Daystart: 15499
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    X-XSS-Protection: 1; mode=block
                                                                                    Server: GSE
                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                    Accept-Ranges: none
                                                                                    Vary: Accept-Encoding
                                                                                    Connection: close
                                                                                    Transfer-Encoding: chunked
                                                                                    2023-05-26 11:18:19 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 38 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 35 34 39 39 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                                                                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5989" elapsed_seconds="15499"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                                                                    2023-05-26 11:18:19 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                                                                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                                                                    2023-05-26 11:18:19 UTC2INData Raw: 30 0d 0a 0d 0a
                                                                                    Data Ascii: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                    1192.168.2.349749142.250.186.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    TimestampkBytes transferredDirectionData
                                                                                    2023-05-26 11:18:19 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                                                                    Host: accounts.google.com
                                                                                    Connection: keep-alive
                                                                                    Content-Length: 1
                                                                                    Origin: https://www.google.com
                                                                                    Content-Type: application/x-www-form-urlencoded
                                                                                    Sec-Fetch-Site: none
                                                                                    Sec-Fetch-Mode: no-cors
                                                                                    Sec-Fetch-Dest: empty
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                    Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
                                                                                    2023-05-26 11:18:19 UTC1OUTData Raw: 20
                                                                                    Data Ascii:
                                                                                    2023-05-26 11:18:19 UTC2INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json; charset=utf-8
                                                                                    Access-Control-Allow-Origin: https://www.google.com
                                                                                    Access-Control-Allow-Credentials: true
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                    Date: Fri, 26 May 2023 11:18:19 GMT
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                    Cross-Origin-Opener-Policy: same-origin
                                                                                    Content-Security-Policy: script-src 'report-sample' 'nonce-To8RjGWPAOqXRHu0lVV2eA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                                                                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                                                                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                                                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                                    Server: ESF
                                                                                    X-XSS-Protection: 0
                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                    Accept-Ranges: none
                                                                                    Vary: Accept-Encoding
                                                                                    Connection: close
                                                                                    Transfer-Encoding: chunked
                                                                                    2023-05-26 11:18:19 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                                                                    Data Ascii: 11["gaia.l.a.r",[]]
                                                                                    2023-05-26 11:18:19 UTC4INData Raw: 30 0d 0a 0d 0a
                                                                                    Data Ascii: 0


                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Target ID:0
                                                                                    Start time:13:18:16
                                                                                    Start date:26/05/2023
                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html
                                                                                    Imagebase:0x7ff70f0c0000
                                                                                    File size:2852640 bytes
                                                                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high

                                                                                    Target ID:1
                                                                                    Start time:13:18:17
                                                                                    Start date:26/05/2023
                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1772,i,15227930420298686886,3054010558266752575,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                                    Imagebase:0x7ff70f0c0000
                                                                                    File size:2852640 bytes
                                                                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high

                                                                                    No disassembly