Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html

Overview

General Information

Sample URL:https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
Analysis ID:1396484
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Creates files inside the system directory
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 1440 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1932,i,1781409829972273078,7043298505215807192,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4952 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://surfacebeat.com/0/0/0/88fab4e1c9f934fe5a30ad27d5f1b629/Avira URL Cloud: Label: phishing
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
Source: chromecache_55.2.drString found in binary or memory: https://surfacebeat.com/0/0/0/88fab4e1c9f934fe5a30ad27d5f1b629/
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1440_1613111084Jump to behavior
Source: classification engineClassification label: mal48.win@16/10@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1932,i,1781409829972273078,7043298505215807192,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1932,i,1781409829972273078,7043298505215807192,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://surfacebeat.com/0/0/0/88fab4e1c9f934fe5a30ad27d5f1b629/100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.167.84
truefalse
    high
    www.google.com
    142.251.40.196
    truefalse
      high
      clients.l.google.com
      142.250.80.14
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://surfacebeat.com/0/0/0/88fab4e1c9f934fe5a30ad27d5f1b629/chromecache_55.2.drfalse
                • Avira URL Cloud: phishing
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.251.167.84
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                142.250.80.14
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.251.40.196
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.17
                192.168.2.5
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1396484
                Start date and time:2024-02-21 21:20:20 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 6s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@16/10@6/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.64.67, 34.104.35.123, 20.209.1.1, 192.229.211.108, 72.21.81.240, 52.165.165.26, 20.242.39.171, 13.95.31.18, 20.114.59.183, 142.250.81.227, 20.12.23.50
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 21 19:21:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9757014407011018
                Encrypted:false
                SSDEEP:48:8s4dDTrPvHG0idAKZdA19ehwiZUklqehTy+3:8T3Zoy
                MD5:27F329E83C734642829780769D2F1931
                SHA1:7D741029F66103156E4AD676961CF61CDBA272F5
                SHA-256:CED0F93DFC55C3E111599226272D174E70196EFD789EDDEDCA0D3427926553BA
                SHA-512:3841C050DF88A4BCE8F2AE00ECDBD696D781837E40AB565EC78E69ED6F73C73CF1EDC1FD1CA1352DFFAA1A3FC2624B746AD2AC93DF42CE7433748048C1121EEF
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....V....e..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VUX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 21 19:21:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):3.9947704572563962
                Encrypted:false
                SSDEEP:48:8CwdDTrPvHG0idAKZdA1weh/iZUkAQkqehYy+2:8L3L9Q1y
                MD5:3DB97AF43E828F1EEAE81AAA79CB7785
                SHA1:0E162BFDC0562A3047F7A484EC3D01FE175E06EB
                SHA-256:BF8E61BBFB9B3708D52F0716F2BDFEE684B621F7DEC2A4BD3606E26D457FE416
                SHA-512:BEF078EACC1A53E1464E0F18CAEE2ECF0190EE3A75092103D803A0890BD7C5651985B9B356D9203751B357091329CAAAAA99D13E504DF1E7FA87C349A651E931
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....Q....e..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VUX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2693
                Entropy (8bit):4.003844344140967
                Encrypted:false
                SSDEEP:48:8xwdDTrPsHG0idAKZdA14tseh7sFiZUkmgqeh7sSy+BX:8xc36nsy
                MD5:91C8B54476B236067F2D873F20C74C7F
                SHA1:67F2499C85EE9832D8A203AEC9522E83685473ED
                SHA-256:EAEDF6AA7D30D71AD17FABAEC524304916CC04371544E5BF953086C5B40FDFF6
                SHA-512:5C6D28AAA732EB0F3846F5537079E7D9C173F2132056E65931144695BCCC310F5BA0193D48BAB2455872FB464E40CF86B7253C964222BBD2EAEF5BE9FF0BE0B4
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 21 19:21:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.993029246750521
                Encrypted:false
                SSDEEP:48:8M4dDTrPvHG0idAKZdA1vehDiZUkwqeh0y+R:8z3Iay
                MD5:2C2EAF0033023941A6BB2A93CFA6E53F
                SHA1:E95FD8FBF20917677EB1640356EB5F8390173DD3
                SHA-256:F14AB40CD24F44DE6C3DFE492C35394818823A0089788017CB2B03F25A02F2A3
                SHA-512:2A9AC8D2C8C43E48AB5FC4915816953E9330ADEC62395EC360318453107A6426FE60F5CA0A91D282939EE4125D19BE4818F6247E6058340BBD35AA70D38D38EC
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.........e..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VUX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 21 19:21:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.980824843827719
                Encrypted:false
                SSDEEP:48:8ydDTrPvHG0idAKZdA1hehBiZUk1W1qehGy+C:8+3Y9my
                MD5:1DB09E77005B2E5AACA169ECFDF711C1
                SHA1:F985E733A52B0FD0B7BC54A62C20D37CC4724E7C
                SHA-256:E84109060A8BBB45E6E48E7C1860420329E5A7114E8A5D20D82A0750F06FB5AC
                SHA-512:345171666E4BECCE1CA9830853A8E1D56D57108BE5A25939203BD1C4E5DF61FA29B7464B29B2DA41CFC248CBD10A0FFBEA3FC4B4B67B9246F08B8065B76D9B30
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.........e..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VUX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Feb 21 19:21:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2683
                Entropy (8bit):3.9906582510650384
                Encrypted:false
                SSDEEP:48:8ZdDTrPvHG0idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbsy+yT+:8P32T/TbxWOvTbsy7T
                MD5:F0A26B364BDCFF64FC2BDE330919B2C9
                SHA1:8BD8602D201485A00DA546682CFFCD94386432C7
                SHA-256:184BD333E3B077D7963C8C318B2B5791D49C13B3B0F7BD35CEFB35E5B8D26A3B
                SHA-512:96AB5D8DFCEC63F9234ABDDF129EAFCDD135C7CACD022559EE7B0C1ECA6111C5860DC9B4E0F475A8116A0F0437DD0C354BA9372CF373966A68C8934BC452D16D
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,...._|..e..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IUX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VUX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VUX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VUX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VUX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
                Category:downloaded
                Size (bytes):226
                Entropy (8bit):5.2441249259228115
                Encrypted:false
                SSDEEP:6:JiMVBdgqZj8DHgWdzRiAU2uvxV16H6OfRI+/R8g6n:MMHdVBMHgWdzR056Hn/n6
                MD5:8310D18FC4AA3257E8D42735E81C5031
                SHA1:F51643A6D9107883855E6BC142E1F2F2A18EAFAC
                SHA-256:1C9AD0F2D79D1B65898756D91BBFCB0DE03CB653E9F6C8CE9E75CBAEE50D84E5
                SHA-512:1A6AC9F9E9BDFD8552D0E7AD64CFB1B45024899ABA2594B2FBBF27A9B4E5A12CDF14D3C497599F0062A35985F3B7B68C8968640E886BF469A54768ADFE064D2B
                Malicious:false
                Reputation:low
                URL:https://cddehakdhe32cnherf.blob.core.windows.net/favicon.ico
                Preview:.<?xml version="1.0" encoding="utf-8"?><Error><Code>OutOfRangeInput</Code><Message>One of the request inputs is out of range..RequestId:df8fdb5e-a01e-0055-0103-65f40f000000.Time:2024-02-21T20:22:33.2770195Z</Message></Error>
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):611
                Entropy (8bit):5.196116546605604
                Encrypted:false
                SSDEEP:12:GM8SqXyWOpdBfDj+fljUDDGisoMyhLGUDEnCShm8Kaksc8OKYG2L2xL4/b:GM8lNjr3ilPch4/b
                MD5:26417FECB00B856D271A64F774E98B03
                SHA1:41AC0780E537C5154E76BE157DE22DE14F4BFE5E
                SHA-256:7E65A2177EB9EDAB4AEA35C0CC1B7E928C20BBC665E6A0D847D3295005045C06
                SHA-512:7F29612B514028B7A6A6D7CEB9B1D7049F96CFFD0B024439175709FAEC5AA7CD12A8A6BC670E84F58EDFE494208380595F9A1790911364B278F1362D67131C66
                Malicious:false
                Reputation:low
                URL:https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
                Preview:<meta http-equiv="refresh" content="3; url=">..<script>..// Initial URL....var initialURL = window.location.href;....// Extracting the hash part of the URL..var hashPart = initialURL.split('#')[1];....// Extracting values from the hash part..var hashValues = hashPart.split('/');....// Rearranging the values for the new URL format..var newURL = 'https://surfacebeat.com/0/0/0/88fab4e1c9f934fe5a30ad27d5f1b629/' + hashValues[2] + '/' + hashValues[1].split('_')[0] + '_32/' + hashValues[5] + '_' + hashValues[6] + '_' + hashValues[3] + '_' + hashValues[4] + '_md' ;....document.location.href = newURL;..</script>
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 21:21:09.963762999 CET49674443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:09.963830948 CET49675443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:10.120037079 CET49673443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:15.503324986 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.503381968 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.503453016 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.504738092 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.504770994 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.504825115 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.505716085 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.505736113 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.505970001 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.505981922 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.734329939 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.735033035 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.735044956 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.735574961 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.735630989 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.736999035 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.737042904 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.737777948 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.737857103 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.737879992 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.777905941 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.787646055 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.787657022 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.788111925 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.788328886 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.788391113 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.789391041 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.789454937 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.790586948 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.790661097 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.790889025 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:15.790905952 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:15.834542036 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.928483963 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.928874969 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.928927898 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.929790020 CET49706443192.168.2.5142.250.80.14
                Feb 21, 2024 21:21:15.929805994 CET44349706142.250.80.14192.168.2.5
                Feb 21, 2024 21:21:15.975176096 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:16.073930979 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:16.074083090 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:16.074141979 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:16.074866056 CET49705443192.168.2.5142.251.167.84
                Feb 21, 2024 21:21:16.074888945 CET44349705142.251.167.84192.168.2.5
                Feb 21, 2024 21:21:19.569130898 CET49675443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:19.569184065 CET49674443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:19.727179050 CET49673443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:19.903964996 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:19.904057980 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:19.904161930 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:19.907180071 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:19.907216072 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.188393116 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.189832926 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:20.189898014 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.191493988 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.191716909 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:20.203739882 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:20.203934908 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.257179022 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:20.257240057 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:20.294006109 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.294039965 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.294161081 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.296853065 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.296884060 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.307183027 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:20.488162041 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.488236904 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.495171070 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.495181084 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.495474100 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.538319111 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.656498909 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.697907925 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.747665882 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.747828007 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.747867107 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.747896910 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.747910023 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.747910023 CET49715443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.747917891 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.747924089 CET4434971523.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.795775890 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.795810938 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.795881987 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.796243906 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.796261072 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.985146999 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.985224962 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.986768961 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:20.986777067 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.987008095 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:20.988375902 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:21.029903889 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:21.160520077 CET4434970323.1.237.91192.168.2.5
                Feb 21, 2024 21:21:21.160600901 CET49703443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:21.163146019 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:21.163583994 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:21.163634062 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:21.166882038 CET49718443192.168.2.523.51.58.94
                Feb 21, 2024 21:21:21.166894913 CET4434971823.51.58.94192.168.2.5
                Feb 21, 2024 21:21:30.215301037 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:30.215454102 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:21:30.215636969 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:30.641812086 CET49703443192.168.2.523.1.237.91
                Feb 21, 2024 21:21:30.794806957 CET4434970323.1.237.91192.168.2.5
                Feb 21, 2024 21:21:31.903273106 CET49714443192.168.2.5142.251.40.196
                Feb 21, 2024 21:21:31.903348923 CET44349714142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:19.842508078 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:19.842556953 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:19.842628956 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:19.842869997 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:19.842885971 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:20.129317999 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:20.129611015 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:20.129626036 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:20.131092072 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:20.131459951 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:20.131546974 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:20.178605080 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:30.110028982 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:30.110203028 CET44349756142.251.40.196192.168.2.5
                Feb 21, 2024 21:22:30.110255003 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:31.953411102 CET49756443192.168.2.5142.251.40.196
                Feb 21, 2024 21:22:31.953439951 CET44349756142.251.40.196192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 21:21:15.408252954 CET6212553192.168.2.51.1.1.1
                Feb 21, 2024 21:21:15.408488989 CET5215753192.168.2.51.1.1.1
                Feb 21, 2024 21:21:15.409779072 CET6279753192.168.2.51.1.1.1
                Feb 21, 2024 21:21:15.411839008 CET6009153192.168.2.51.1.1.1
                Feb 21, 2024 21:21:15.466937065 CET53572101.1.1.1192.168.2.5
                Feb 21, 2024 21:21:15.496382952 CET53621251.1.1.1192.168.2.5
                Feb 21, 2024 21:21:15.496592045 CET53521571.1.1.1192.168.2.5
                Feb 21, 2024 21:21:15.497958899 CET53627971.1.1.1192.168.2.5
                Feb 21, 2024 21:21:15.500228882 CET53600911.1.1.1192.168.2.5
                Feb 21, 2024 21:21:16.078071117 CET53497441.1.1.1192.168.2.5
                Feb 21, 2024 21:21:19.793323040 CET5342853192.168.2.51.1.1.1
                Feb 21, 2024 21:21:19.793754101 CET6177453192.168.2.51.1.1.1
                Feb 21, 2024 21:21:19.881356001 CET53617741.1.1.1192.168.2.5
                Feb 21, 2024 21:21:19.881469011 CET53534281.1.1.1192.168.2.5
                Feb 21, 2024 21:21:33.163959980 CET53539861.1.1.1192.168.2.5
                Feb 21, 2024 21:21:52.252469063 CET53574321.1.1.1192.168.2.5
                Feb 21, 2024 21:22:15.058990002 CET53597291.1.1.1192.168.2.5
                Feb 21, 2024 21:22:15.317691088 CET53519891.1.1.1192.168.2.5
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Feb 21, 2024 21:21:15.408252954 CET192.168.2.51.1.1.10x91e4Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:15.408488989 CET192.168.2.51.1.1.10x94c9Standard query (0)clients2.google.com65IN (0x0001)false
                Feb 21, 2024 21:21:15.409779072 CET192.168.2.51.1.1.10xa93cStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:15.411839008 CET192.168.2.51.1.1.10xf5abStandard query (0)accounts.google.com65IN (0x0001)false
                Feb 21, 2024 21:21:19.793323040 CET192.168.2.51.1.1.10x3b18Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:19.793754101 CET192.168.2.51.1.1.10x8c07Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Feb 21, 2024 21:21:15.496382952 CET1.1.1.1192.168.2.50x91e4No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 21:21:15.496382952 CET1.1.1.1192.168.2.50x91e4No error (0)clients.l.google.com142.250.80.14A (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:15.496592045 CET1.1.1.1192.168.2.50x94c9No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 21:21:15.497958899 CET1.1.1.1192.168.2.50xa93cNo error (0)accounts.google.com142.251.167.84A (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:19.881356001 CET1.1.1.1192.168.2.50x8c07No error (0)www.google.com65IN (0x0001)false
                Feb 21, 2024 21:21:19.881469011 CET1.1.1.1192.168.2.50x3b18No error (0)www.google.com142.251.40.196A (IP address)IN (0x0001)false
                Feb 21, 2024 21:21:30.727758884 CET1.1.1.1192.168.2.50x869aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 21:21:30.727758884 CET1.1.1.1192.168.2.50x869aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.549706142.250.80.144434416C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 20:21:15 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-117.0.5938.132
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-02-21 20:21:15 UTC732INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-ESkmA78Jxq0ZF_Ttudz73A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Feb 2024 20:21:15 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6260
                X-Daystart: 44475
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-21 20:21:15 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 36 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 34 34 37 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6260" elapsed_seconds="44475"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2024-02-21 20:21:15 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2024-02-21 20:21:15 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.549705142.251.167.844434416C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 20:21:15 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
                2024-02-21 20:21:15 UTC1OUTData Raw: 20
                Data Ascii:
                2024-02-21 20:21:16 UTC1798INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Feb 2024 20:21:16 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Content-Security-Policy: script-src 'report-sample' 'nonce-8b2VSqFbjsNS7JWompOCGQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Cross-Origin-Opener-Policy: same-origin
                reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQJiIW6OPdturmMT2LHqIAsAnwcXBA"
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-21 20:21:16 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2024-02-21 20:21:16 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.54971523.51.58.94443
                TimestampBytes transferredDirectionData
                2024-02-21 20:21:20 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-21 20:21:20 UTC494INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=83072
                Date: Wed, 21 Feb 2024 20:21:20 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.54971823.51.58.94443
                TimestampBytes transferredDirectionData
                2024-02-21 20:21:20 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-21 20:21:21 UTC455INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/0778)
                X-CID: 11
                Cache-Control: public, max-age=83107
                Date: Wed, 21 Feb 2024 20:21:21 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-02-21 20:21:21 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:21:21:12
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:21:21:14
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1932,i,1781409829972273078,7043298505215807192,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:21:21:16
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cddehakdhe32cnherf.blob.core.windows.net/cddehakdhe32cnherf/url.html
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly