Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
kxcihiul.html

Overview

General Information

Sample name:kxcihiul.html
(renamed file extension from aspx to html)
Original sample name:kxcihiul.aspx
Analysis ID:1411156
MD5:68cae420d4f0b5655c6cbd1becfe4d68
SHA1:cb78f5e61e284a2d16a40e7167be0a070a099ac1
SHA256:46e8d2bd84b9e7e3e1215ef309acda7a09b9d2885805f4e02e308a8372733fd1
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 5764 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\kxcihiul.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2852 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2016,i,7631876182672491712,1348624576867069447,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: kxcihiul.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/kxcihiul.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49752 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.121.39
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.121.39
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.121.39
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Xdr52YOfpxN5+wZ&MD=oo3vURkm HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Xdr52YOfpxN5+wZ&MD=oo3vURkm HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49752 version: TLS 1.2
Source: classification engineClassification label: clean1.winHTML@24/0@2/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\kxcihiul.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2016,i,7631876182672491712,1348624576867069447,262144 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2016,i,7631876182672491712,1348624576867069447,262144 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
file:///C:/Users/user/Desktop/kxcihiul.html0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.176.196
truefalse
    high
    NameMaliciousAntivirus DetectionReputation
    file:///C:/Users/user/Desktop/kxcihiul.htmlfalse
    • Avira URL Cloud: safe
    low
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    142.250.176.196
    www.google.comUnited States
    15169GOOGLEUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    IP
    192.168.2.4
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1411156
    Start date and time:2024-03-18 17:06:03 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 5m 12s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:defaultwindowshtmlcookbook.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:7
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:kxcihiul.html
    (renamed file extension from aspx to html)
    Original Sample Name:kxcihiul.aspx
    Detection:CLEAN
    Classification:clean1.winHTML@24/0@2/3
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.250.80.99, 142.251.41.14, 142.251.163.84, 34.104.35.123, 142.251.40.138, 142.251.40.170, 142.250.64.74, 142.250.65.170, 142.250.80.42, 142.250.80.74, 142.250.80.106, 142.251.40.234, 142.251.40.202, 142.250.65.202, 142.251.32.106, 142.251.41.10, 142.250.65.234, 142.250.81.234, 142.250.176.202, 142.250.72.106, 104.102.251.57, 104.102.251.17, 104.102.251.82, 104.102.251.89, 142.250.80.35, 104.102.251.73, 104.102.251.80, 142.250.65.174, 23.206.121.48, 23.206.121.13, 23.206.121.50, 23.206.121.21, 23.206.121.31, 23.206.121.18, 23.206.121.46, 23.206.121.52, 23.206.121.8, 23.206.121.53, 23.206.121.38, 72.21.81.240
    • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, clients2.google.com, edgedl.me.gvt1.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, update.googleapis.com, hlb.apr-52dd2-0.edgecastdns.net, clients.l.google.com, optimizationguide-pa.googleapis.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    • VT rate limit hit for: kxcihiul.html
    No simulations
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    239.255.255.250https://officeonline-sharepoint.powerappsportals.com/Get hashmaliciousHtmlDropper, HTMLPhisherBrowse
      https://cloudflare-ipfs.com/ipfs/bafkreif2klim7glbgcsrfe6lm7wfd2scwmhee5i6dglyggzgvjgl53zw2i/#anJzQGFwYWNvbnN1bHRpbmcubmV0Get hashmaliciousUnknownBrowse
        http://officeonline-sharepoint.powerappsportals.comGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
          Quarantined Messages (4).zipGet hashmaliciousHTMLPhisherBrowse
            https://upd.autopoisk.su/files/Autopoisk-1.0.0.12.zipGet hashmaliciousUnknownBrowse
              https://marvin-occentus.net/statistic/js/stat.jsGet hashmaliciousUnknownBrowse
                advice.htmlGet hashmaliciousUnknownBrowse
                  https://iughgre5re87.s3.amazonaws.com/teteght.htmlGet hashmaliciousUnknownBrowse
                    https://vghpsimdplmwc.s3.amazonaws.com/vghpsimdplmwc.html#4FRnVP6868zmfR493tnmwllyusk1585HHMTITXPKQQDUGQ18091/733104C21#c1p42w46m4kwzliliqghbluf3ezx6gf7ur7w1piqq0gw35fwp51s1ixGet hashmaliciousPhisherBrowse
                      https://pxrj.adj.st/subscriptions?plansJson=ewogICJpb3MiOiB7CiAgICAiZGUscHQsaGUsaXQsZnIsYXIsZW4semgsa28samEsanAsZXMsbmwsZmksc3Ysbm8sZGEsZWwiOiB7CiAgICAgICJpZCI6ICJlZHVjYXRpb25fMjQwMV90aWVyMSIsCiAgICAgICJwbGFuIjogImNvbS5ld2EucmVuZXdhYmxlLnN1YnNjcmlwdGlvbi55ZWFyXzUwX2VtYWlsIiwKICAgICAgInZhbGlkaXR5RHVyYXRpb24iOiAzNjAwLAogICAgICAiZGlzY291bnQiOiA1MAogICAgfSwKICAgICJkZWZhdWx0IjogewogICAgICAiaWQiOiAiZWR1Y2F0aW9uXzI0MDFfdGllcjIiLAogICAgICAicGxhbiI6ICJjb20uZXdhLnJlbmV3YWJsZS5zdWJzY3JpcHRpb24ueWVhcl8yNV9lbWFpbCIsCiAgICAgICJ2YWxpZGl0eUR1cmF0aW9uIjogMzYwMCwKICAgICAgImRpc2NvdW50IjogNTAKICAgIH0KICB9LAogICJhbmRyb2lkIjogewogICAgImRlZmF1bHQiOiB7CiAgICAgICJpZCI6ICJlZHVjYXRpb25fMjQwMV90ZXN0IiwKICAgICAgInBsYW4iOiAic3Vic2NyaWJlLmZ1bGxfeWVhcjE3X2VtYWlsIiwKICAgICAgInZhbGlkaXR5RHVyYXRpb24iOiAzNjAwLAogICAgICAiZGlzY291bnQiOiA1MAogICAgfQogIH0sCiAgInN0eWxlIjogImRpc2NvdW50X3BvcHVwIiwKICAic3R5bGVfc2V0dGluZ3MiOiB7CiAgICAiYmdfY29sb3IiOiAiIzAwRDU3OCIsCiAgICAiYmciOiAiaHR0cHM6Ly9zdG9yYWdlLmFwcGV3YS5jb20vYXBpL3YxL2ZpbGVzL2QxNjU2YTc5LTFkNDEtNDcwZC1hZWFlLTBkNDNjYzgxYjQ2NiIsCiAgICAiYmdfaXBhZCI6ICJodHRwczovL3N0b3JhZ2UuYXBwZXdhLmNvbS9hcGkvdjEvZmlsZXMvNTFkZGFjM2ItYTVkNS00NWMxLWFlZWMtYTM4MDQ4MzExNTBlIiwKICAgICJmcm9udCI6ICJodHRwczovL3N0b3JhZ2UuYXBwZXdhLmNvbS9hcGkvdjEvZmlsZXMvY2E0MzQyNTItYTk2Ny00MjFiLWJlMWItYmQwNDg4YzQ1NWM5IiwKICAgICJmcm9udF9pcGFkIjogImh0dHBzOi8vc3RvcmFnZS5hcHBld2EuY29tL2FwaS92MS9maWxlcy84YmM5YzNiNC02NDMyLTQzOTktOTVmMi1hNjM2N2JkMmE2NWMiLAogICAgInNraXAiOiAiI0ZGRkZGRiIsCiAgICAidGl0bGUiOiAiI0ZGRkZGRiIsCiAgICAidGV4dCI6ICIjRkZGRkZGIiwKICAgICJidXlfdGV4dCI6ICIjNDcxRTZEIiwKICAgICJidXlfc3RhcnQiOiAiI0ZFREU1QyIsCiAgICAiYnV5X2VuZCI6ICIjRkVERTVDIgogIH0KfQ==&adj_t=6m6i49o&adj_fallback=https%3A%2F%2F//abundantlifetabernaclebx.org#JTNDbWV0YSUyMGh0dHAtZXF1aXYlM0QlMjJyZWZyZXNoJTIyJTIwY29udGVudCUzRCUyMjAlM0IlMjB1cmwlM0RodHRwcyUzQS8vYWxtb3N0YWZhY2xlYW4uY29tLzElMjNsaHVtbWVsQGJjaWZpbmFuY2lhbC5jb20lMjIlMjAvJTNFGet hashmaliciousUnknownBrowse
                        No context
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        28a2c9bd18a11de089ef85a160da29e4https://officeonline-sharepoint.powerappsportals.com/Get hashmaliciousHtmlDropper, HTMLPhisherBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        Eneans3varlig.vbsGet hashmaliciousGuLoader, XWormBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        https://cloudflare-ipfs.com/ipfs/bafkreif2klim7glbgcsrfe6lm7wfd2scwmhee5i6dglyggzgvjgl53zw2i/#anJzQGFwYWNvbnN1bHRpbmcubmV0Get hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        http://officeonline-sharepoint.powerappsportals.comGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        https://upd.autopoisk.su/files/Autopoisk-1.0.0.12.zipGet hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        https://marvin-occentus.net/statistic/js/stat.jsGet hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        advice.htmlGet hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        https://iughgre5re87.s3.amazonaws.com/teteght.htmlGet hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        https://pxrj.adj.st/subscriptions?plansJson=ewogICJpb3MiOiB7CiAgICAiZGUscHQsaGUsaXQsZnIsYXIsZW4semgsa28samEsanAsZXMsbmwsZmksc3Ysbm8sZGEsZWwiOiB7CiAgICAgICJpZCI6ICJlZHVjYXRpb25fMjQwMV90aWVyMSIsCiAgICAgICJwbGFuIjogImNvbS5ld2EucmVuZXdhYmxlLnN1YnNjcmlwdGlvbi55ZWFyXzUwX2VtYWlsIiwKICAgICAgInZhbGlkaXR5RHVyYXRpb24iOiAzNjAwLAogICAgICAiZGlzY291bnQiOiA1MAogICAgfSwKICAgICJkZWZhdWx0IjogewogICAgICAiaWQiOiAiZWR1Y2F0aW9uXzI0MDFfdGllcjIiLAogICAgICAicGxhbiI6ICJjb20uZXdhLnJlbmV3YWJsZS5zdWJzY3JpcHRpb24ueWVhcl8yNV9lbWFpbCIsCiAgICAgICJ2YWxpZGl0eUR1cmF0aW9uIjogMzYwMCwKICAgICAgImRpc2NvdW50IjogNTAKICAgIH0KICB9LAogICJhbmRyb2lkIjogewogICAgImRlZmF1bHQiOiB7CiAgICAgICJpZCI6ICJlZHVjYXRpb25fMjQwMV90ZXN0IiwKICAgICAgInBsYW4iOiAic3Vic2NyaWJlLmZ1bGxfeWVhcjE3X2VtYWlsIiwKICAgICAgInZhbGlkaXR5RHVyYXRpb24iOiAzNjAwLAogICAgICAiZGlzY291bnQiOiA1MAogICAgfQogIH0sCiAgInN0eWxlIjogImRpc2NvdW50X3BvcHVwIiwKICAic3R5bGVfc2V0dGluZ3MiOiB7CiAgICAiYmdfY29sb3IiOiAiIzAwRDU3OCIsCiAgICAiYmciOiAiaHR0cHM6Ly9zdG9yYWdlLmFwcGV3YS5jb20vYXBpL3YxL2ZpbGVzL2QxNjU2YTc5LTFkNDEtNDcwZC1hZWFlLTBkNDNjYzgxYjQ2NiIsCiAgICAiYmdfaXBhZCI6ICJodHRwczovL3N0b3JhZ2UuYXBwZXdhLmNvbS9hcGkvdjEvZmlsZXMvNTFkZGFjM2ItYTVkNS00NWMxLWFlZWMtYTM4MDQ4MzExNTBlIiwKICAgICJmcm9udCI6ICJodHRwczovL3N0b3JhZ2UuYXBwZXdhLmNvbS9hcGkvdjEvZmlsZXMvY2E0MzQyNTItYTk2Ny00MjFiLWJlMWItYmQwNDg4YzQ1NWM5IiwKICAgICJmcm9udF9pcGFkIjogImh0dHBzOi8vc3RvcmFnZS5hcHBld2EuY29tL2FwaS92MS9maWxlcy84YmM5YzNiNC02NDMyLTQzOTktOTVmMi1hNjM2N2JkMmE2NWMiLAogICAgInNraXAiOiAiI0ZGRkZGRiIsCiAgICAidGl0bGUiOiAiI0ZGRkZGRiIsCiAgICAidGV4dCI6ICIjRkZGRkZGIiwKICAgICJidXlfdGV4dCI6ICIjNDcxRTZEIiwKICAgICJidXlfc3RhcnQiOiAiI0ZFREU1QyIsCiAgICAiYnV5X2VuZCI6ICIjRkVERTVDIgogIH0KfQ==&adj_t=6m6i49o&adj_fallback=https%3A%2F%2F//abundantlifetabernaclebx.org#JTNDbWV0YSUyMGh0dHAtZXF1aXYlM0QlMjJyZWZyZXNoJTIyJTIwY29udGVudCUzRCUyMjAlM0IlMjB1cmwlM0RodHRwcyUzQS8vYWxtb3N0YWZhY2xlYW4uY29tLzElMjNsaHVtbWVsQGJjaWZpbmFuY2lhbC5jb20lMjIlMjAvJTNFGet hashmaliciousUnknownBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        ART#U00cdCULOS IPAR-YATCHS EN LA LISTA DE ORDEN DE COMPRA ADJUNTA..vbsGet hashmaliciousAgentTesla, GuLoaderBrowse
                        • 23.54.68.82
                        • 20.12.23.50
                        No context
                        No created / dropped files found
                        File type:HTML document, ASCII text, with CRLF line terminators
                        Entropy (8bit):2.383964802619259
                        TrID:
                        • HyperText Markup Language (12001/1) 51.06%
                        • HyperText Markup Language (11501/1) 48.94%
                        File name:kxcihiul.html
                        File size:4'958 bytes
                        MD5:68cae420d4f0b5655c6cbd1becfe4d68
                        SHA1:cb78f5e61e284a2d16a40e7167be0a070a099ac1
                        SHA256:46e8d2bd84b9e7e3e1215ef309acda7a09b9d2885805f4e02e308a8372733fd1
                        SHA512:08aa491afb6e46a7a0b743f212b784844ae5c7228da8ebdc242d8892556dc2d352f5c7fbc34b64e9fbab59a63620f5f7f94aa3b4f48278247962e4deec301f76
                        SSDEEP:48:8LLhBi31Vol5mAruWhWDl8vSvTHFdmaax:ELCy5VuIs8GTHLmaax
                        TLSH:C0A1E0498CFB7C48C0B31334ABD19115D3222163514B8D78B6EC9E442F7D67D8E29776
                        File Content Preview:<% @ Page Language="C#" %> ..<% @ Import Namespace="System.IO" %> ..<!DOCTYPE html> ....<html xmln
                        TimestampSource PortDest PortSource IPDest IP
                        Mar 18, 2024 17:07:07.851537943 CET49675443192.168.2.4173.222.162.32
                        Mar 18, 2024 17:07:13.064807892 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.064843893 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.064948082 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.065460920 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.065478086 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.263480902 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.264354944 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.264379978 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.265461922 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.265552044 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.267819881 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.267885923 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.319205046 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.319214106 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:13.366080046 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:13.674303055 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.674340963 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:13.674412012 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.679410934 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.679426908 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:13.868469954 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:13.868551016 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.879043102 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.879057884 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:13.879307032 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:13.928642035 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:13.964838028 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.012229919 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.074249983 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.074305058 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.074465036 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.074505091 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.074517965 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.074517965 CET49742443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.074526072 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.074532986 CET4434974223.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.106758118 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.106796026 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.106863976 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.107309103 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.107321978 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.289832115 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.289905071 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.314110994 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.314141035 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.314342976 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.316837072 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.364239931 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.468194962 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.468250990 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:14.468311071 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.472219944 CET49743443192.168.2.423.54.68.82
                        Mar 18, 2024 17:07:14.472239971 CET4434974323.54.68.82192.168.2.4
                        Mar 18, 2024 17:07:23.265542984 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:23.265615940 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:23.265703917 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:23.868773937 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:23.868824005 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:23.868900061 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:23.872756004 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:23.872780085 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.184746027 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.184835911 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.191349983 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.191371918 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.191720009 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.237741947 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.451502085 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.496242046 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650000095 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650024891 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650032997 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650044918 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650069952 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650084972 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.650105000 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650121927 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.650151014 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.650396109 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650441885 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.650449991 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650484085 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.650573969 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.710804939 CET49745443192.168.2.420.12.23.50
                        Mar 18, 2024 17:07:24.710838079 CET4434974520.12.23.50192.168.2.4
                        Mar 18, 2024 17:07:24.730392933 CET49741443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:07:24.730427027 CET44349741142.250.176.196192.168.2.4
                        Mar 18, 2024 17:07:56.758960009 CET4973180192.168.2.423.206.121.39
                        Mar 18, 2024 17:07:56.847650051 CET804973123.206.121.39192.168.2.4
                        Mar 18, 2024 17:07:56.847706079 CET4973180192.168.2.423.206.121.39
                        Mar 18, 2024 17:08:01.201289892 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.201320887 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.201387882 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.202037096 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.202049971 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.523363113 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.523437023 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.526918888 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.526927948 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.527261972 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.539932013 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.584224939 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.816267014 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.816289902 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.816318989 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.816406012 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.816406012 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.816417933 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.816791058 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.817071915 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.817104101 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.817141056 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.817151070 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.817158937 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.817214966 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.825407982 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.825407982 CET49752443192.168.2.420.12.23.50
                        Mar 18, 2024 17:08:01.825423002 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:01.825434923 CET4434975220.12.23.50192.168.2.4
                        Mar 18, 2024 17:08:04.397793055 CET4973280192.168.2.4192.229.211.108
                        Mar 18, 2024 17:08:04.398010969 CET4973380192.168.2.423.206.121.39
                        Mar 18, 2024 17:08:04.488853931 CET8049732192.229.211.108192.168.2.4
                        Mar 18, 2024 17:08:04.489136934 CET4973280192.168.2.4192.229.211.108
                        Mar 18, 2024 17:08:04.489978075 CET804973323.206.121.39192.168.2.4
                        Mar 18, 2024 17:08:04.490415096 CET4973380192.168.2.423.206.121.39
                        Mar 18, 2024 17:08:13.026365995 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:13.026408911 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.026504993 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:13.027242899 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:13.027254105 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.218035936 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.222512007 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:13.222531080 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.223107100 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.223809958 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:13.223902941 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:13.272576094 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:23.215147972 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:23.215312004 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:23.215377092 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:25.302144051 CET49754443192.168.2.4142.250.176.196
                        Mar 18, 2024 17:08:25.302176952 CET44349754142.250.176.196192.168.2.4
                        Mar 18, 2024 17:08:56.201148033 CET44349729173.222.162.32192.168.2.4
                        Mar 18, 2024 17:08:56.201173067 CET44349729173.222.162.32192.168.2.4
                        Mar 18, 2024 17:08:56.201272011 CET49729443192.168.2.4173.222.162.32
                        Mar 18, 2024 17:08:56.201272011 CET49729443192.168.2.4173.222.162.32
                        Mar 18, 2024 17:09:55.960454941 CET8049730192.229.211.108192.168.2.4
                        Mar 18, 2024 17:09:55.960612059 CET4973080192.168.2.4192.229.211.108
                        TimestampSource PortDest PortSource IPDest IP
                        Mar 18, 2024 17:07:08.867676020 CET53571771.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:08.875756025 CET53618201.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:09.427109003 CET53522681.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:12.974044085 CET5240453192.168.2.41.1.1.1
                        Mar 18, 2024 17:07:12.974529982 CET6099053192.168.2.41.1.1.1
                        Mar 18, 2024 17:07:13.061945915 CET53524041.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:13.062582970 CET53609901.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:15.911673069 CET138138192.168.2.4192.168.2.255
                        Mar 18, 2024 17:07:21.068239927 CET53619541.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:26.514390945 CET53579511.1.1.1192.168.2.4
                        Mar 18, 2024 17:07:45.425190926 CET53630261.1.1.1192.168.2.4
                        Mar 18, 2024 17:08:08.296298981 CET53501621.1.1.1192.168.2.4
                        Mar 18, 2024 17:08:08.336966038 CET53632061.1.1.1192.168.2.4
                        Mar 18, 2024 17:08:36.175921917 CET53628021.1.1.1192.168.2.4
                        Mar 18, 2024 17:09:23.165478945 CET53606111.1.1.1192.168.2.4
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Mar 18, 2024 17:07:12.974044085 CET192.168.2.41.1.1.10xbaStandard query (0)www.google.comA (IP address)IN (0x0001)false
                        Mar 18, 2024 17:07:12.974529982 CET192.168.2.41.1.1.10x120Standard query (0)www.google.com65IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Mar 18, 2024 17:07:13.061945915 CET1.1.1.1192.168.2.40xbaNo error (0)www.google.com142.250.176.196A (IP address)IN (0x0001)false
                        Mar 18, 2024 17:07:13.062582970 CET1.1.1.1192.168.2.40x120No error (0)www.google.com65IN (0x0001)false
                        • fs.microsoft.com
                        • slscr.update.microsoft.com
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.44974223.54.68.82443
                        TimestampBytes transferredDirectionData
                        2024-03-18 16:07:13 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-03-18 16:07:14 UTC496INHTTP/1.1 200 OK
                        ApiVersion: Distribute 1.1
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (chd/073D)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-eus2-z1
                        Cache-Control: public, max-age=184694
                        Date: Mon, 18 Mar 2024 16:07:14 GMT
                        Connection: close
                        X-CID: 2


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.44974323.54.68.82443
                        TimestampBytes transferredDirectionData
                        2024-03-18 16:07:14 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                        Range: bytes=0-2147483646
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-03-18 16:07:14 UTC531INHTTP/1.1 200 OK
                        Content-Type: application/octet-stream
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        ApiVersion: Distribute 1.1
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                        Cache-Control: public, max-age=184700
                        Date: Mon, 18 Mar 2024 16:07:14 GMT
                        Content-Length: 55
                        Connection: close
                        X-CID: 2
                        2024-03-18 16:07:14 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        2192.168.2.44974520.12.23.50443
                        TimestampBytes transferredDirectionData
                        2024-03-18 16:07:24 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Xdr52YOfpxN5+wZ&MD=oo3vURkm HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                        Host: slscr.update.microsoft.com
                        2024-03-18 16:07:24 UTC560INHTTP/1.1 200 OK
                        Cache-Control: no-cache
                        Pragma: no-cache
                        Content-Type: application/octet-stream
                        Expires: -1
                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                        ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                        MS-CorrelationId: a46bbde6-eeab-4dbf-98fd-0fcde57b4534
                        MS-RequestId: 73fed5d1-425f-4eb4-a3a9-cb1d57d0fdc5
                        MS-CV: JJ/C3u1zWEqY3Byr.0
                        X-Microsoft-SLSClientCache: 2880
                        Content-Disposition: attachment; filename=environment.cab
                        X-Content-Type-Options: nosniff
                        Date: Mon, 18 Mar 2024 16:07:23 GMT
                        Connection: close
                        Content-Length: 24490
                        2024-03-18 16:07:24 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                        Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                        2024-03-18 16:07:24 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                        Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        3192.168.2.44975220.12.23.50443
                        TimestampBytes transferredDirectionData
                        2024-03-18 16:08:01 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Xdr52YOfpxN5+wZ&MD=oo3vURkm HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                        Host: slscr.update.microsoft.com
                        2024-03-18 16:08:01 UTC560INHTTP/1.1 200 OK
                        Cache-Control: no-cache
                        Pragma: no-cache
                        Content-Type: application/octet-stream
                        Expires: -1
                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                        ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
                        MS-CorrelationId: 803ed320-a413-43ff-9928-ecd76d936e31
                        MS-RequestId: 756f1684-1af1-448a-b8c4-195537009ede
                        MS-CV: bolYXDdRr02oc3Pa.0
                        X-Microsoft-SLSClientCache: 2160
                        Content-Disposition: attachment; filename=environment.cab
                        X-Content-Type-Options: nosniff
                        Date: Mon, 18 Mar 2024 16:08:00 GMT
                        Connection: close
                        Content-Length: 25457
                        2024-03-18 16:08:01 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
                        Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
                        2024-03-18 16:08:01 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
                        Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:17:07:04
                        Start date:18/03/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\kxcihiul.html
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:2
                        Start time:17:07:06
                        Start date:18/03/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2016,i,7631876182672491712,1348624576867069447,262144 /prefetch:8
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        No disassembly