Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisc

Overview

General Information

Sample URL:HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consu
Analysis ID:1417177
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6400 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2408 --field-trial-handle=2368,i,17427900061271599603,4557120256687689452,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49724 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49724 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369 HTTP/1.1Host: ta.trs.cnConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ta.trs.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _trs_gv=g_lubf7tjh_5062_2crz
Source: unknownDNS traffic detected: queries for: ta.trs.cn
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1711645592757&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 17:06:49 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: keep-aliveServer: nginx/1.22.0Vary: Accept-EncodingContent-Encoding: gzipData Raw: 61 65 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 8e 41 0a c2 30 10 45 f7 82 77 18 0f 90 a6 2d 5d 0e d9 88 05 17 ba f1 04 a9 33 36 81 34 91 18 c1 de de 54 5b 10 d7 2e 5d 0d f3 e7 fd c7 a0 49 83 53 eb 15 1a d6 a4 30 d9 e4 58 35 65 03 c7 90 a0 0d 77 4f 28 df 21 ca 17 92 d1 2e d0 38 cd 33 fb c4 51 a1 a9 be 1b 39 41 39 9f 27 77 86 e6 cd f7 d6 3f 64 55 d4 75 51 7e 22 72 91 ca e5 a1 8d 10 a0 e1 aa 89 ac ef 21 05 20 7b d3 9d 63 38 9c f6 3b d0 9e 60 6b 62 18 18 2e d1 b2 27 37 02 c7 18 62 6e f4 0c 42 fc 15 bf 56 3c 01 7f 9c d3 6f 2b 02 00 00 0d 0a Data Ascii: aeA0Ew-]364T[.]IS0X5ewO(!.83Q9A9'w?dUuQ~"r! {c8;`kb.'7bnBV<o+
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/8@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2408 --field-trial-handle=2368,i,17427900061271599603,4557120256687689452,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2408 --field-trial-handle=2368,i,17427900061271599603,4557120256687689452,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=3690%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ta.trs.cn/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
ta.trs.cn
120.53.131.129
truefalse
    unknown
    www.google.com
    142.250.31.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369false
          unknown
          http://ta.trs.cn/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.31.105
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          120.53.131.129
          ta.trs.cnChina
          45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
          IP
          192.168.2.5
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1417177
          Start date and time:2024-03-28 18:05:59 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 1s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean1.win@16/8@4/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.163.94, 172.253.115.101, 172.253.115.113, 172.253.115.139, 172.253.115.100, 172.253.115.138, 172.253.115.102, 172.253.122.84, 34.104.35.123, 20.12.23.50, 69.164.0.0, 23.207.202.8, 23.207.202.20, 23.207.202.34, 23.207.202.24, 23.207.202.16, 23.207.202.15, 23.207.202.31, 23.207.202.12, 23.207.202.13, 192.229.211.108, 13.85.23.206, 20.3.187.198, 142.251.167.94, 104.97.85.11, 104.97.85.34, 104.97.85.50, 104.97.85.54, 104.97.85.32, 104.97.85.10
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 16:06:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9827358851470116
          Encrypted:false
          SSDEEP:48:8G3dNTVt/WHi0idAKZdA19ehwiZUklqehNy+3:8W/mKy
          MD5:FBE1303D31D1CD62F89F4A0781CBD94A
          SHA1:73FF79F8AAACFF229F29B2CA178C4539EB0D12CD
          SHA-256:5C09981F1E3D80E61EC5E9180DC30FF7598B6C74A23D5843E8E0B5B2E4141D0D
          SHA-512:6390CDCA44CCF1D2DDBE93C82360B508F4D3318FB32FAFBBA26C5B2C52DBDC467997FCAD70D63086582A6E74EA25914C34882E3DE8DA2FB5D74B8A3CC56962E4
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....GnR2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 16:06:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):4.000624172240693
          Encrypted:false
          SSDEEP:48:8Hx3dNTVt/WHi0idAKZdA1weh/iZUkAQkqeh6y+2:8H5/k9Q/y
          MD5:A46A46B361DB945056E045E0A0A13167
          SHA1:CEF4A5490F8862ED301B203060020F913746DC76
          SHA-256:190BF36D19B5291D99515C11236A1E4327EC44082B99ECC19440C738ACBC7139
          SHA-512:BBE91997CC088138A4707FAB8B43F46E6108AD260E4F89F635557FE38BF436CD959F5275E6C423715042BC15D305F11C6A2ED033FEC01297F1A20925AF278DD6
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....]bR2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2693
          Entropy (8bit):4.01226765046531
          Encrypted:false
          SSDEEP:48:8xGdNTVtsHi0idAKZdA14tseh7sFiZUkmgqeh7s8y+BX:8x8/Gn2y
          MD5:F9FF69096C7F99E64157BC3BFF3D44AE
          SHA1:60FD0568A53609153C5973AA6F9927EFA0573CB4
          SHA-256:3E6796A75DEAE2E9DE3C20E5917B47AF0EA3D674493AE38D317F836A390958E7
          SHA-512:785CA665DF8A6780E27B414E107CE5F75D3755C238FA8C4C6270F898285323FE07F6FC5FEF4B47BC99A46AEF42036416D9825513F3089CAC9F2FEE25295953AA
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 16:06:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):4.000036194685267
          Encrypted:false
          SSDEEP:48:823dNTVt/WHi0idAKZdA1vehDiZUkwqehOy+R:8m/v0y
          MD5:C8E8EE15EE54E2B8CF423625C6585FA5
          SHA1:002900ADEE238327C47DC9E61DB57BECBF70F5FB
          SHA-256:D97E4F49528783573518075AA14B85F61C39B4DE3B7AF8F62209DE2F37C60137
          SHA-512:8A4579A2828C3B6570AAF5199472DBD765F913A10CDED1EAB4A7804326CFC44D2C505A3D3509451273E6B1806680D764359378E6E4DD29C31C9C0F5B5676B104
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....N[R2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 16:06:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.9866986356916234
          Encrypted:false
          SSDEEP:48:8N3dNTVt/WHi0idAKZdA1hehBiZUk1W1qehYy+C:81/P94y
          MD5:642530679CEED737DC7351CDE2B33A16
          SHA1:4CE792FC9AA952EF57C965418964003DF541C6B1
          SHA-256:33FDBEF570F6FFC2FCB1A8891781CCE8F5D8CA3E42477C9ADD4412A5E3978D92
          SHA-512:9754FD569DC12BAC5AF5636A876810D659B7A1710B437AFDB245227437B5ECF6C9B1DCC26F1B412783DFC6F3866F4B9B2CADBACB4865D937F22C7FAC7DE876B9
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......hR2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 16:06:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2683
          Entropy (8bit):3.9956354502141034
          Encrypted:false
          SSDEEP:48:8i3dNTVt/WHi0idAKZdA1duT+ehOuTbbiZUk5OjqehOuTb2y+yT+:8S/HT/TbxWOvTb2y7T
          MD5:93CED63B77521EA4517768BF4B27ED0C
          SHA1:E76A552A6B9579F0EF4978D14E48A024531E3294
          SHA-256:FBBEE2EE6BA94562B15BD8B2F379060B091253890357AD08BF44908E4DEBB2F8
          SHA-512:9481E573FDE3B91401A802CEF1A7D6191F52D1EDF28105FAED56CF1D7D8A205F1B6BE1FB5C1C386031D7979B721B293B8FFEECBE555109517C132AFED45FF475
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....4oPR2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........O.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, original size modulo 2^32 555
          Category:downloaded
          Size (bytes):174
          Entropy (8bit):6.756828105128866
          Encrypted:false
          SSDEEP:3:FttNkvfXn4gTkS9k5KyL4oFsAraeMaT0S2B50jkvADFmsJKLe24K5j0XURPnZvV4:XtNK4WkOkHMB75w0S2EDF4LWbUZz4ll
          MD5:20C0810FEE7D342C0041ED5475F7B725
          SHA1:3BC10ED11C792AACBAA09F2CB97BA3DE685E6D78
          SHA-256:6F18FD4755BBABAA498203ABDE0FC7CFCE92812F69267FCDD2EC3CB598E9D4E2
          SHA-512:99EBBF24269BBFB749F06300A8956CE352A7CF1BE0A6F99E0D8AA7833D309449B14C9ECA3ED6D2ABAB77496F453FB412E05287A96C6F79B55A188C4603428EA8
          Malicious:false
          Reputation:low
          URL:http://ta.trs.cn/favicon.ico
          Preview:...........A..0.E..w....-]........36.4.....T[...].....I.S....0..X5e....wO(.!......8.3..Q....9A9.'w.....?dU.uQ~"r........!. {.c8..;.`kb....'7...bn..B...V<....o+...
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 18:06:42.547086000 CET49674443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:42.547110081 CET49675443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:42.640837908 CET49673443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:48.876558065 CET4971080192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:48.876869917 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.015160084 CET4971280192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.178220034 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.178395033 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.178617954 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.180459023 CET8049710120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.180516958 CET4971080192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.323307991 CET8049712120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.323395967 CET4971280192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.480525017 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.484448910 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.484462976 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.484536886 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.581828117 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:49.885029078 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.888766050 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.888780117 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:06:49.888967991 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:06:50.998101950 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:50.998123884 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:50.998182058 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:50.999083042 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:50.999092102 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.217906952 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.221522093 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:51.221538067 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.222479105 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.222547054 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:51.224977016 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:51.225035906 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.275090933 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:51.275103092 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:06:51.326751947 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:06:52.134566069 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.134603977 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.134686947 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.137567043 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.137583971 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.154916048 CET49675443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:52.154934883 CET49674443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:52.248663902 CET49673443192.168.2.523.1.237.91
          Mar 28, 2024 18:06:52.485064983 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.485232115 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.489046097 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.489057064 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.489279985 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.529863119 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.552860975 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.600229025 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.818306923 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.818389893 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.818435907 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.855443001 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.855468035 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.855480909 CET49717443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.855487108 CET4434971723.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.918606043 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.918648005 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:52.918710947 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.919605017 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:52.919621944 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.265239000 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.265337944 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:53.266885996 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:53.266894102 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.267121077 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.268310070 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:53.316239119 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.620754957 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.620809078 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.620876074 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:53.631134987 CET49718443192.168.2.523.209.58.93
          Mar 28, 2024 18:06:53.631161928 CET4434971823.209.58.93192.168.2.5
          Mar 28, 2024 18:06:53.636311054 CET4434970323.1.237.91192.168.2.5
          Mar 28, 2024 18:06:53.636388063 CET49703443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:01.223151922 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:01.223202944 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:01.223254919 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:01.723769903 CET49716443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:01.723789930 CET44349716142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:04.110688925 CET49703443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.110865116 CET49703443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.112066031 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.112131119 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.112210035 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.113881111 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.113892078 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.268486977 CET4434970323.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.268558025 CET4434970323.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.439654112 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.439718962 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.464108944 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.464123964 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.464462996 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.464560032 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.465296984 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.465326071 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.465718985 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.465725899 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.822870970 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.822926998 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.823488951 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.823538065 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.823551893 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.823595047 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.843311071 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.843336105 CET4434972423.1.237.91192.168.2.5
          Mar 28, 2024 18:07:04.843349934 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:04.843390942 CET49724443192.168.2.523.1.237.91
          Mar 28, 2024 18:07:34.186132908 CET4971080192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:34.326771975 CET4971280192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:34.492768049 CET8049710120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:34.636145115 CET8049712120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:34.889691114 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:35.195561886 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:49.484982014 CET8049710120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:49.485088110 CET4971080192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:49.627671003 CET8049712120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:49.627742052 CET4971280192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:49.720194101 CET4971280192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:49.720241070 CET4971080192.168.2.5120.53.131.129
          Mar 28, 2024 18:07:50.027782917 CET8049712120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:50.029165030 CET8049710120.53.131.129192.168.2.5
          Mar 28, 2024 18:07:50.948921919 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:50.948957920 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:50.953214884 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:50.953352928 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:50.953367949 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:51.158886909 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:51.160933018 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:51.160948992 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:51.161262035 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:51.164973021 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:07:51.165034056 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:07:51.216839075 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:08:01.158240080 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:08:01.158294916 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:08:01.161889076 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:08:01.717267990 CET49728443192.168.2.5142.250.31.105
          Mar 28, 2024 18:08:01.717308044 CET44349728142.250.31.105192.168.2.5
          Mar 28, 2024 18:08:04.889194012 CET8049711120.53.131.129192.168.2.5
          Mar 28, 2024 18:08:04.889712095 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:08:05.713699102 CET4971180192.168.2.5120.53.131.129
          Mar 28, 2024 18:08:06.020306110 CET8049711120.53.131.129192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 18:06:48.021121025 CET53550011.1.1.1192.168.2.5
          Mar 28, 2024 18:06:48.751092911 CET5650253192.168.2.51.1.1.1
          Mar 28, 2024 18:06:48.751149893 CET5411653192.168.2.51.1.1.1
          Mar 28, 2024 18:06:48.847155094 CET53565021.1.1.1192.168.2.5
          Mar 28, 2024 18:06:50.623914003 CET53541161.1.1.1192.168.2.5
          Mar 28, 2024 18:06:50.898813963 CET5914753192.168.2.51.1.1.1
          Mar 28, 2024 18:06:50.899425030 CET5641053192.168.2.51.1.1.1
          Mar 28, 2024 18:06:50.995338917 CET53591471.1.1.1192.168.2.5
          Mar 28, 2024 18:06:50.995359898 CET53564101.1.1.1192.168.2.5
          Mar 28, 2024 18:07:05.830224037 CET53527311.1.1.1192.168.2.5
          Mar 28, 2024 18:07:24.801074028 CET53545011.1.1.1192.168.2.5
          Mar 28, 2024 18:07:46.783370018 CET53629931.1.1.1192.168.2.5
          Mar 28, 2024 18:07:47.111270905 CET53624251.1.1.1192.168.2.5
          Mar 28, 2024 18:08:14.736200094 CET53540121.1.1.1192.168.2.5
          TimestampSource IPDest IPChecksumCodeType
          Mar 28, 2024 18:06:50.623969078 CET192.168.2.51.1.1.1c216(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 28, 2024 18:06:48.751092911 CET192.168.2.51.1.1.10xefafStandard query (0)ta.trs.cnA (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:48.751149893 CET192.168.2.51.1.1.10x6b64Standard query (0)ta.trs.cn65IN (0x0001)false
          Mar 28, 2024 18:06:50.898813963 CET192.168.2.51.1.1.10xe316Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.899425030 CET192.168.2.51.1.1.10x391Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 28, 2024 18:06:48.847155094 CET1.1.1.1192.168.2.50xefafNo error (0)ta.trs.cn120.53.131.129A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.105A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.106A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.99A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.103A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.147A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995338917 CET1.1.1.1192.168.2.50xe316No error (0)www.google.com142.250.31.104A (IP address)IN (0x0001)false
          Mar 28, 2024 18:06:50.995359898 CET1.1.1.1192.168.2.50x391No error (0)www.google.com65IN (0x0001)false
          Mar 28, 2024 18:07:03.733457088 CET1.1.1.1192.168.2.50x341dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 18:07:03.733457088 CET1.1.1.1192.168.2.50x341dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 18:07:16.673353910 CET1.1.1.1192.168.2.50x374bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 18:07:16.673353910 CET1.1.1.1192.168.2.50x374bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 18:07:39.876836061 CET1.1.1.1192.168.2.50x5d59No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 18:07:39.876836061 CET1.1.1.1192.168.2.50x5d59No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Mar 28, 2024 18:07:59.871788979 CET1.1.1.1192.168.2.50xe575No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 18:07:59.871788979 CET1.1.1.1192.168.2.50xe575No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • https:
            • www.bing.com
          • ta.trs.cn
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.549711120.53.131.129802180C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 18:06:49.178617954 CET859OUTGET /c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369 HTTP/1.1
          Host: ta.trs.cn
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Mar 28, 2024 18:06:49.484448910 CET560INHTTP/1.1 200
          Date: Thu, 28 Mar 2024 17:06:49 GMT
          Content-Type: image/gif;charset=ISO-8859-1
          Transfer-Encoding: chunked
          Connection: keep-alive
          Server: nginx/1.22.0
          P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
          Set-Cookie: _trs_gv=g_lubf7tjh_5062_2crz; Max-Age=63072000; Expires=Sat, 28-Mar-2026 17:06:49 GMT; Path=/
          Cache-Control: no-cache
          Cache-Control: no-store
          Pragma: no-cache
          Expires: Wed, 31 Dec 1969 23:59:59 GMT
          max-age: Thu, 01 Jan 1970 00:00:00 GMT
          Cache-Control: max-age=14400
          Data Raw: 36 0d 0a 47 49 46 38 39 61 0d 0a
          Data Ascii: 6GIF89a
          Mar 28, 2024 18:06:49.484462976 CET5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0
          Mar 28, 2024 18:06:49.581828117 CET835OUTGET /favicon.ico HTTP/1.1
          Host: ta.trs.cn
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Cookie: _trs_gv=g_lubf7tjh_5062_2crz
          Mar 28, 2024 18:06:49.888766050 CET404INHTTP/1.1 404 Not Found
          Date: Thu, 28 Mar 2024 17:06:49 GMT
          Content-Type: text/html; charset=utf-8
          Transfer-Encoding: chunked
          Connection: keep-alive
          Server: nginx/1.22.0
          Vary: Accept-Encoding
          Content-Encoding: gzip
          Data Raw: 61 65 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 8e 41 0a c2 30 10 45 f7 82 77 18 0f 90 a6 2d 5d 0e d9 88 05 17 ba f1 04 a9 33 36 81 34 91 18 c1 de de 54 5b 10 d7 2e 5d 0d f3 e7 fd c7 a0 49 83 53 eb 15 1a d6 a4 30 d9 e4 58 35 65 03 c7 90 a0 0d 77 4f 28 df 21 ca 17 92 d1 2e d0 38 cd 33 fb c4 51 a1 a9 be 1b 39 41 39 9f 27 77 86 e6 cd f7 d6 3f 64 55 d4 75 51 7e 22 72 91 ca e5 a1 8d 10 a0 e1 aa 89 ac ef 21 05 20 7b d3 9d 63 38 9c f6 3b d0 9e 60 6b 62 18 18 2e d1 b2 27 37 02 c7 18 62 6e f4 0c 42 fc 15 bf 56 3c 01 7f 9c d3 6f 2b 02 00 00 0d 0a
          Data Ascii: aeA0Ew-]364T[.]IS0X5ewO(!.83Q9A9'w?dUuQ~"r! {c8;`kb.'7bnBV<o+
          Mar 28, 2024 18:06:49.888780117 CET5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0
          Mar 28, 2024 18:07:34.889691114 CET6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.549710120.53.131.129802180C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 18:07:34.186132908 CET6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.549712120.53.131.129802180C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 18:07:34.326771975 CET6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.54971723.209.58.93443
          TimestampBytes transferredDirectionData
          2024-03-28 17:06:52 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 17:06:52 UTC468INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/079C)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus2-z1
          Cache-Control: public, max-age=222960
          Date: Thu, 28 Mar 2024 17:06:52 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.54971823.209.58.93443
          TimestampBytes transferredDirectionData
          2024-03-28 17:06:53 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 17:06:53 UTC774INHTTP/1.1 200 OK
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-CID: 7
          X-CCC: US
          X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
          X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
          Content-Type: application/octet-stream
          X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=222847
          Date: Thu, 28 Mar 2024 17:06:53 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-03-28 17:06:53 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Session IDSource IPSource PortDestination IPDestination Port
          2192.168.2.54972423.1.237.91443
          TimestampBytes transferredDirectionData
          2024-03-28 17:07:04 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
          Origin: https://www.bing.com
          Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
          Accept: */*
          Accept-Language: en-CH
          Content-type: text/xml
          X-Agent-DeviceId: 01000A410900D492
          X-BM-CBT: 1696428841
          X-BM-DateFormat: dd/MM/yyyy
          X-BM-DeviceDimensions: 784x984
          X-BM-DeviceDimensionsLogical: 784x984
          X-BM-DeviceScale: 100
          X-BM-DTZ: 120
          X-BM-Market: CH
          X-BM-Theme: 000000;0078d7
          X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
          X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
          X-Device-isOptin: false
          X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
          X-Device-OSSKU: 48
          X-Device-Touch: false
          X-DeviceID: 01000A410900D492
          X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
          X-MSEdge-ExternalExpType: JointCoord
          X-PositionerType: Desktop
          X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
          X-Search-CortanaAvailableCapabilities: None
          X-Search-SafeSearch: Moderate
          X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
          X-UserAgeClass: Unknown
          Accept-Encoding: gzip, deflate, br
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
          Host: www.bing.com
          Content-Length: 2484
          Connection: Keep-Alive
          Cache-Control: no-cache
          Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1711645592757&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
          2024-03-28 17:07:04 UTC1OUTData Raw: 3c
          Data Ascii: <
          2024-03-28 17:07:04 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
          Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
          2024-03-28 17:07:04 UTC478INHTTP/1.1 204 No Content
          Access-Control-Allow-Origin: *
          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
          X-MSEdge-Ref: Ref A: 7CD18E4BF27E4EAFA7D68961555643E0 Ref B: LAX311000109029 Ref C: 2024-03-28T17:07:04Z
          Date: Thu, 28 Mar 2024 17:07:04 GMT
          Connection: close
          Alt-Svc: h3=":443"; ma=93600
          X-CDN-TraceID: 0.57ed0117.1711645624.ca99cc


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:18:06:42
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:18:06:45
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2408 --field-trial-handle=2368,i,17427900061271599603,4557120256687689452,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:18:06:48
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "HTTP://ta.trs.cn/c/1.gif?event=mousedown&sr=1280*720&br=1241*1163&dpr=1.5000&clicktype=2&mpId=5062&cs=lubf7tjh_5062_bc07&cu=lubf7tjh_5062_2crz&pv=5062_lubfq5xe_37wk&url=http://sanfrancisco.china-consulate.gov.cn/eng/lgjs/ContactUs/&e_tu=http://sanfrancisco.china-consulate.gov.cn/chn&e_td=sanfrancisco.china-consulate.gov.cn&e_tp=http&e_tx=../../images/top.jpg&e_tn=area&e_iac=1&e_et=mouseup&e_nd=Ly8qW0BpZD0nTWFwJ10vYXJlYQ==&e_etd=71&x=998&y=10&x2=369"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly