Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://tronjn52ws.z13.web.core.windows.net/

Overview

General Information

Sample URL:https://tronjn52ws.z13.web.core.windows.net/
Analysis ID:1417338
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2028,i,1663768306904287656,15371416736751185219,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6628 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tronjn52ws.z13.web.core.windows.net/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://tronjn52ws.z13.web.core.windows.net/SlashNext: detection malicious, Label: Scareware type: Phishing & Social Engineering
Source: https://tronjn52ws.z13.web.core.windows.net/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.48.10.90:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.48.10.90:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.156.54
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.156.54
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.48.10.90:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.48.10.90:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@2/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2028,i,1663768306904287656,15371416736751185219,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tronjn52ws.z13.web.core.windows.net/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2028,i,1663768306904287656,15371416736751185219,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://tronjn52ws.z13.web.core.windows.net/0%Avira URL Cloudsafe
https://tronjn52ws.z13.web.core.windows.net/3%VirustotalBrowse
https://tronjn52ws.z13.web.core.windows.net/100%SlashNextScareware type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
windowsupdatebg.s.llnwi.net0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.253.115.106
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    windowsupdatebg.s.llnwi.net
    69.164.0.0
    truefalseunknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    172.253.115.106
    www.google.comUnited States
    15169GOOGLEUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    IP
    192.168.2.4
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1417338
    Start date and time:2024-03-29 01:20:19 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 1s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:https://tronjn52ws.z13.web.core.windows.net/
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:8
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal48.win@16/4@2/3
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.251.167.94, 172.253.122.84, 172.253.122.100, 172.253.122.138, 172.253.122.102, 172.253.122.113, 172.253.122.139, 172.253.122.101, 34.104.35.123, 20.209.41.14, 20.114.59.183, 69.164.0.0, 192.229.211.108, 52.165.164.15, 13.95.31.18, 172.253.115.94
    • Excluded domains from analysis (whitelisted): fs.microsoft.com, web.mnz22prdstr15a.store.core.windows.net, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, tronjn52ws.z13.web.core.windows.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
    Category:downloaded
    Size (bytes):321
    Entropy (8bit):5.079066540124159
    Encrypted:false
    SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOFFRR2p02WfsZCoE:hax0rKRHkhzRH/Un2i2GprK5YWOhFbh
    MD5:9AB92B522A37BE8841F78A6AC3A297CD
    SHA1:8A8D49E666B49A00CC20E5842F5A29C621F6D0D3
    SHA-256:6F3C0D9DAED8C98EF7A1A8905F43428B2B45329C7F8FC4DF441DB7BBADD4D9D3
    SHA-512:3D99E7C6D2F12216F2629FAFBB70DF6052518F7C70661EBC3B1C0B7A569117E745B46C44BCC2AE880AD156AC283CA7D885410D5380CB2701B42AFF0AD682831F
    Malicious:false
    Reputation:low
    URL:https://tronjn52ws.z13.web.core.windows.net/
    Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : 9c6cef80-901e-005d-5e6e-8183a8000000</li><li>TimeStamp : 2024-03-29T00:21:09.6336432Z</li></ul></p></body></html>
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
    Category:downloaded
    Size (bytes):321
    Entropy (8bit):5.064888698186839
    Encrypted:false
    SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOxZIWTVXzR2p02WfsZTMZgE:hax0rKRHkhzRH/Un2i2GprK5YWOzIWTx
    MD5:C80E174BF9F575FE7520AE72B32722DA
    SHA1:3B11BAC472C7311497709020A6CE7F114D5E5702
    SHA-256:9AF4E8FC551B842FBFB377BF491689B6742D1A1EA5B4B5A52760ADF7E2C6F4F0
    SHA-512:EC6AA9A6D6020A7A7832E3056073613F77FEE6B277A6CBA0A1AD12E5E635F450736B9A9F88B9C9B8E2AF884F917577DC3A127372145BCB4910B36035135370EA
    Malicious:false
    Reputation:low
    URL:https://tronjn52ws.z13.web.core.windows.net/favicon.ico
    Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : 0d5d18d1-801e-006e-576e-81dc03000000</li><li>TimeStamp : 2024-03-29T00:21:09.7836599Z</li></ul></p></body></html>
    No static file info
    TimestampSource PortDest PortSource IPDest IP
    Mar 29, 2024 01:21:01.825659037 CET49678443192.168.2.4104.46.162.224
    Mar 29, 2024 01:21:02.372478008 CET49675443192.168.2.4173.222.162.32
    Mar 29, 2024 01:21:11.622606039 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.622646093 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.622704029 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.652110100 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.652131081 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.862149000 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.864092112 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.864108086 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.865099907 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.865298986 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.869537115 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.869599104 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.918081999 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.918091059 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:11.965538025 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:11.972124100 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:11.972151041 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:11.973675966 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:11.975604057 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:11.975619078 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:11.980396986 CET49675443192.168.2.4173.222.162.32
    Mar 29, 2024 01:21:12.324578047 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.324733973 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.332834005 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.332839966 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.333066940 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.389533043 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.390114069 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.436233997 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.658257961 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.658320904 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.658427954 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.658427954 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.658452988 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.658482075 CET49740443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.658490896 CET4434974023.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.687263966 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.687294960 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:12.687419891 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.687731981 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:12.687741995 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.035315037 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.035377979 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.079112053 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.079133987 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.079364061 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.084714890 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.128241062 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.373671055 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.373744965 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.373790979 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.375932932 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.375946045 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:13.375953913 CET49741443192.168.2.423.48.10.90
    Mar 29, 2024 01:21:13.375958920 CET4434974123.48.10.90192.168.2.4
    Mar 29, 2024 01:21:21.861469030 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:21.861542940 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:21:21.861660004 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:23.536349058 CET49739443192.168.2.4172.253.115.106
    Mar 29, 2024 01:21:23.536376953 CET44349739172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.532835007 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:11.532866001 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.532926083 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:11.534204006 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:11.534215927 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.758500099 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.759264946 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:11.759275913 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.759608030 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.760392904 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:11.760454893 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:11.808396101 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:20.772156000 CET4972380192.168.2.423.46.156.54
    Mar 29, 2024 01:22:20.772155046 CET4972480192.168.2.472.21.81.240
    Mar 29, 2024 01:22:20.866626024 CET804972472.21.81.240192.168.2.4
    Mar 29, 2024 01:22:20.866863966 CET4972480192.168.2.472.21.81.240
    Mar 29, 2024 01:22:20.875108004 CET804972323.46.156.54192.168.2.4
    Mar 29, 2024 01:22:20.875184059 CET4972380192.168.2.423.46.156.54
    Mar 29, 2024 01:22:21.786000013 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:21.786067009 CET44349750172.253.115.106192.168.2.4
    Mar 29, 2024 01:22:21.786111116 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:23.542771101 CET49750443192.168.2.4172.253.115.106
    Mar 29, 2024 01:22:23.542795897 CET44349750172.253.115.106192.168.2.4
    TimestampSource PortDest PortSource IPDest IP
    Mar 29, 2024 01:21:07.114703894 CET53513401.1.1.1192.168.2.4
    Mar 29, 2024 01:21:07.243527889 CET53651531.1.1.1192.168.2.4
    Mar 29, 2024 01:21:07.876323938 CET53494971.1.1.1192.168.2.4
    Mar 29, 2024 01:21:11.485002995 CET6034453192.168.2.41.1.1.1
    Mar 29, 2024 01:21:11.485440016 CET6109353192.168.2.41.1.1.1
    Mar 29, 2024 01:21:11.580416918 CET53603441.1.1.1192.168.2.4
    Mar 29, 2024 01:21:11.604224920 CET53610931.1.1.1192.168.2.4
    Mar 29, 2024 01:21:24.928154945 CET53650461.1.1.1192.168.2.4
    Mar 29, 2024 01:21:32.368264914 CET138138192.168.2.4192.168.2.255
    Mar 29, 2024 01:21:43.983927965 CET53584181.1.1.1192.168.2.4
    Mar 29, 2024 01:22:06.424390078 CET53578851.1.1.1192.168.2.4
    Mar 29, 2024 01:22:07.208291054 CET53651791.1.1.1192.168.2.4
    Mar 29, 2024 01:22:35.094647884 CET53537111.1.1.1192.168.2.4
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Mar 29, 2024 01:21:11.485002995 CET192.168.2.41.1.1.10x1d49Standard query (0)www.google.comA (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.485440016 CET192.168.2.41.1.1.10x8677Standard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.106A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.105A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.104A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.103A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.147A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.580416918 CET1.1.1.1192.168.2.40x1d49No error (0)www.google.com172.253.115.99A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:11.604224920 CET1.1.1.1192.168.2.40x8677No error (0)www.google.com65IN (0x0001)false
    Mar 29, 2024 01:21:24.446985006 CET1.1.1.1192.168.2.40x8e69No error (0)windowsupdatebg.s.llnwi.net69.164.0.0A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:24.756422043 CET1.1.1.1192.168.2.40x1618No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 29, 2024 01:21:24.756422043 CET1.1.1.1192.168.2.40x1618No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:38.170471907 CET1.1.1.1192.168.2.40x8eacNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 29, 2024 01:21:38.170471907 CET1.1.1.1192.168.2.40x8eacNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 29, 2024 01:21:59.062748909 CET1.1.1.1192.168.2.40x865cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 29, 2024 01:21:59.062748909 CET1.1.1.1192.168.2.40x865cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 29, 2024 01:22:19.821082115 CET1.1.1.1192.168.2.40xba08No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 29, 2024 01:22:19.821082115 CET1.1.1.1192.168.2.40xba08No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    • fs.microsoft.com
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.44974023.48.10.90443
    TimestampBytes transferredDirectionData
    2024-03-29 00:21:12 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-03-29 00:21:12 UTC468INHTTP/1.1 200 OK
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    Content-Type: application/octet-stream
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    Server: ECAcc (chd/073D)
    X-CID: 11
    X-Ms-ApiVersion: Distribute 1.2
    X-Ms-Region: prod-eus2-z1
    Cache-Control: public, max-age=196915
    Date: Fri, 29 Mar 2024 00:21:12 GMT
    Connection: close
    X-CID: 2


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    1192.168.2.44974123.48.10.90443
    TimestampBytes transferredDirectionData
    2024-03-29 00:21:13 UTC239OUTGET /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
    Range: bytes=0-2147483646
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-03-29 00:21:13 UTC774INHTTP/1.1 200 OK
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    ApiVersion: Distribute 1.1
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    X-CID: 7
    X-CCC: US
    X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
    X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
    Content-Type: application/octet-stream
    X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
    Cache-Control: public, max-age=196956
    Date: Fri, 29 Mar 2024 00:21:13 GMT
    Content-Length: 55
    Connection: close
    X-CID: 2
    2024-03-29 00:21:13 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:01:21:03
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:2
    Start time:01:21:05
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2028,i,1663768306904287656,15371416736751185219,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:3
    Start time:01:21:07
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tronjn52ws.z13.web.core.windows.net/"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    No disassembly