Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://en.getguri.com/

Overview

General Information

Sample URL:https://en.getguri.com/
Analysis ID:1417419
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 4832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2008,i,12105213634753244638,12533229504263358409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 2548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://en.getguri.com/" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 104.98.116.138:443 -> 192.168.2.7:49715 version: TLS 1.0
Source: unknownHTTPS traffic detected: 104.98.116.138:443 -> 192.168.2.7:49715 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: en.getguri.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A4109005EFEX-BM-CBT: 1696492382X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 60X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: 7964DE11F2244989AF4CA95A808EA94CX-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A4109005EFEX-MSEdge-ExternalExp: bfbwsbcm0921cf,d-thshld42,websuganno_t2,wsbmsaqfuxt3,wsbqfasmsall_t,wsbqfminiserp500,wsbref-t,wsbuacfX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 516Connection: Keep-AliveCache-Control: no-cacheCookie: SRCHUID=V=2&GUID=19565074ACE142FCABAF0CDCC0DFAAEB&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231005; SRCHHPGUSR=SRCHLANG=en&LUT=1696492216762&IPMH=45187fb8&IPMID=1696492382078&HV=1696492289; CortanaAppUID=FE52A12E95B5DF3DB5902D0602A16B66; MUID=A92BA4E78D2946A0AFDA5029FA43D7A8; _SS=SID=21E2F496C67F672E2F62E737C76966EF&CPID=1696492383022&AC=1&CPH=644b7eae; _EDGE_S=SID=21E2F496C67F672E2F62E737C76966EF; MUIDB=A92BA4E78D2946A0AFDA5029FA43D7A8
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: classification engineClassification label: unknown0.win@19/0@13/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2008,i,12105213634753244638,12533229504263358409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://en.getguri.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2008,i,12105213634753244638,12533229504263358409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://en.getguri.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.253.63.102
truefalse
    high
    www.google.com
    172.253.115.104
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        en.getguri.com
        unknown
        unknownfalse
          unknown
          time.windows.com
          unknown
          unknownfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            172.253.115.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.7
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1417419
            Start date and time:2024-03-29 08:45:10 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 2s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://en.getguri.com/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:15
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@13/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.63.139, 172.253.63.101, 172.253.63.100, 172.253.63.138, 172.253.63.102, 172.253.63.113, 172.253.122.84, 142.251.111.94, 34.104.35.123, 23.62.24.116, 168.61.215.74, 20.114.59.183, 69.164.0.128, 192.229.211.108, 72.21.81.240, 13.85.23.206
            • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, twc.trafficmanager.net, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://en.getguri.com/
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 29, 2024 08:45:57.306456089 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:45:57.618627071 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:45:58.228003979 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:45:59.431200981 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:45:59.712400913 CET49674443192.168.2.7104.98.116.138
            Mar 29, 2024 08:45:59.712408066 CET49675443192.168.2.7104.98.116.138
            Mar 29, 2024 08:45:59.806107998 CET49672443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:01.837379932 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:46:05.853539944 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:06.229481936 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:06.649610043 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:46:06.978435040 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:07.795200109 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:07.795236111 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:07.795286894 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:07.796016932 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:07.796026945 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.017925024 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.019773006 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:08.019798994 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.020845890 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.020900965 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:08.025512934 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:08.025577068 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.071822882 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:08.071831942 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:08.118696928 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:08.480185986 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:09.321149111 CET49674443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:09.321465015 CET49675443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:09.414913893 CET49672443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:10.873786926 CET44349699104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:10.873902082 CET49699443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:11.462296963 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:16.263765097 CET49671443192.168.2.7204.79.197.203
            Mar 29, 2024 08:46:17.415994883 CET49677443192.168.2.720.50.201.200
            Mar 29, 2024 08:46:18.049941063 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:18.050019026 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:18.050075054 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:18.888410091 CET49708443192.168.2.7172.253.115.104
            Mar 29, 2024 08:46:18.888437033 CET44349708172.253.115.104192.168.2.7
            Mar 29, 2024 08:46:21.552472115 CET49699443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:21.552845955 CET49699443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:21.687642097 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:21.687669992 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:21.687736988 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:21.688410044 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:21.688420057 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:21.706959009 CET44349699104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:21.707207918 CET44349699104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.008383036 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.008498907 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.048954010 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.048973083 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.049377918 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.049436092 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.050230980 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.050257921 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.050421953 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.092236042 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.364648104 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.364739895 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.365058899 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.365108013 CET44349715104.98.116.138192.168.2.7
            Mar 29, 2024 08:46:22.365118027 CET49715443192.168.2.7104.98.116.138
            Mar 29, 2024 08:46:22.365159035 CET49715443192.168.2.7104.98.116.138
            TimestampSource PortDest PortSource IPDest IP
            Mar 29, 2024 08:46:04.803560019 CET53617991.1.1.1192.168.2.7
            Mar 29, 2024 08:46:04.818336010 CET53502061.1.1.1192.168.2.7
            Mar 29, 2024 08:46:05.428136110 CET53499001.1.1.1192.168.2.7
            Mar 29, 2024 08:46:06.038630962 CET5642153192.168.2.71.1.1.1
            Mar 29, 2024 08:46:06.038813114 CET5336453192.168.2.71.1.1.1
            Mar 29, 2024 08:46:06.136017084 CET53564211.1.1.1192.168.2.7
            Mar 29, 2024 08:46:06.147440910 CET53533641.1.1.1192.168.2.7
            Mar 29, 2024 08:46:06.148391962 CET4990253192.168.2.71.1.1.1
            Mar 29, 2024 08:46:06.246418953 CET53499021.1.1.1192.168.2.7
            Mar 29, 2024 08:46:06.340945959 CET5021653192.168.2.78.8.8.8
            Mar 29, 2024 08:46:06.341922045 CET5425353192.168.2.71.1.1.1
            Mar 29, 2024 08:46:06.437510014 CET53542531.1.1.1192.168.2.7
            Mar 29, 2024 08:46:06.452331066 CET53502168.8.8.8192.168.2.7
            Mar 29, 2024 08:46:07.329838037 CET6313353192.168.2.71.1.1.1
            Mar 29, 2024 08:46:07.330420017 CET5203453192.168.2.71.1.1.1
            Mar 29, 2024 08:46:07.427325010 CET53631331.1.1.1192.168.2.7
            Mar 29, 2024 08:46:07.428958893 CET53520341.1.1.1192.168.2.7
            Mar 29, 2024 08:46:07.697546005 CET5076053192.168.2.71.1.1.1
            Mar 29, 2024 08:46:07.697813988 CET6091353192.168.2.71.1.1.1
            Mar 29, 2024 08:46:07.792661905 CET53507601.1.1.1192.168.2.7
            Mar 29, 2024 08:46:07.792678118 CET53609131.1.1.1192.168.2.7
            Mar 29, 2024 08:46:10.581778049 CET5452453192.168.2.71.1.1.1
            Mar 29, 2024 08:46:12.619576931 CET4940153192.168.2.71.1.1.1
            Mar 29, 2024 08:46:12.619981050 CET5067853192.168.2.71.1.1.1
            Mar 29, 2024 08:46:12.717504025 CET53494011.1.1.1192.168.2.7
            Mar 29, 2024 08:46:12.732280970 CET53506781.1.1.1192.168.2.7
            Mar 29, 2024 08:46:12.873878002 CET6023053192.168.2.71.1.1.1
            Mar 29, 2024 08:46:12.970048904 CET53602301.1.1.1192.168.2.7
            Mar 29, 2024 08:46:22.465727091 CET53649921.1.1.1192.168.2.7
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 29, 2024 08:46:06.038630962 CET192.168.2.71.1.1.10xc03fStandard query (0)en.getguri.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.038813114 CET192.168.2.71.1.1.10xcd5dStandard query (0)en.getguri.com65IN (0x0001)false
            Mar 29, 2024 08:46:06.148391962 CET192.168.2.71.1.1.10x711dStandard query (0)en.getguri.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.340945959 CET192.168.2.78.8.8.80x292bStandard query (0)google.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.341922045 CET192.168.2.71.1.1.10x4c0Standard query (0)google.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.329838037 CET192.168.2.71.1.1.10xf5d0Standard query (0)en.getguri.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.330420017 CET192.168.2.71.1.1.10x5394Standard query (0)en.getguri.com65IN (0x0001)false
            Mar 29, 2024 08:46:07.697546005 CET192.168.2.71.1.1.10x6268Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.697813988 CET192.168.2.71.1.1.10x52e3Standard query (0)www.google.com65IN (0x0001)false
            Mar 29, 2024 08:46:10.581778049 CET192.168.2.71.1.1.10x68a0Standard query (0)time.windows.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:12.619576931 CET192.168.2.71.1.1.10x309eStandard query (0)en.getguri.comA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:12.619981050 CET192.168.2.71.1.1.10x7223Standard query (0)en.getguri.com65IN (0x0001)false
            Mar 29, 2024 08:46:12.873878002 CET192.168.2.71.1.1.10xde76Standard query (0)en.getguri.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 29, 2024 08:46:06.136017084 CET1.1.1.1192.168.2.70xc03fName error (3)en.getguri.comnonenoneA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.246418953 CET1.1.1.1192.168.2.70x711dName error (3)en.getguri.comnonenoneA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.102A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.113A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.100A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.101A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.138A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.437510014 CET1.1.1.1192.168.2.70x4c0No error (0)google.com172.253.63.139A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.102A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.101A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.138A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.139A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.100A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:06.452331066 CET8.8.8.8192.168.2.70x292bNo error (0)google.com172.253.122.113A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.427325010 CET1.1.1.1192.168.2.70xf5d0Name error (3)en.getguri.comnonenoneA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.428958893 CET1.1.1.1192.168.2.70x5394Name error (3)en.getguri.comnonenone65IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.104A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.105A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.147A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.103A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.106A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792661905 CET1.1.1.1192.168.2.70x6268No error (0)www.google.com172.253.115.99A (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:07.792678118 CET1.1.1.1192.168.2.70x52e3No error (0)www.google.com65IN (0x0001)false
            Mar 29, 2024 08:46:10.678275108 CET1.1.1.1192.168.2.70x68a0No error (0)time.windows.comtwc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 08:46:12.717504025 CET1.1.1.1192.168.2.70x309eName error (3)en.getguri.comnonenoneA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:12.970048904 CET1.1.1.1192.168.2.70xde76Name error (3)en.getguri.comnonenoneA (IP address)IN (0x0001)false
            Mar 29, 2024 08:46:20.656457901 CET1.1.1.1192.168.2.70x7f50No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 08:46:20.656457901 CET1.1.1.1192.168.2.70x7f50No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • https:
              • www.bing.com
            Session IDSource IPSource PortDestination IPDestination Port
            0192.168.2.749715104.98.116.138443
            TimestampBytes transferredDirectionData
            2024-03-29 07:46:22 UTC2205OUTPOST /threshold/xls.aspx HTTP/1.1
            Origin: https://www.bing.com
            Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
            Accept: */*
            Accept-Language: en-CH
            Content-type: text/xml
            X-Agent-DeviceId: 01000A4109005EFE
            X-BM-CBT: 1696492382
            X-BM-DateFormat: dd/MM/yyyy
            X-BM-DeviceDimensions: 784x984
            X-BM-DeviceDimensionsLogical: 784x984
            X-BM-DeviceScale: 100
            X-BM-DTZ: 60
            X-BM-Market: CH
            X-BM-Theme: 000000;0078d7
            X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
            X-Device-ClientSession: 7964DE11F2244989AF4CA95A808EA94C
            X-Device-isOptin: false
            X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
            X-Device-OSSKU: 48
            X-Device-Touch: false
            X-DeviceID: 01000A4109005EFE
            X-MSEdge-ExternalExp: bfbwsbcm0921cf,d-thshld42,websuganno_t2,wsbmsaqfuxt3,wsbqfasmsall_t,wsbqfminiserp500,wsbref-t,wsbuacf
            X-MSEdge-ExternalExpType: JointCoord
            X-PositionerType: Desktop
            X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
            X-Search-CortanaAvailableCapabilities: None
            X-Search-SafeSearch: Moderate
            X-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard Time
            X-UserAgeClass: Unknown
            Accept-Encoding: gzip, deflate, br
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
            Host: www.bing.com
            Content-Length: 516
            Connection: Keep-Alive
            Cache-Control: no-cache
            Cookie: SRCHUID=V=2&GUID=19565074ACE142FCABAF0CDCC0DFAAEB&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231005; SRCHHPGUSR=SRCHLANG=en&LUT=1696492216762&IPMH=45187fb8&IPMID=1696492382078&HV=1696492289; CortanaAppUID=FE52A12E95B5DF3DB5902D0602A16B66; MUID=A92BA4E78D2946A0AFDA5029FA43D7A8; _SS=SID=21E2F496C67F672E2F62E737C76966EF&CPID=1696492383022&AC=1&CPH=644b7eae; _EDGE_S=SID=21E2F496C67F672E2F62E737C76966EF; MUIDB=A92BA4E78D2946A0AFDA5029FA43D7A8
            2024-03-29 07:46:22 UTC1OUTData Raw: 3c
            Data Ascii: <
            2024-03-29 07:46:22 UTC515OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 41 39 32 42 41 34 45 37 38 44 32 39 34 36 41 30 41 46 44 41 35 30 32 39 46 41 34 33 44 37 41 38 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 31 45 39 44 31 37 45 34 43 44 34 32 45 42 41 41 36 41 45 35 39 41 36 45 44 35 43 32 32 41 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
            Data Ascii: ClientInstRequest><CID>A92BA4E78D2946A0AFDA5029FA43D7A8</CID><Events><E><T>Event.ClientInst</T><IG>751E9D17E4CD42EBAA6AE59A6ED5C22A</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
            2024-03-29 07:46:22 UTC479INHTTP/1.1 204 No Content
            Access-Control-Allow-Origin: *
            Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
            X-MSEdge-Ref: Ref A: C6E5DBF7C9A8401F857A0C07BC5CC178 Ref B: LAX311000114031 Ref C: 2024-03-29T07:46:22Z
            Date: Fri, 29 Mar 2024 07:46:22 GMT
            Connection: close
            Alt-Svc: h3=":443"; ma=93600
            X-CDN-TraceID: 0.86746268.1711698382.2bf4b27


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:08:46:00
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff6c4390000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:08:46:02
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2008,i,12105213634753244638,12533229504263358409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff6c4390000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:5
            Start time:08:46:05
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://en.getguri.com/"
            Imagebase:0x7ff6c4390000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly