Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://us.securewebstatus.com

Overview

General Information

Sample URL:http://us.securewebstatus.com
Analysis ID:1417531
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 1476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2200,i,4482577667092401635,2642425844030144361,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://us.securewebstatus.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://us.securewebstatus.comAvira URL Cloud: detection malicious, Label: malware
Source: https://us.securewebstatus.com/favicon.icoAvira URL Cloud: Label: malware
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49723 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49723 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: us.securewebstatus.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: us.securewebstatus.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://us.securewebstatus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: us.securewebstatus.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: us.securewebstatus.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1711721523929&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: mal56.win@17/9@8/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2200,i,4482577667092401635,2642425844030144361,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://us.securewebstatus.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2200,i,4482577667092401635,2642425844030144361,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://us.securewebstatus.com100%Avira URL Cloudmalware
http://us.securewebstatus.com4%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
us.securewebstatus.com4%VirustotalBrowse
SourceDetectionScannerLabelLink
https://us.securewebstatus.com/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
us.securewebstatus.com
104.21.32.77
truefalseunknown
www.google.com
142.250.31.104
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://us.securewebstatus.com/false
      unknown
      https://us.securewebstatus.com/favicon.icofalse
      • Avira URL Cloud: malware
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      142.250.31.104
      www.google.comUnited States
      15169GOOGLEUSfalse
      104.21.32.77
      us.securewebstatus.comUnited States
      13335CLOUDFLARENETUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      IP
      192.168.2.5
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1417531
      Start date and time:2024-03-29 15:11:30 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 3s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://us.securewebstatus.com
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal56.win@17/9@8/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.253.115.94, 172.253.62.84, 172.253.63.139, 172.253.63.138, 172.253.63.100, 172.253.63.113, 172.253.63.101, 172.253.63.102, 34.104.35.123, 13.85.23.86, 72.21.81.240, 192.229.211.108, 52.165.164.15, 13.85.23.206, 20.114.59.183, 172.253.122.94
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:12:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.9877286004938357
      Encrypted:false
      SSDEEP:48:8UdtrTNTJhHJidAKZdA19ehwiZUklqehHy+3:8Erxl5oy
      MD5:0AE63ED1FE7FCD11259B47A0DC25A9EB
      SHA1:83487343467CBB902CBFC11C45776A8C8CE40EE0
      SHA-256:C8F3363430C6C3A3C97ACD7A9B918B154B32DEF4C73BC4E7E5CCCB4A59D740C4
      SHA-512:12888798B46DCC566AB96808C742C8E885C59E47ED07D86C6C45435D3E84FE5C4E5BA0193F8A26E98B372170E5A3436984740ED016D8165C3A8623DFB3F9F326
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....d.v....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V}X.q...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:12:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):4.004264428892738
      Encrypted:false
      SSDEEP:48:8bdtrTNTJhHJidAKZdA1weh/iZUkAQkqehYy+2:8frxlr9Qdy
      MD5:7007639C81B976344A25CD273034484B
      SHA1:1C56C389B0E92E80407CC3CE6A0C1E2E766B96E6
      SHA-256:2FEEECFED747E4C1D6DC2F281A165E8E0836BA6456EEB0259D7C6D337F8CD084
      SHA-512:913450C77A0D98FAC96CF0742754F333BA3D62367189FA9FA088C1162FE91FC455D5FAA417B559A35ED8503251060DBEFD051436FD2F275CF9AC7F9652793B5F
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......i....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V}X.q...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2693
      Entropy (8bit):4.013379768066451
      Encrypted:false
      SSDEEP:48:8xKdtrTNTJsHJidAKZdA14tseh7sFiZUkmgqeh7s2y+BX:8x2rxlonky
      MD5:3170E9F17E02ED7B523B62223C6B5471
      SHA1:CC0DBD4E0DAD4E7E4598FCC01C979FAE5CDFEC0D
      SHA-256:92E3108203846E137A02984A37DB1B55EB15E6F459539267D4C344B4EC7DAD83
      SHA-512:7D6AA2A35917B084BEACF273107BBD338965B781FDA70092551209396083E54CCEBDF803289CE70FFAEB5B9E20F1DF388B4348BAEE77BA80603284A8D8499903
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:12:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):4.000841544939608
      Encrypted:false
      SSDEEP:48:84dtrTNTJhHJidAKZdA1vehDiZUkwqehcy+R:8Yrxlouy
      MD5:0137CFC66989B61C97E5279B0B309B8E
      SHA1:B6C58EEC5D6BC87EDE203753C68B3EBE9CF75C0E
      SHA-256:00FD29D2A332B31625F4D49DFA478D4DD049BFB37B8DF44AD3BD0BDF70544A1F
      SHA-512:56EC0F80933DA08C75C6209631F8F0933AE83857174A5189DE6802BE77F42F3168D375F1404352A94783213C76B45FA4A08CCDD9F36F21767F2B9752F15D3C4A
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....)md....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V}X.q...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:12:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9905291495167905
      Encrypted:false
      SSDEEP:48:85dtrTNTJhHJidAKZdA1hehBiZUk1W1qehyy+C:8Jrxl49Sy
      MD5:45F04DCCAA803E4848122394B4719CFF
      SHA1:831146730C0FDE55B4BEBD7D044D390CBF473AA8
      SHA-256:81A7444B8B8F7752A77996DDBCD33BB00BBC5FEDB1953E6CEBBF8E2EE280D879
      SHA-512:70433A3D0A8D389EDA8DAF254EED36AB90EBD97C891CA15699DC3779392CD900EB7FDC16B7B9D5A065B869C9B351AA2F5B363FD486BB5FF91FCFC92E133BB371
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......o....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V}X.q...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:12:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2683
      Entropy (8bit):4.003424061450023
      Encrypted:false
      SSDEEP:48:8hdtrTNTJhHJidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbky+yT+:8hrxlWT/TbxWOvTbky7T
      MD5:E81833C9CF39645F084469A7869EFA2D
      SHA1:3E5AA55697581F844672891BA9AE187118A7CFFE
      SHA-256:D84516D4AA8C6CDFD9685751725C2B848DAA301AED359CFF57253D7C3B325186
      SHA-512:0E8D8CFF266FFED5296B112BBACBBCB069D7E9F8526ACB67E6DD333B26DFEF42FB4AC04CA40BEA07E25B748551292C31FC58DFCC7D9355A4D1230177EABC6CA2
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....u.Z....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I}X.q....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V}X.q....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V}X.q....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V}X.q..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V}X.q...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
      Category:dropped
      Size (bytes):198
      Entropy (8bit):1.23143406345007
      Encrypted:false
      SSDEEP:3:2oXllvlNl/FXltlBe/h/555555555555555n:2Y1UJ555555555555555n
      MD5:C6ACEDAFF906029FC5455D9EC52C7F42
      SHA1:92CBD806CA421AA2C9FF5E1FF76BBC20913A2F81
      SHA-256:9DEB629637088856FE61DC868BF40A7D21ED942E4117659F3D6C3408F59B906B
      SHA-512:7A8D002CA6B607E38860AD4485493E109CB7D3BEF241B0E5BF2A65C2E316E6185DED8EC74E3FCBD78745AB302C6D876657ABC178EE028D1B8B9A5572F429D972
      Malicious:false
      Reputation:low
      Preview:......................(....... .......................................................................................................................................................................
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
      Category:downloaded
      Size (bytes):198
      Entropy (8bit):1.23143406345007
      Encrypted:false
      SSDEEP:3:2oXllvlNl/FXltlBe/h/555555555555555n:2Y1UJ555555555555555n
      MD5:C6ACEDAFF906029FC5455D9EC52C7F42
      SHA1:92CBD806CA421AA2C9FF5E1FF76BBC20913A2F81
      SHA-256:9DEB629637088856FE61DC868BF40A7D21ED942E4117659F3D6C3408F59B906B
      SHA-512:7A8D002CA6B607E38860AD4485493E109CB7D3BEF241B0E5BF2A65C2E316E6185DED8EC74E3FCBD78745AB302C6D876657ABC178EE028D1B8B9A5572F429D972
      Malicious:false
      Reputation:low
      URL:https://us.securewebstatus.com/favicon.ico
      Preview:......................(....... .......................................................................................................................................................................
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Mar 29, 2024 15:12:14.541481018 CET49675443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:14.541482925 CET49674443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:14.666471958 CET49673443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:20.683731079 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.683752060 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.683826923 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.684324980 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.684339046 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.888454914 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.918708086 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.918721914 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.919884920 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.919950962 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.923032999 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.923135996 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:20.923224926 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.963109970 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:20.963119984 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.009202957 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.146320105 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.146385908 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.146436930 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.165693998 CET49709443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.165714979 CET44349709104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.226600885 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.226645947 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.226716042 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.226963043 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.226977110 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.435101032 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.435405016 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.435419083 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.435764074 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.436244965 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.436306953 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.436414957 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.480237961 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.679017067 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.679084063 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.679136992 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.681425095 CET49712443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.681441069 CET44349712104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.811923981 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.811949968 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:21.812057018 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.818434000 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:21.818442106 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.020040035 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.020394087 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.020402908 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.021578074 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.021650076 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.023438931 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.023494005 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.023915052 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.023921013 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.071470976 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.263555050 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.263617992 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.263664961 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.335241079 CET49713443192.168.2.5104.21.32.77
      Mar 29, 2024 15:12:22.335256100 CET44349713104.21.32.77192.168.2.5
      Mar 29, 2024 15:12:22.975861073 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:22.975898027 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:22.975967884 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:22.979860067 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:22.979882002 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.234654903 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.291867018 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.303766012 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.303772926 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.305298090 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.305383921 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.305418015 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.328438044 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.328597069 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.383454084 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.383464098 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:23.431857109 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:23.631864071 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:23.631907940 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:23.635982037 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:23.638361931 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:23.638377905 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:23.842251062 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:23.842549086 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:23.847856045 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:23.847865105 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:23.848134041 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:23.899022102 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.043169022 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.088238955 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.141572952 CET49674443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:24.146064043 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.146127939 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.146183014 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.146594048 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.146611929 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.146625042 CET49715443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.146630049 CET4434971523.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.164654970 CET49675443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:24.185429096 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.185457945 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.185533047 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.185925961 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.185940981 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.268923044 CET49673443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:24.389405012 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.389494896 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.391102076 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.391110897 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.391360998 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.392621994 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.440231085 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.654340982 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.654406071 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:24.654464006 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.680506945 CET49716443192.168.2.523.221.242.90
      Mar 29, 2024 15:12:24.680522919 CET4434971623.221.242.90192.168.2.5
      Mar 29, 2024 15:12:25.645553112 CET4434970323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:25.645725965 CET49703443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:33.227442980 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:33.227514029 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:33.227566957 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:35.142066956 CET49714443192.168.2.5142.250.31.104
      Mar 29, 2024 15:12:35.142095089 CET44349714142.250.31.104192.168.2.5
      Mar 29, 2024 15:12:36.228724957 CET49703443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.228804111 CET49703443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.229073048 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.229113102 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.229311943 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.229521036 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.229536057 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.387839079 CET4434970323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.387860060 CET4434970323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.557215929 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.557295084 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.582123995 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.582140923 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.582422018 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.582482100 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.582928896 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.582957029 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.583219051 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.583225965 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.942390919 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.942537069 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.942656994 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.942703962 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:12:36.942725897 CET4434972323.1.237.91192.168.2.5
      Mar 29, 2024 15:12:36.942783117 CET49723443192.168.2.523.1.237.91
      Mar 29, 2024 15:13:22.500057936 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:22.500108957 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.500184059 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:22.501188993 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:22.501205921 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.751329899 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.751794100 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:22.751857042 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.752183914 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.753345966 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:22.753407001 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:22.806022882 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:32.752346039 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:32.752408028 CET44349727142.250.31.104192.168.2.5
      Mar 29, 2024 15:13:32.752520084 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:33.203246117 CET49727443192.168.2.5142.250.31.104
      Mar 29, 2024 15:13:33.203263998 CET44349727142.250.31.104192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Mar 29, 2024 15:12:18.490124941 CET53576021.1.1.1192.168.2.5
      Mar 29, 2024 15:12:18.609205961 CET53603551.1.1.1192.168.2.5
      Mar 29, 2024 15:12:19.331928015 CET53618181.1.1.1192.168.2.5
      Mar 29, 2024 15:12:20.437256098 CET6151153192.168.2.51.1.1.1
      Mar 29, 2024 15:12:20.437509060 CET6224553192.168.2.51.1.1.1
      Mar 29, 2024 15:12:20.541815042 CET53622451.1.1.1192.168.2.5
      Mar 29, 2024 15:12:20.547095060 CET5011153192.168.2.51.1.1.1
      Mar 29, 2024 15:12:20.547290087 CET5110053192.168.2.51.1.1.1
      Mar 29, 2024 15:12:20.628667116 CET53615111.1.1.1192.168.2.5
      Mar 29, 2024 15:12:20.647825003 CET53501111.1.1.1192.168.2.5
      Mar 29, 2024 15:12:20.691061974 CET53511001.1.1.1192.168.2.5
      Mar 29, 2024 15:12:21.689168930 CET5944453192.168.2.51.1.1.1
      Mar 29, 2024 15:12:21.689528942 CET5392653192.168.2.51.1.1.1
      Mar 29, 2024 15:12:21.789845943 CET53594441.1.1.1192.168.2.5
      Mar 29, 2024 15:12:21.790756941 CET53539261.1.1.1192.168.2.5
      Mar 29, 2024 15:12:22.448431015 CET5663753192.168.2.51.1.1.1
      Mar 29, 2024 15:12:22.449053049 CET5268753192.168.2.51.1.1.1
      Mar 29, 2024 15:12:22.544717073 CET53566371.1.1.1192.168.2.5
      Mar 29, 2024 15:12:22.545298100 CET53526871.1.1.1192.168.2.5
      Mar 29, 2024 15:12:37.059506893 CET53563741.1.1.1192.168.2.5
      Mar 29, 2024 15:12:55.765996933 CET53492671.1.1.1192.168.2.5
      Mar 29, 2024 15:13:18.266525030 CET53616141.1.1.1192.168.2.5
      Mar 29, 2024 15:13:18.467210054 CET53554051.1.1.1192.168.2.5
      TimestampSource IPDest IPChecksumCodeType
      Mar 29, 2024 15:12:20.631907940 CET192.168.2.51.1.1.1c20d(Port unreachable)Destination Unreachable
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Mar 29, 2024 15:12:20.437256098 CET192.168.2.51.1.1.10x2550Standard query (0)us.securewebstatus.comA (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.437509060 CET192.168.2.51.1.1.10xb329Standard query (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:20.547095060 CET192.168.2.51.1.1.10xb45eStandard query (0)us.securewebstatus.comA (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.547290087 CET192.168.2.51.1.1.10x768fStandard query (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:21.689168930 CET192.168.2.51.1.1.10xb78Standard query (0)us.securewebstatus.comA (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:21.689528942 CET192.168.2.51.1.1.10xf0e4Standard query (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:22.448431015 CET192.168.2.51.1.1.10x65afStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.449053049 CET192.168.2.51.1.1.10xac9bStandard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Mar 29, 2024 15:12:20.541815042 CET1.1.1.1192.168.2.50xb329No error (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:20.628667116 CET1.1.1.1192.168.2.50x2550No error (0)us.securewebstatus.com104.21.32.77A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.628667116 CET1.1.1.1192.168.2.50x2550No error (0)us.securewebstatus.com172.67.184.104A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.647825003 CET1.1.1.1192.168.2.50xb45eNo error (0)us.securewebstatus.com104.21.32.77A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.647825003 CET1.1.1.1192.168.2.50xb45eNo error (0)us.securewebstatus.com172.67.184.104A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:20.691061974 CET1.1.1.1192.168.2.50x768fNo error (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:21.789845943 CET1.1.1.1192.168.2.50xb78No error (0)us.securewebstatus.com104.21.32.77A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:21.789845943 CET1.1.1.1192.168.2.50xb78No error (0)us.securewebstatus.com172.67.184.104A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:21.790756941 CET1.1.1.1192.168.2.50xf0e4No error (0)us.securewebstatus.com65IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.104A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.147A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.105A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.103A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.106A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.544717073 CET1.1.1.1192.168.2.50x65afNo error (0)www.google.com142.250.31.99A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:22.545298100 CET1.1.1.1192.168.2.50xac9bNo error (0)www.google.com65IN (0x0001)false
      Mar 29, 2024 15:12:35.938442945 CET1.1.1.1192.168.2.50xf54fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Mar 29, 2024 15:12:35.938442945 CET1.1.1.1192.168.2.50xf54fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Mar 29, 2024 15:12:48.701448917 CET1.1.1.1192.168.2.50x5f5bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Mar 29, 2024 15:12:48.701448917 CET1.1.1.1192.168.2.50x5f5bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Mar 29, 2024 15:13:10.856473923 CET1.1.1.1192.168.2.50xaff2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Mar 29, 2024 15:13:10.856473923 CET1.1.1.1192.168.2.50xaff2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • us.securewebstatus.com
      • https:
        • www.bing.com
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.549709104.21.32.774435268C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:20 UTC665OUTGET / HTTP/1.1
      Host: us.securewebstatus.com
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-03-29 14:12:21 UTC302INHTTP/1.1 200 OK
      Date: Fri, 29 Mar 2024 14:12:21 GMT
      Content-Type: text/html
      Transfer-Encoding: chunked
      Connection: close
      Last-Modified: Thu, 09 Nov 2017 20:54:36 GMT
      Accept-Ranges: bytes
      CF-Cache-Status: DYNAMIC
      Server: cloudflare
      CF-RAY: 86c0744faa3287a3-IAD
      alt-svc: h3=":443"; ma=86400
      2024-03-29 14:12:21 UTC5INData Raw: 30 0d 0a 0d 0a
      Data Ascii: 0


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.549712104.21.32.774435268C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:21 UTC600OUTGET /favicon.ico HTTP/1.1
      Host: us.securewebstatus.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://us.securewebstatus.com/
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-03-29 14:12:21 UTC360INHTTP/1.1 200 OK
      Date: Fri, 29 Mar 2024 14:12:21 GMT
      Content-Type: image/x-icon
      Content-Length: 198
      Connection: close
      Last-Modified: Thu, 25 Jun 2020 05:30:34 GMT
      ETag: "c6-5a8e1e43f1280"
      Cache-Control: max-age=14400
      CF-Cache-Status: HIT
      Age: 455
      Accept-Ranges: bytes
      Server: cloudflare
      CF-RAY: 86c074531c346fcd-IAD
      alt-svc: h3=":443"; ma=86400
      2024-03-29 14:12:21 UTC198INData Raw: 00 00 01 00 01 00 10 10 02 00 01 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00
      Data Ascii: (


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.549713104.21.32.774435268C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:22 UTC357OUTGET /favicon.ico HTTP/1.1
      Host: us.securewebstatus.com
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: */*
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: cors
      Sec-Fetch-Dest: empty
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-03-29 14:12:22 UTC359INHTTP/1.1 200 OK
      Date: Fri, 29 Mar 2024 14:12:22 GMT
      Content-Type: image/x-icon
      Content-Length: 198
      Connection: close
      Last-Modified: Thu, 25 Jun 2020 05:30:34 GMT
      ETag: "c6-5a8e1e43f1280"
      Cache-Control: max-age=14400
      CF-Cache-Status: HIT
      Age: 32
      Accept-Ranges: bytes
      Server: cloudflare
      CF-RAY: 86c07456ccbb3b17-IAD
      alt-svc: h3=":443"; ma=86400
      2024-03-29 14:12:22 UTC198INData Raw: 00 00 01 00 01 00 10 10 02 00 01 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00
      Data Ascii: (


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.54971523.221.242.90443
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:24 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-03-29 14:12:24 UTC468INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/073D)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus2-z1
      Cache-Control: public, max-age=147065
      Date: Fri, 29 Mar 2024 14:12:24 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.54971623.221.242.90443
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:24 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-03-29 14:12:24 UTC774INHTTP/1.1 200 OK
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-CID: 7
      X-CCC: US
      X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
      X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
      Content-Type: application/octet-stream
      X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=147045
      Date: Fri, 29 Mar 2024 14:12:24 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-03-29 14:12:24 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Session IDSource IPSource PortDestination IPDestination Port
      5192.168.2.54972323.1.237.91443
      TimestampBytes transferredDirectionData
      2024-03-29 14:12:36 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
      Origin: https://www.bing.com
      Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
      Accept: */*
      Accept-Language: en-CH
      Content-type: text/xml
      X-Agent-DeviceId: 01000A410900D492
      X-BM-CBT: 1696428841
      X-BM-DateFormat: dd/MM/yyyy
      X-BM-DeviceDimensions: 784x984
      X-BM-DeviceDimensionsLogical: 784x984
      X-BM-DeviceScale: 100
      X-BM-DTZ: 120
      X-BM-Market: CH
      X-BM-Theme: 000000;0078d7
      X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
      X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
      X-Device-isOptin: false
      X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
      X-Device-OSSKU: 48
      X-Device-Touch: false
      X-DeviceID: 01000A410900D492
      X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
      X-MSEdge-ExternalExpType: JointCoord
      X-PositionerType: Desktop
      X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
      X-Search-CortanaAvailableCapabilities: None
      X-Search-SafeSearch: Moderate
      X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
      X-UserAgeClass: Unknown
      Accept-Encoding: gzip, deflate, br
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
      Host: www.bing.com
      Content-Length: 2484
      Connection: Keep-Alive
      Cache-Control: no-cache
      Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1711721523929&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
      2024-03-29 14:12:36 UTC1OUTData Raw: 3c
      Data Ascii: <
      2024-03-29 14:12:36 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
      Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
      2024-03-29 14:12:36 UTC479INHTTP/1.1 204 No Content
      Access-Control-Allow-Origin: *
      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
      X-MSEdge-Ref: Ref A: 4B5AE323EC164BE4A2C4C7D897118E4C Ref B: LAX311000110047 Ref C: 2024-03-29T14:12:36Z
      Date: Fri, 29 Mar 2024 14:12:36 GMT
      Connection: close
      Alt-Svc: h3=":443"; ma=93600
      X-CDN-TraceID: 0.57ed0117.1711721556.6ecc921


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:15:12:13
      Start date:29/03/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:15:12:16
      Start date:29/03/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2200,i,4482577667092401635,2642425844030144361,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:15:12:19
      Start date:29/03/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://us.securewebstatus.com"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly