Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://Tigfunds.com&d=DwQFaQ

Overview

General Information

Sample URL:http://Tigfunds.com&d=DwQFaQ
Analysis ID:1426759
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1060 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=2528,i,3914063338842899733,8597625769034651513,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6400 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Tigfunds.com&d=DwQFaQ" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: classification engineClassification label: clean0.win@20/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=2528,i,3914063338842899733,8597625769034651513,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Tigfunds.com&d=DwQFaQ"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=2528,i,3914063338842899733,8597625769034651513,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
64.233.185.100
truefalse
    high
    www.google.com
    64.233.176.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        64.233.176.105
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.17
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1426759
        Start date and time:2024-04-16 15:31:52 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 41s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://Tigfunds.com&d=DwQFaQ
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:9
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@20/0@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.253.124.94, 108.177.122.84, 64.233.176.101, 64.233.176.113, 64.233.176.139, 64.233.176.102, 64.233.176.138, 64.233.176.100, 34.104.35.123, 40.127.169.103, 23.40.205.67, 23.40.205.59, 23.40.205.49, 23.40.205.65, 23.40.205.43, 23.40.205.8, 23.40.205.26, 192.229.211.108, 52.165.164.15, 13.85.23.206, 108.177.122.94
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 16, 2024 15:32:39.990879059 CEST49675443192.168.2.4173.222.162.32
        Apr 16, 2024 15:32:49.631975889 CEST49675443192.168.2.4173.222.162.32
        Apr 16, 2024 15:32:54.044621944 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.044708967 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.044805050 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.045201063 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.045236111 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.262516975 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.285598993 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.285628080 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.286739111 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.286808014 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.291570902 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.291646004 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.333647013 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.333715916 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:32:54.380398989 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:32:54.604269028 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.604304075 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:54.604510069 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.608647108 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.608663082 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:54.826200008 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:54.826360941 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.832123041 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.832156897 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:54.832411051 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:54.880374908 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.913855076 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:54.960115910 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.037741899 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.037817001 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.038060904 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.038333893 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.038363934 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.038466930 CEST49739443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.038474083 CEST4434973923.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.073307037 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.073394060 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.073522091 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.073944092 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.073978901 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.286036968 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.286134958 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.288042068 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.288069963 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.288315058 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.289678097 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.336126089 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.494117975 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.494198084 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.494261980 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.496840954 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.496840954 CEST49740443192.168.2.423.36.68.63
        Apr 16, 2024 15:32:55.496872902 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:32:55.496901035 CEST4434974023.36.68.63192.168.2.4
        Apr 16, 2024 15:33:04.207479000 CEST4972380192.168.2.4199.232.214.172
        Apr 16, 2024 15:33:04.278583050 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:04.278654099 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:04.278743029 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:04.310977936 CEST8049723199.232.214.172192.168.2.4
        Apr 16, 2024 15:33:04.311009884 CEST8049723199.232.214.172192.168.2.4
        Apr 16, 2024 15:33:04.311083078 CEST4972380192.168.2.4199.232.214.172
        Apr 16, 2024 15:33:05.775470018 CEST49738443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:05.775494099 CEST4434973864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:53.162405014 CEST4972480192.168.2.4199.232.210.172
        Apr 16, 2024 15:33:53.266097069 CEST8049724199.232.210.172192.168.2.4
        Apr 16, 2024 15:33:53.266123056 CEST8049724199.232.210.172192.168.2.4
        Apr 16, 2024 15:33:53.266206980 CEST4972480192.168.2.4199.232.210.172
        Apr 16, 2024 15:33:53.804282904 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:53.804342031 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:53.804462910 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:53.804735899 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:53.804749966 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:54.021929979 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:54.022275925 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:54.022308111 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:54.023413897 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:54.023807049 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:33:54.023977995 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:33:54.068444967 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:34:04.017420053 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:34:04.017493010 CEST4434974864.233.176.105192.168.2.4
        Apr 16, 2024 15:34:04.017556906 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:34:05.774149895 CEST49748443192.168.2.464.233.176.105
        Apr 16, 2024 15:34:05.774188995 CEST4434974864.233.176.105192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 16, 2024 15:32:49.687912941 CEST53559881.1.1.1192.168.2.4
        Apr 16, 2024 15:32:49.692831039 CEST53597451.1.1.1192.168.2.4
        Apr 16, 2024 15:32:50.287506104 CEST53507651.1.1.1192.168.2.4
        Apr 16, 2024 15:32:51.688116074 CEST6228653192.168.2.48.8.8.8
        Apr 16, 2024 15:32:51.688555002 CEST5976153192.168.2.41.1.1.1
        Apr 16, 2024 15:32:51.792933941 CEST53597611.1.1.1192.168.2.4
        Apr 16, 2024 15:32:51.792953968 CEST53622868.8.8.8192.168.2.4
        Apr 16, 2024 15:32:53.749294043 CEST5716453192.168.2.41.1.1.1
        Apr 16, 2024 15:32:53.749605894 CEST5538553192.168.2.41.1.1.1
        Apr 16, 2024 15:32:53.853724957 CEST53571641.1.1.1192.168.2.4
        Apr 16, 2024 15:32:53.853849888 CEST53553851.1.1.1192.168.2.4
        Apr 16, 2024 15:33:04.763456106 CEST138138192.168.2.4192.168.2.255
        Apr 16, 2024 15:33:07.436932087 CEST53565681.1.1.1192.168.2.4
        Apr 16, 2024 15:33:26.456442118 CEST53631661.1.1.1192.168.2.4
        Apr 16, 2024 15:33:49.146095037 CEST53568581.1.1.1192.168.2.4
        Apr 16, 2024 15:33:49.640901089 CEST53569031.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 16, 2024 15:32:51.688116074 CEST192.168.2.48.8.8.80x7583Standard query (0)google.comA (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.688555002 CEST192.168.2.41.1.1.10xd30aStandard query (0)google.comA (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.749294043 CEST192.168.2.41.1.1.10x1a28Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.749605894 CEST192.168.2.41.1.1.10x1a82Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.100A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.113A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.101A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.139A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.102A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792933941 CEST1.1.1.1192.168.2.40xd30aNo error (0)google.com64.233.185.138A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:51.792953968 CEST8.8.8.8192.168.2.40x7583No error (0)google.com142.250.217.174A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.105A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.103A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.99A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.147A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.104A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853724957 CEST1.1.1.1192.168.2.40x1a28No error (0)www.google.com64.233.176.106A (IP address)IN (0x0001)false
        Apr 16, 2024 15:32:53.853849888 CEST1.1.1.1192.168.2.40x1a82No error (0)www.google.com65IN (0x0001)false
        Apr 16, 2024 15:33:04.931163073 CEST1.1.1.1192.168.2.40x9e6aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 15:33:04.931163073 CEST1.1.1.1192.168.2.40x9e6aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 15:33:17.212388039 CEST1.1.1.1192.168.2.40x1b86No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 15:33:17.212388039 CEST1.1.1.1192.168.2.40x1b86No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 15:33:41.548873901 CEST1.1.1.1192.168.2.40x59d5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 15:33:41.548873901 CEST1.1.1.1192.168.2.40x59d5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 15:34:01.908040047 CEST1.1.1.1192.168.2.40xa307No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 15:34:01.908040047 CEST1.1.1.1192.168.2.40xa307No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973923.36.68.63443
        TimestampBytes transferredDirectionData
        2024-04-16 13:32:54 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-16 13:32:55 UTC436INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (dcd/7D15)
        X-CID: 11
        Cache-Control: public, max-age=149373
        Date: Tue, 16 Apr 2024 13:32:54 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974023.36.68.63443
        TimestampBytes transferredDirectionData
        2024-04-16 13:32:55 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-16 13:32:55 UTC456INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (dcd/7D15)
        X-CID: 11
        Cache-Control: public, max-age=149372
        Date: Tue, 16 Apr 2024 13:32:55 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-16 13:32:55 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:15:32:43
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:15:32:47
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2556 --field-trial-handle=2528,i,3914063338842899733,8597625769034651513,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:15:32:50
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Tigfunds.com&d=DwQFaQ"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly