Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://s.ksrndkehqnwntyxlhgto.com

Overview

General Information

Sample URL:http://s.ksrndkehqnwntyxlhgto.com
Analysis ID:1426790
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 2412 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3980 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1712 --field-trial-handle=2040,i,7161388999453672329,14156101956632630469,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6376 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: s.ksrndkehqnwntyxlhgto.comVirustotal: Detection: 5%Perma Link
Source: http://s.ksrndkehqnwntyxlhgto.com/Virustotal: Detection: 5%Perma Link
Source: http://s.ksrndkehqnwntyxlhgto.comVirustotal: Detection: 5%Perma Link
Source: https://s.ksrndkehqnwntyxlhgto.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://s.ksrndkehqnwntyxlhgto.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: s.ksrndkehqnwntyxlhgto.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeDate: Tue, 16 Apr 2024 14:21:37 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 9cef05ab6cc8095e8cbb2721cdabd510.cloudfront.net (CloudFront)X-Amz-Cf-Pop: ATL58-P1X-Amz-Cf-Id: o8ZJ1lw4_YYg23kaxDZ2oUj3ucA52sjgNiMmQzTLo2RIH_tUs-9qcw==
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal56.win@17/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1712 --field-trial-handle=2040,i,7161388999453672329,14156101956632630469,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1712 --field-trial-handle=2040,i,7161388999453672329,14156101956632630469,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://s.ksrndkehqnwntyxlhgto.com5%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
s.ksrndkehqnwntyxlhgto.com5%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://s.ksrndkehqnwntyxlhgto.com/5%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
s.ksrndkehqnwntyxlhgto.com
13.33.4.23
truefalseunknown
www.google.com
64.233.177.147
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    http://s.ksrndkehqnwntyxlhgto.com/falseunknown
    https://s.ksrndkehqnwntyxlhgto.com/false
      unknown
      https://s.ksrndkehqnwntyxlhgto.com/favicon.icofalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        13.33.4.23
        s.ksrndkehqnwntyxlhgto.comUnited States
        7018ATT-INTERNET4USfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        64.233.177.147
        www.google.comUnited States
        15169GOOGLEUSfalse
        13.33.4.42
        unknownUnited States
        7018ATT-INTERNET4USfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1426790
        Start date and time:2024-04-16 16:20:42 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 13s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://s.ksrndkehqnwntyxlhgto.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@17/4@6/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 64.233.176.94, 172.253.124.138, 172.253.124.113, 172.253.124.139, 172.253.124.100, 172.253.124.101, 172.253.124.102, 64.233.176.84, 34.104.35.123, 20.114.59.183, 199.232.210.172, 20.166.126.56, 192.229.211.108, 20.3.187.198, 108.177.122.94
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:XML 1.0 document, ASCII text
        Category:downloaded
        Size (bytes):263
        Entropy (8bit):5.624999275049695
        Encrypted:false
        SSDEEP:6:TMVBd/ZbZjZvKtWRVzj8zJ8CiJUj3joZol/hMWuan:TMHd9BZKtWRizJ8t4joWlSa
        MD5:79629D140056A7C6202F306B5E3DF4CB
        SHA1:800FA01F71AA3965AF46F88109150D6E7CD73C31
        SHA-256:86037FC148FE559527CFE095995A67C22945174A7CA2A9A74CD6BCD06ABAD4D1
        SHA-512:2E48513EC041BFB8D53F9D4C03933CF48A30D0B55D44E4039892363C9076302A26AD896FEFB2AFCBBF11737FF424EB6F25B1E2DC853B4913BA54DDF8FF588363
        Malicious:false
        Reputation:low
        URL:https://s.ksrndkehqnwntyxlhgto.com/favicon.ico
        Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>YVV6NPTVVGD1NSDR</RequestId><HostId>3skDuK6DrExk0YHulkUNDEbz/W6j3uMB/eDNSOWf4TI0Qxvnie11aZyb+YSqTVJmNrDIBLUUNw98o0V9wmh3sRy1YUUiENhk</HostId></Error>
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:ASCII text, with no line terminators
        Category:downloaded
        Size (bytes):20
        Entropy (8bit):3.3841837197791884
        Encrypted:false
        SSDEEP:3:OHKW3Ae:OqOAe
        MD5:DC5BCBF7F9372CCC9AEDB581FE88EDFE
        SHA1:79097FE77C29B4CA590114BDD0331431A1EFC470
        SHA-256:D872E8E4176213EA84EBC76D8FB621C31B4CA116FD0A51258813E804FE110CA4
        SHA-512:1EA2F632E9647FBDE1DA45DB3F295620E3B8228E48C237134DE7ADCE74121F9F12B0A647D27A574B4172A93A4E86B9C1B5868C24ABA5F48253E6283EAB35F6F0
        Malicious:false
        Reputation:low
        URL:https://s.ksrndkehqnwntyxlhgto.com/
        Preview:Nothing to see here.
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 16, 2024 16:21:29.878895998 CEST49675443192.168.2.4173.222.162.32
        Apr 16, 2024 16:21:36.225987911 CEST4973580192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.226598024 CEST4973680192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.330001116 CEST804973513.33.4.23192.168.2.4
        Apr 16, 2024 16:21:36.330163002 CEST804973613.33.4.23192.168.2.4
        Apr 16, 2024 16:21:36.330219030 CEST4973580192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.330384970 CEST4973580192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.330413103 CEST4973680192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.434088945 CEST804973513.33.4.23192.168.2.4
        Apr 16, 2024 16:21:36.434154034 CEST804973513.33.4.23192.168.2.4
        Apr 16, 2024 16:21:36.474421978 CEST4973580192.168.2.413.33.4.23
        Apr 16, 2024 16:21:36.544069052 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.544157028 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.544226885 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.544497967 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.544522047 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.768301964 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.768574953 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.768609047 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.770265102 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.770338058 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.771359921 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.771452904 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.771532059 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.812163115 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.820401907 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.820461988 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.866847038 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.974637032 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.974832058 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:36.975229979 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.975430012 CEST49737443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:36.975455046 CEST4434973713.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.040271997 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.040333033 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.040433884 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.040693045 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.040709019 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.259654045 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.259957075 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.259984970 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.260472059 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.260750055 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.260828972 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.260862112 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.304181099 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.304239035 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.560255051 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.560534000 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:37.560609102 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.570254087 CEST49738443192.168.2.413.33.4.42
        Apr 16, 2024 16:21:37.570280075 CEST4434973813.33.4.42192.168.2.4
        Apr 16, 2024 16:21:39.457473993 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.457560062 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.457740068 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.458064079 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.458097935 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.487314939 CEST49675443192.168.2.4173.222.162.32
        Apr 16, 2024 16:21:39.610093117 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.610178947 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:39.610270977 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.612680912 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.612714052 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:39.685700893 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.686052084 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.686109066 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.687580109 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.687659979 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.689733028 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.689827919 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.737341881 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.737396955 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:39.784202099 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:39.835424900 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:39.835495949 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.838423014 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.838443995 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:39.838663101 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:39.893564939 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.902292013 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:39.948124886 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.039562941 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.039743900 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.039793968 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.039983034 CEST49742443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.040005922 CEST44349742184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.085654974 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.085738897 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.085835934 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.086152077 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.086189032 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.304891109 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.304991007 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.308193922 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.308223963 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.308666945 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.311492920 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.352205038 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.510111094 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.510272026 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.510452986 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.511476040 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.511518955 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:40.512187004 CEST49743443192.168.2.4184.31.62.93
        Apr 16, 2024 16:21:40.512206078 CEST44349743184.31.62.93192.168.2.4
        Apr 16, 2024 16:21:49.738203049 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:49.738502979 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:21:49.738570929 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:51.113023043 CEST49741443192.168.2.464.233.177.147
        Apr 16, 2024 16:21:51.113091946 CEST4434974164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:06.433892965 CEST804973613.33.4.23192.168.2.4
        Apr 16, 2024 16:22:06.434004068 CEST4973680192.168.2.413.33.4.23
        Apr 16, 2024 16:22:07.116090059 CEST4973680192.168.2.413.33.4.23
        Apr 16, 2024 16:22:07.219985962 CEST804973613.33.4.23192.168.2.4
        Apr 16, 2024 16:22:21.440844059 CEST4973580192.168.2.413.33.4.23
        Apr 16, 2024 16:22:21.544461966 CEST804973513.33.4.23192.168.2.4
        Apr 16, 2024 16:22:39.399863005 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:39.399939060 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.400044918 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:39.400321007 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:39.400336981 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.616554976 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.616894960 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:39.616915941 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.617245913 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.618204117 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:39.618264914 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:39.658986092 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:49.611205101 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:49.611294985 CEST4434975164.233.177.147192.168.2.4
        Apr 16, 2024 16:22:49.611361027 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:51.114571095 CEST49751443192.168.2.464.233.177.147
        Apr 16, 2024 16:22:51.114603996 CEST4434975164.233.177.147192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 16, 2024 16:21:34.799387932 CEST53533361.1.1.1192.168.2.4
        Apr 16, 2024 16:21:34.860066891 CEST53505901.1.1.1192.168.2.4
        Apr 16, 2024 16:21:35.463572025 CEST53607031.1.1.1192.168.2.4
        Apr 16, 2024 16:21:36.114727974 CEST5866753192.168.2.41.1.1.1
        Apr 16, 2024 16:21:36.116784096 CEST6234453192.168.2.41.1.1.1
        Apr 16, 2024 16:21:36.222253084 CEST53586671.1.1.1192.168.2.4
        Apr 16, 2024 16:21:36.225311041 CEST53623441.1.1.1192.168.2.4
        Apr 16, 2024 16:21:36.436790943 CEST6164953192.168.2.41.1.1.1
        Apr 16, 2024 16:21:36.437000990 CEST6343953192.168.2.41.1.1.1
        Apr 16, 2024 16:21:36.542526960 CEST53634391.1.1.1192.168.2.4
        Apr 16, 2024 16:21:36.543543100 CEST53616491.1.1.1192.168.2.4
        Apr 16, 2024 16:21:39.349190950 CEST5431453192.168.2.41.1.1.1
        Apr 16, 2024 16:21:39.349481106 CEST4936153192.168.2.41.1.1.1
        Apr 16, 2024 16:21:39.453866005 CEST53493611.1.1.1192.168.2.4
        Apr 16, 2024 16:21:39.453931093 CEST53543141.1.1.1192.168.2.4
        Apr 16, 2024 16:21:52.684230089 CEST53611621.1.1.1192.168.2.4
        Apr 16, 2024 16:21:55.381046057 CEST138138192.168.2.4192.168.2.255
        Apr 16, 2024 16:22:11.545406103 CEST53566701.1.1.1192.168.2.4
        Apr 16, 2024 16:22:34.453944921 CEST53551261.1.1.1192.168.2.4
        Apr 16, 2024 16:22:34.752943039 CEST53651901.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 16, 2024 16:21:36.114727974 CEST192.168.2.41.1.1.10xaa37Standard query (0)s.ksrndkehqnwntyxlhgto.comA (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.116784096 CEST192.168.2.41.1.1.10xee6bStandard query (0)s.ksrndkehqnwntyxlhgto.com65IN (0x0001)false
        Apr 16, 2024 16:21:36.436790943 CEST192.168.2.41.1.1.10x19f6Standard query (0)s.ksrndkehqnwntyxlhgto.comA (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.437000990 CEST192.168.2.41.1.1.10xfc27Standard query (0)s.ksrndkehqnwntyxlhgto.com65IN (0x0001)false
        Apr 16, 2024 16:21:39.349190950 CEST192.168.2.41.1.1.10x26b8Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.349481106 CEST192.168.2.41.1.1.10xc886Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 16, 2024 16:21:36.222253084 CEST1.1.1.1192.168.2.40xaa37No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.23A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.222253084 CEST1.1.1.1192.168.2.40xaa37No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.45A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.222253084 CEST1.1.1.1192.168.2.40xaa37No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.40A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.222253084 CEST1.1.1.1192.168.2.40xaa37No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.42A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.543543100 CEST1.1.1.1192.168.2.40x19f6No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.42A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.543543100 CEST1.1.1.1192.168.2.40x19f6No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.40A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.543543100 CEST1.1.1.1192.168.2.40x19f6No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.23A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:36.543543100 CEST1.1.1.1192.168.2.40x19f6No error (0)s.ksrndkehqnwntyxlhgto.com13.33.4.45A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453866005 CEST1.1.1.1192.168.2.40xc886No error (0)www.google.com65IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:39.453931093 CEST1.1.1.1192.168.2.40x26b8No error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:52.759280920 CEST1.1.1.1192.168.2.40xc3e3No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:52.759280920 CEST1.1.1.1192.168.2.40xc3e3No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Apr 16, 2024 16:21:53.681848049 CEST1.1.1.1192.168.2.40x58e3No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 16:21:53.681848049 CEST1.1.1.1192.168.2.40x58e3No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 16:22:07.795367956 CEST1.1.1.1192.168.2.40x1923No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 16:22:07.795367956 CEST1.1.1.1192.168.2.40x1923No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 16:22:26.718605995 CEST1.1.1.1192.168.2.40x39efNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 16:22:26.718605995 CEST1.1.1.1192.168.2.40x39efNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 16, 2024 16:22:47.499514103 CEST1.1.1.1192.168.2.40x8852No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 16, 2024 16:22:47.499514103 CEST1.1.1.1192.168.2.40x8852No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • s.ksrndkehqnwntyxlhgto.com
        • https:
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973513.33.4.23803980C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 16, 2024 16:21:36.330384970 CEST441OUTGET / HTTP/1.1
        Host: s.ksrndkehqnwntyxlhgto.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Apr 16, 2024 16:21:36.434154034 CEST576INHTTP/1.1 301 Moved Permanently
        Server: CloudFront
        Date: Tue, 16 Apr 2024 14:21:36 GMT
        Content-Type: text/html
        Content-Length: 167
        Connection: keep-alive
        Location: https://s.ksrndkehqnwntyxlhgto.com/
        X-Cache: Redirect from cloudfront
        Via: 1.1 fdf00b190a061de7e2517d80e4d54e0e.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: ATL58-P1
        X-Amz-Cf-Id: IQuPMNz5rrOS14qeN7ZBEpsF6fWuybfDPLRlo1VK06PXkjVczYe82A==
        Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 43 6c 6f 75 64 46 72 6f 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
        Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>CloudFront</center></body></html>
        Apr 16, 2024 16:22:21.440844059 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973713.33.4.424433980C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-16 14:21:36 UTC669OUTGET / HTTP/1.1
        Host: s.ksrndkehqnwntyxlhgto.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-04-16 14:21:36 UTC481INHTTP/1.1 200 OK
        Content-Type: text/plain
        Content-Length: 20
        Connection: close
        Date: Tue, 16 Apr 2024 02:58:38 GMT
        Last-Modified: Wed, 13 Jun 2018 16:12:20 GMT
        ETag: "dc5bcbf7f9372ccc9aedb581fe88edfe"
        x-amz-version-id: null
        Accept-Ranges: bytes
        Server: AmazonS3
        X-Cache: Hit from cloudfront
        Via: 1.1 71c9229c52c40e2117e67076e35eb6dc.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: ATL58-P1
        X-Amz-Cf-Id: hK-5lrekTMEvkA51NSXdABZRKzXIIkbivbDhcjegXk9egI7N12W1Vw==
        Age: 40979
        2024-04-16 14:21:36 UTC20INData Raw: 4e 6f 74 68 69 6e 67 20 74 6f 20 73 65 65 20 68 65 72 65 2e
        Data Ascii: Nothing to see here.


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44973813.33.4.424433980C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-16 14:21:37 UTC608OUTGET /favicon.ico HTTP/1.1
        Host: s.ksrndkehqnwntyxlhgto.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://s.ksrndkehqnwntyxlhgto.com/
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-04-16 14:21:37 UTC357INHTTP/1.1 403 Forbidden
        Content-Type: application/xml
        Transfer-Encoding: chunked
        Connection: close
        Date: Tue, 16 Apr 2024 14:21:37 GMT
        Server: AmazonS3
        X-Cache: Error from cloudfront
        Via: 1.1 9cef05ab6cc8095e8cbb2721cdabd510.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: ATL58-P1
        X-Amz-Cf-Id: o8ZJ1lw4_YYg23kaxDZ2oUj3ucA52sjgNiMmQzTLo2RIH_tUs-9qcw==
        2024-04-16 14:21:37 UTC270INData Raw: 31 30 37 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 59 56 56 36 4e 50 54 56 56 47 44 31 4e 53 44 52 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 33 73 6b 44 75 4b 36 44 72 45 78 6b 30 59 48 75 6c 6b 55 4e 44 45 62 7a 2f 57 36 6a 33 75 4d 42 2f 65 44 4e 53 4f 57 66 34 54 49 30 51 78 76 6e 69 65 31 31 61 5a 79 62 2b 59 53 71 54 56 4a 6d 4e 72 44 49 42 4c 55 55 4e 77 39 38 6f 30 56 39 77 6d 68 33 73 52 79 31 59 55 55 69 45 4e 68 6b 3c 2f 48 6f
        Data Ascii: 107<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>YVV6NPTVVGD1NSDR</RequestId><HostId>3skDuK6DrExk0YHulkUNDEbz/W6j3uMB/eDNSOWf4TI0Qxvnie11aZyb+YSqTVJmNrDIBLUUNw98o0V9wmh3sRy1YUUiENhk</Ho
        2024-04-16 14:21:37 UTC5INData Raw: 30 0d 0a 0d 0a
        Data Ascii: 0


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.449742184.31.62.93443
        TimestampBytes transferredDirectionData
        2024-04-16 14:21:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-16 14:21:40 UTC468INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/079C)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus2-z1
        Cache-Control: public, max-age=146560
        Date: Tue, 16 Apr 2024 14:21:39 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.449743184.31.62.93443
        TimestampBytes transferredDirectionData
        2024-04-16 14:21:40 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-16 14:21:40 UTC805INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/0778)
        X-CID: 11
        X-CCC: US
        X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
        X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
        Content-Type: application/octet-stream
        X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
        Cache-Control: public, max-age=146496
        Date: Tue, 16 Apr 2024 14:21:40 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-16 14:21:40 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:16:21:32
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:16:21:33
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1712 --field-trial-handle=2040,i,7161388999453672329,14156101956632630469,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:16:21:35
        Start date:16/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly