Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0

Overview

General Information

Sample URL:http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0
Analysis ID:1427035
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 5688 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,9440622862132702257,4919387107100475336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0 HTTP/1.1Host: x01.aidata.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0&bounce=1 HTTP/1.1Host: x01.aidata.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: x01.aidata.io
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713301478051&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/6@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,9440622862132702257,4919387107100475336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,9440622862132702257,4919387107100475336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
64.233.185.104
truefalse
    high
    x01.aidata.io
    89.108.120.76
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0false
          unknown
          http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0&bounce=1false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            89.108.120.76
            x01.aidata.ioRussian Federation
            43146AGAVA3RUfalse
            64.233.185.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.5
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1427035
            Start date and time:2024-04-16 23:04:03 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 6s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean1.win@16/6@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 173.194.219.94, 173.194.219.102, 173.194.219.113, 173.194.219.139, 173.194.219.100, 173.194.219.138, 173.194.219.101, 74.125.138.84, 34.104.35.123, 20.114.59.183, 72.21.81.240, 192.229.211.108, 13.95.31.18, 20.242.39.171, 40.68.123.157, 172.253.124.94, 20.12.23.50
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 20:04:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9838282247521812
            Encrypted:false
            SSDEEP:48:8xdoTMgVHKidAKZdA19ehwiZUklqehAy+3:88vC/y
            MD5:C9301DCF9C433B03D8F0963473F00482
            SHA1:D0059CAE86A75FF0B5776072D6FB9E0D8D8D4DD9
            SHA-256:8A07C940EB00D420EDBD7F19C57BC17FD9491CF24291152095E780127EEE7BAC
            SHA-512:A4CAF05D8B7FACD1289D73E6EC75B47A6A2DDAB602802106C13E6C1146DFD2738BA462E632EA5DCEF22154F645AB4F85D7151F241630D371A11D026B5B8DF4D4
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....,..A...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 20:04:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.9992010810351233
            Encrypted:false
            SSDEEP:48:8AdoTMgVHKidAKZdA1weh/iZUkAQkqehvy+2:8rvY9Q+y
            MD5:236CC83CE08262CFDFE9CCDA8F21C9CF
            SHA1:F622001C489E8E05DCC8088D2353DAF1B08835A4
            SHA-256:DE526183650631C8E8424A5BB1FECF32DDEA463D877F6404CCD1682F8879FF65
            SHA-512:4BFDE54EBA0420F4192097F7E318BA9986E135545922451E6E8177490C3094761BC9D7CD3128D42E660690D66BED8A875A8CC151D8327D904E9A481DE9BAA624
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,........A...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2693
            Entropy (8bit):4.009592270502315
            Encrypted:false
            SSDEEP:48:8xJdoTMgsHKidAKZdA14tseh7sFiZUkmgqeh7sVy+BX:8xUvPnLy
            MD5:1B5EE84C846F99E8A6CEB4E9A642583B
            SHA1:D2D6DDCA20A9DF46A42629D04B974ADE36B23D3C
            SHA-256:8972A3FF952BFA5119B52DBAE14E60B949DA847CC3A91F92C4864D888C03E6D4
            SHA-512:609021EFF7CD32350AEFCD6DDA4A6E10E0D5E9A26A631C19312A35FAD37FB30AB8525F84B7CFF6657347852A02DC3A68D228CAD19DCF628FCDCDEA82A63AF541
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 20:04:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.9966815197360446
            Encrypted:false
            SSDEEP:48:8ZdoTMgVHKidAKZdA1vehDiZUkwqehjy+R:8EvDty
            MD5:D50202B445B5505E1CBED15B787155BE
            SHA1:846766E99366B5142AA8371FD823AC9A9BC44F9A
            SHA-256:3A13EADE9B0C3138A552C0335BDA7889DD2BB73F302969B20CE7E6A0299523F2
            SHA-512:632C0E9F5B0E0D20FC02FB2C1A5ED1F6DE8339E4FE6BFF45E5859B6750B476A1E1F8D96B04A5A4DD2B1DD7953D048A62A54274302B0A00048603757463714930
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....u|.A...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 20:04:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.9839699216324895
            Encrypted:false
            SSDEEP:48:8pdoTMgVHKidAKZdA1hehBiZUk1W1qehBy+C:80vT9hy
            MD5:1D2A202A40B271515840BF54909E531D
            SHA1:7AFDC0CA14A3961C4EA44489FE082571BCCA8B12
            SHA-256:CEEF9DC005E42DCDC6627F46AE7BEE56E80F32F24D4B45D90FD5A85E83726DEF
            SHA-512:D9DCC36A5B26575CD450C78C1B7BE3296A1FB3F839A8077D7AAA82D1EE67B4F0C68874FDE794F6253FF8F0347644568AC9FE77FCD1055EB9A78A43B7266685F4
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.......A...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 20:04:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2683
            Entropy (8bit):3.9949874407188553
            Encrypted:false
            SSDEEP:48:8aQdoTMgVHKidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8abvDT/TbxWOvTbLy7T
            MD5:00904B9892A59464F24155E6C1FD6596
            SHA1:74B1481CEDF84A1D4D4E84E219B635BF9F06BEFA
            SHA-256:F7BE19F6D8CF39F489DCD7049C672DF6B90E869832A37F186AD4E25E32FE857E
            SHA-512:251131C818C7E226843BD2ABFD9F91FF1B29B8CDBEBD2B9CBF38614957959EAC1216252BAABF38E9FA3682011F7E54620D8622CC2773503E08A742526FD62886
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....y.o.A...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 16, 2024 23:04:48.058944941 CEST49675443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:48.078583002 CEST49674443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:48.156712055 CEST49673443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:56.171813011 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.172781944 CEST4971380192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.338102102 CEST4971480192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.406115055 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.406297922 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.406440020 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.408282995 CEST804971389.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.408473969 CEST4971380192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.578685045 CEST804971489.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.579035044 CEST4971480192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.640640974 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.640675068 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.643858910 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.878806114 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:04:56.981405020 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:04:56.992784977 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:56.992868900 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:56.993057966 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:56.993171930 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:56.993196011 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.222311020 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.222635984 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:57.222696066 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.224363089 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.224495888 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:57.225832939 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:57.225935936 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.288786888 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:57.288816929 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:04:57.335386992 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:04:57.679332972 CEST49674443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:57.757410049 CEST49675443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:57.757438898 CEST49673443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:58.515383959 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.515464067 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.515568972 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.517358065 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.517438889 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.742482901 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.742681026 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.745321989 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.745373964 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.745807886 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.784738064 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.828186035 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.941484928 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.941569090 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.941914082 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.942260981 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.942261934 CEST49716443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.942323923 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.942363024 CEST4434971623.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.980710983 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.980798006 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:58.980895042 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.981154919 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:58.981175900 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.151691914 CEST4434970323.1.237.91192.168.2.5
            Apr 16, 2024 23:04:59.151917934 CEST49703443192.168.2.523.1.237.91
            Apr 16, 2024 23:04:59.197402000 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.197654009 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.199153900 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.199177980 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.199515104 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.200545073 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.248132944 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.407968998 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.408164978 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.408221006 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.441943884 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.441975117 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:04:59.441992044 CEST49717443192.168.2.523.201.212.130
            Apr 16, 2024 23:04:59.441999912 CEST4434971723.201.212.130192.168.2.5
            Apr 16, 2024 23:05:06.821517944 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:05:06.821599007 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:05:07.232425928 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:05:07.232564926 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:05:07.232753038 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:07.998120070 CEST4971280192.168.2.589.108.120.76
            Apr 16, 2024 23:05:07.998250008 CEST49715443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:07.998292923 CEST4434971564.233.185.104192.168.2.5
            Apr 16, 2024 23:05:08.232057095 CEST804971289.108.120.76192.168.2.5
            Apr 16, 2024 23:05:09.424096107 CEST49703443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.424249887 CEST49703443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.426109076 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.426156044 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.426246881 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.491158962 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.491185904 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.576057911 CEST4434970323.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.576219082 CEST4434970323.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.806477070 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.806559086 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.839189053 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.839231968 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.840507030 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.840564013 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.841133118 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.841191053 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:09.841367960 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:09.841372967 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:10.473280907 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:10.473351955 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:10.473372936 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:10.473417044 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:10.473843098 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:10.473889112 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:10.473969936 CEST4434972223.1.237.91192.168.2.5
            Apr 16, 2024 23:05:10.474015951 CEST49722443192.168.2.523.1.237.91
            Apr 16, 2024 23:05:41.413484097 CEST4971380192.168.2.589.108.120.76
            Apr 16, 2024 23:05:41.585314989 CEST4971480192.168.2.589.108.120.76
            Apr 16, 2024 23:05:41.652406931 CEST804971389.108.120.76192.168.2.5
            Apr 16, 2024 23:05:41.841038942 CEST804971489.108.120.76192.168.2.5
            Apr 16, 2024 23:05:56.625188112 CEST804971389.108.120.76192.168.2.5
            Apr 16, 2024 23:05:56.625261068 CEST4971380192.168.2.589.108.120.76
            Apr 16, 2024 23:05:56.737097025 CEST804971489.108.120.76192.168.2.5
            Apr 16, 2024 23:05:56.737221956 CEST4971480192.168.2.589.108.120.76
            Apr 16, 2024 23:05:56.936825037 CEST4971380192.168.2.589.108.120.76
            Apr 16, 2024 23:05:56.936865091 CEST4971480192.168.2.589.108.120.76
            Apr 16, 2024 23:05:56.937849998 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:56.937930107 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:56.939099073 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:56.939511061 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:56.939549923 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:57.157212019 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:57.158373117 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:57.158409119 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:57.158878088 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:57.160290956 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:05:57.160377979 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:05:57.176064014 CEST804971389.108.120.76192.168.2.5
            Apr 16, 2024 23:05:57.192606926 CEST804971489.108.120.76192.168.2.5
            Apr 16, 2024 23:05:57.210319996 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:06:07.203952074 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:06:07.204039097 CEST4434972764.233.185.104192.168.2.5
            Apr 16, 2024 23:06:07.204269886 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:06:07.993906975 CEST49727443192.168.2.564.233.185.104
            Apr 16, 2024 23:06:07.993940115 CEST4434972764.233.185.104192.168.2.5
            TimestampSource PortDest PortSource IPDest IP
            Apr 16, 2024 23:04:53.182714939 CEST53578071.1.1.1192.168.2.5
            Apr 16, 2024 23:04:53.399549007 CEST53535361.1.1.1192.168.2.5
            Apr 16, 2024 23:04:54.186491966 CEST53541741.1.1.1192.168.2.5
            Apr 16, 2024 23:04:56.063530922 CEST6185953192.168.2.51.1.1.1
            Apr 16, 2024 23:04:56.063647985 CEST5998953192.168.2.51.1.1.1
            Apr 16, 2024 23:04:56.168410063 CEST53599891.1.1.1192.168.2.5
            Apr 16, 2024 23:04:56.169256926 CEST53618591.1.1.1192.168.2.5
            Apr 16, 2024 23:04:56.886671066 CEST6499353192.168.2.51.1.1.1
            Apr 16, 2024 23:04:56.886770964 CEST5387153192.168.2.51.1.1.1
            Apr 16, 2024 23:04:56.991669893 CEST53649931.1.1.1192.168.2.5
            Apr 16, 2024 23:04:56.991731882 CEST53538711.1.1.1192.168.2.5
            Apr 16, 2024 23:05:12.024336100 CEST53622051.1.1.1192.168.2.5
            Apr 16, 2024 23:05:31.035604000 CEST53628111.1.1.1192.168.2.5
            Apr 16, 2024 23:05:52.474791050 CEST53602131.1.1.1192.168.2.5
            Apr 16, 2024 23:05:53.942986012 CEST53646811.1.1.1192.168.2.5
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 16, 2024 23:04:56.063530922 CEST192.168.2.51.1.1.10xaf85Standard query (0)x01.aidata.ioA (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.063647985 CEST192.168.2.51.1.1.10x39cStandard query (0)x01.aidata.io65IN (0x0001)false
            Apr 16, 2024 23:04:56.886671066 CEST192.168.2.51.1.1.10x73bStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.886770964 CEST192.168.2.51.1.1.10xd6fdStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 16, 2024 23:04:56.169256926 CEST1.1.1.1192.168.2.50xaf85No error (0)x01.aidata.io89.108.120.76A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.169256926 CEST1.1.1.1192.168.2.50xaf85No error (0)x01.aidata.io89.108.119.28A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.169256926 CEST1.1.1.1192.168.2.50xaf85No error (0)x01.aidata.io89.108.119.43A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.169256926 CEST1.1.1.1192.168.2.50xaf85No error (0)x01.aidata.io89.108.120.68A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.104A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.147A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.99A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.106A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.105A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991669893 CEST1.1.1.1192.168.2.50x73bNo error (0)www.google.com64.233.185.103A (IP address)IN (0x0001)false
            Apr 16, 2024 23:04:56.991731882 CEST1.1.1.1192.168.2.50xd6fdNo error (0)www.google.com65IN (0x0001)false
            Apr 16, 2024 23:05:09.080513000 CEST1.1.1.1192.168.2.50xfba3No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 16, 2024 23:05:09.080513000 CEST1.1.1.1192.168.2.50xfba3No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 16, 2024 23:05:22.003925085 CEST1.1.1.1192.168.2.50x9e4eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 16, 2024 23:05:22.003925085 CEST1.1.1.1192.168.2.50x9e4eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 16, 2024 23:05:46.128346920 CEST1.1.1.1192.168.2.50x8093No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 16, 2024 23:05:46.128346920 CEST1.1.1.1192.168.2.50x8093No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • https:
              • www.bing.com
            • x01.aidata.io
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.54971289.108.120.76805548C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 16, 2024 23:04:56.406440020 CEST487OUTGET /0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0 HTTP/1.1
            Host: x01.aidata.io
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Apr 16, 2024 23:04:56.640675068 CEST726INHTTP/1.1 302 Found
            Server: nginx
            Date: Tue, 16 Apr 2024 21:04:56 GMT
            Content-Length: 0
            Connection: keep-alive
            Location: http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0&bounce=1
            Expires: Tue, 16 Apr 2024 21:04:55 GMT
            Cache-Control: no-cache
            Access-Control-Allow-Methods: GET, POST
            Pragma: no-cache
            Cache-Control: no-store, must-revalidate, post-check=0, pre-check=0
            Last-Modified: Tue, 16 Apr 2024 21:04:55 GMT
            Set-Cookie: __upin=7aRwe65JVZr7n3e0fgK3GQ;domain=.aidata.io;path=/;max-age=63072000;SameSite=None
            Set-Cookie: __upints=1713301496;domain=.aidata.io;path=/;max-age=63072000;SameSite=None
            P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA'
            Apr 16, 2024 23:04:56.643858910 CEST496OUTGET /0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0&bounce=1 HTTP/1.1
            Host: x01.aidata.io
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Apr 16, 2024 23:04:56.878806114 CEST611INHTTP/1.1 204 No Content
            Server: nginx
            Date: Tue, 16 Apr 2024 21:04:56 GMT
            Connection: keep-alive
            Expires: Tue, 16 Apr 2024 21:04:55 GMT
            Cache-Control: no-cache
            Access-Control-Allow-Methods: GET, POST
            Pragma: no-cache
            Cache-Control: no-store, must-revalidate, post-check=0, pre-check=0
            Last-Modified: Tue, 16 Apr 2024 21:04:55 GMT
            Set-Cookie: __upin=bDXYnVdJiL52BY2v4Sq5ig;domain=.aidata.io;path=/;max-age=63072000;SameSite=None
            Set-Cookie: __upints=1713301496;domain=.aidata.io;path=/;max-age=63072000;SameSite=None
            P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA'


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.54971389.108.120.76805548C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 16, 2024 23:05:41.413484097 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.54971489.108.120.76805548C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 16, 2024 23:05:41.585314989 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.54971623.201.212.130443
            TimestampBytes transferredDirectionData
            2024-04-16 21:04:58 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-16 21:04:58 UTC468INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/079C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=122271
            Date: Tue, 16 Apr 2024 21:04:58 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.54971723.201.212.130443
            TimestampBytes transferredDirectionData
            2024-04-16 21:04:59 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-16 21:04:59 UTC531INHTTP/1.1 200 OK
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Content-Type: application/octet-stream
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=122313
            Date: Tue, 16 Apr 2024 21:04:59 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-16 21:04:59 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination Port
            2192.168.2.54972223.1.237.91443
            TimestampBytes transferredDirectionData
            2024-04-16 21:05:09 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
            Origin: https://www.bing.com
            Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
            Accept: */*
            Accept-Language: en-CH
            Content-type: text/xml
            X-Agent-DeviceId: 01000A410900D492
            X-BM-CBT: 1696428841
            X-BM-DateFormat: dd/MM/yyyy
            X-BM-DeviceDimensions: 784x984
            X-BM-DeviceDimensionsLogical: 784x984
            X-BM-DeviceScale: 100
            X-BM-DTZ: 120
            X-BM-Market: CH
            X-BM-Theme: 000000;0078d7
            X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
            X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
            X-Device-isOptin: false
            X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
            X-Device-OSSKU: 48
            X-Device-Touch: false
            X-DeviceID: 01000A410900D492
            X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
            X-MSEdge-ExternalExpType: JointCoord
            X-PositionerType: Desktop
            X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
            X-Search-CortanaAvailableCapabilities: None
            X-Search-SafeSearch: Moderate
            X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
            X-UserAgeClass: Unknown
            Accept-Encoding: gzip, deflate, br
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
            Host: www.bing.com
            Content-Length: 2484
            Connection: Keep-Alive
            Cache-Control: no-cache
            Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713301478051&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
            2024-04-16 21:05:09 UTC1OUTData Raw: 3c
            Data Ascii: <
            2024-04-16 21:05:09 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
            Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
            2024-04-16 21:05:10 UTC278INHTTP/1.1 200 OK
            X-MSEdge-Ref: Ref A: 8ED93070D1B949ED8394362791CA5723 Ref B: LAX311000113035 Ref C: 2024-04-16T21:05:10Z
            Date: Tue, 16 Apr 2024 21:05:10 GMT
            Content-Length: 875
            Connection: close
            Alt-Svc: h3=":443"; ma=93600
            X-CDN-TraceID: 0.57ed0117.1713301509.229b25e
            2024-04-16 21:05:10 UTC875INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 27 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 27 20 27 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 74 72 61 6e 73 69 74 69 6f 6e 61 6c 2e 64 74 64 27 3e 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 27 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 27 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 27 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 27 20 68 74 74 70 2d 65 71 75 69 76 3d 27 63 6f 6e 74 65 6e 74 2d 74 79 70 65 27 2f 3e 3c 73 74 79 6c 65 20 74 79 70 65 3d 27 74 65 78 74
            Data Ascii: <!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Transitional//EN' 'http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd'><html xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html; charset=utf-8' http-equiv='content-type'/><style type='text


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:23:04:48
            Start date:16/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:23:04:51
            Start date:16/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,9440622862132702257,4919387107100475336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:23:04:54
            Start date:16/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x01.aidata.io/0.gif?pid=LOTAME&id=cebefe6c16bba2647ad2a25a6da79803&gdpr=0"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly