Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://prod.sf.vfcarbon.com

Overview

General Information

Sample URL:https://prod.sf.vfcarbon.com
Analysis ID:1427121
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2696 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2016,i,16729827099064400818,9882852457364780708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prod.sf.vfcarbon.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://prod.sf.vfcarbon.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: prod.sf.vfcarbon.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: prod.sf.vfcarbon.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://prod.sf.vfcarbon.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: prod.sf.vfcarbon.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2016,i,16729827099064400818,9882852457364780708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prod.sf.vfcarbon.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2016,i,16729827099064400818,9882852457364780708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://prod.sf.vfcarbon.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
prod.sf.vfcarbon.com
3.234.113.63
truefalse
    unknown
    www.google.com
    142.250.105.147
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://prod.sf.vfcarbon.com/false
          unknown
          https://prod.sf.vfcarbon.com/favicon.icofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            3.234.113.63
            prod.sf.vfcarbon.comUnited States
            14618AMAZON-AESUSfalse
            142.250.105.147
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1427121
            Start date and time:2024-04-17 02:50:51 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 15s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://prod.sf.vfcarbon.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:9
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/4@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.124.94, 64.233.185.84, 142.250.105.101, 142.250.105.102, 142.250.105.138, 142.250.105.100, 142.250.105.113, 142.250.105.139, 34.104.35.123, 52.165.165.26, 72.21.81.240, 192.229.211.108, 13.95.31.18, 20.242.39.171, 173.194.219.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):632
            Entropy (8bit):4.72894982842216
            Encrypted:false
            SSDEEP:12:TvmwXHVI9BnzlItmwt5r8INGlTF5TF5TF5TF5TF5TFK:DXHUBnRkKTPTPTPTPTPTc
            MD5:6BE05D19E4CA80EB3EF0A7F16F937F13
            SHA1:E589F353292174E34107D80E22C3EB7B3205B9E2
            SHA-256:D39229CC33510B8C095AEC8500CAFF6DC3F76F8FC1B7C8E1564DE22D8389900D
            SHA-512:05DFE91CEC34CB340858E83ED5236FC8095D5A148CC22BCD0B18DCC59CC2875358B4377F9347D89C8D862D47FEDE6D5326541684DDD42421A5A59E5810232CB6
            Malicious:false
            Reputation:low
            URL:https://prod.sf.vfcarbon.com/favicon.ico
            Preview:<html>..<head><title>400 No required SSL certificate was sent</title></head>..<body>..<center><h1>400 Bad Request</h1></center>..<center>No required SSL certificate was sent</center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):632
            Entropy (8bit):4.72894982842216
            Encrypted:false
            SSDEEP:12:TvmwXHVI9BnzlItmwt5r8INGlTF5TF5TF5TF5TF5TFK:DXHUBnRkKTPTPTPTPTPTc
            MD5:6BE05D19E4CA80EB3EF0A7F16F937F13
            SHA1:E589F353292174E34107D80E22C3EB7B3205B9E2
            SHA-256:D39229CC33510B8C095AEC8500CAFF6DC3F76F8FC1B7C8E1564DE22D8389900D
            SHA-512:05DFE91CEC34CB340858E83ED5236FC8095D5A148CC22BCD0B18DCC59CC2875358B4377F9347D89C8D862D47FEDE6D5326541684DDD42421A5A59E5810232CB6
            Malicious:false
            Reputation:low
            URL:https://prod.sf.vfcarbon.com/
            Preview:<html>..<head><title>400 No required SSL certificate was sent</title></head>..<body>..<center><h1>400 Bad Request</h1></center>..<center>No required SSL certificate was sent</center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 17, 2024 02:51:33.939559937 CEST49678443192.168.2.4104.46.162.224
            Apr 17, 2024 02:51:34.282988071 CEST49675443192.168.2.4173.222.162.32
            Apr 17, 2024 02:51:43.374177933 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374227047 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.374491930 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374599934 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374655962 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.374721050 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374794960 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374854088 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.374885082 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.374912024 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.748687983 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.748864889 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.749114990 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.749154091 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.749176979 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.749185085 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.750637054 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.750705957 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.751270056 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.751456022 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.751893044 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.751985073 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.752197981 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.752214909 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.752449036 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.752635002 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.803287983 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.803380013 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.803435087 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.850241899 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.870764017 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.870853901 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.871028900 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.871834040 CEST49736443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.871876955 CEST443497363.234.113.63192.168.2.4
            Apr 17, 2024 02:51:43.890656948 CEST49675443192.168.2.4173.222.162.32
            Apr 17, 2024 02:51:43.931159019 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:43.972214937 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:44.049973965 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:44.050142050 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:44.050374985 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:44.051877975 CEST49735443192.168.2.43.234.113.63
            Apr 17, 2024 02:51:44.051907063 CEST443497353.234.113.63192.168.2.4
            Apr 17, 2024 02:51:45.397572994 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.397650957 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.397758961 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.398031950 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.398081064 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.618302107 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.618613005 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.618632078 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.620060921 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.620119095 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.622342110 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.622423887 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.672687054 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:45.672700882 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:45.719546080 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:46.802385092 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:46.802469969 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:46.802539110 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:46.804789066 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:46.804862976 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.023839951 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.024003983 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.029131889 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.029145002 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.029376030 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.081243038 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.092830896 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.136159897 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.227592945 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.227637053 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.227751970 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.227751970 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.227830887 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.227869987 CEST49740443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.227886915 CEST4434974023.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.254467010 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.254544020 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.254842997 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.254962921 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.254992962 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.467346907 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.467495918 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.468590975 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.468619108 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.468839884 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.469835043 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.516113043 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.677086115 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.677187920 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.677839041 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.678725004 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.678725004 CEST49741443192.168.2.423.63.206.91
            Apr 17, 2024 02:51:47.678765059 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:47.678797007 CEST4434974123.63.206.91192.168.2.4
            Apr 17, 2024 02:51:55.618935108 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:55.619004965 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:51:55.619196892 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:56.112513065 CEST49739443192.168.2.4142.250.105.147
            Apr 17, 2024 02:51:56.112540960 CEST44349739142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.342855930 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:45.342896938 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.342966080 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:45.343380928 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:45.343393087 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.561042070 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.561456919 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:45.561480999 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.562129974 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.562839985 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:45.563076973 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:45.609561920 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:52.891205072 CEST4972380192.168.2.4199.232.210.172
            Apr 17, 2024 02:52:52.891325951 CEST4972480192.168.2.4199.232.210.172
            Apr 17, 2024 02:52:52.995286942 CEST8049723199.232.210.172192.168.2.4
            Apr 17, 2024 02:52:52.995353937 CEST8049724199.232.210.172192.168.2.4
            Apr 17, 2024 02:52:52.995388031 CEST8049724199.232.210.172192.168.2.4
            Apr 17, 2024 02:52:52.995420933 CEST8049723199.232.210.172192.168.2.4
            Apr 17, 2024 02:52:52.995471001 CEST4972380192.168.2.4199.232.210.172
            Apr 17, 2024 02:52:52.995564938 CEST4972480192.168.2.4199.232.210.172
            Apr 17, 2024 02:52:55.579647064 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:55.579818010 CEST44349750142.250.105.147192.168.2.4
            Apr 17, 2024 02:52:55.579866886 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:56.112122059 CEST49750443192.168.2.4142.250.105.147
            Apr 17, 2024 02:52:56.112140894 CEST44349750142.250.105.147192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 17, 2024 02:51:41.982429028 CEST53512631.1.1.1192.168.2.4
            Apr 17, 2024 02:51:41.985620975 CEST53562111.1.1.1192.168.2.4
            Apr 17, 2024 02:51:42.598858118 CEST53572971.1.1.1192.168.2.4
            Apr 17, 2024 02:51:43.267107010 CEST5206253192.168.2.41.1.1.1
            Apr 17, 2024 02:51:43.267276049 CEST5044853192.168.2.41.1.1.1
            Apr 17, 2024 02:51:43.372710943 CEST53520621.1.1.1192.168.2.4
            Apr 17, 2024 02:51:43.373462915 CEST53504481.1.1.1192.168.2.4
            Apr 17, 2024 02:51:45.290968895 CEST6012553192.168.2.41.1.1.1
            Apr 17, 2024 02:51:45.291199923 CEST6370453192.168.2.41.1.1.1
            Apr 17, 2024 02:51:45.395819902 CEST53637041.1.1.1192.168.2.4
            Apr 17, 2024 02:51:45.395853043 CEST53601251.1.1.1192.168.2.4
            Apr 17, 2024 02:52:00.123760939 CEST53522451.1.1.1192.168.2.4
            Apr 17, 2024 02:52:04.459573984 CEST138138192.168.2.4192.168.2.255
            Apr 17, 2024 02:52:19.238607883 CEST53561581.1.1.1192.168.2.4
            Apr 17, 2024 02:52:41.264964104 CEST53514581.1.1.1192.168.2.4
            Apr 17, 2024 02:52:42.170835972 CEST53512251.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 17, 2024 02:51:43.267107010 CEST192.168.2.41.1.1.10x84a1Standard query (0)prod.sf.vfcarbon.comA (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:43.267276049 CEST192.168.2.41.1.1.10xb276Standard query (0)prod.sf.vfcarbon.com65IN (0x0001)false
            Apr 17, 2024 02:51:45.290968895 CEST192.168.2.41.1.1.10x55c4Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.291199923 CEST192.168.2.41.1.1.10x54d4Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 17, 2024 02:51:43.372710943 CEST1.1.1.1192.168.2.40x84a1No error (0)prod.sf.vfcarbon.com3.234.113.63A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395819902 CEST1.1.1.1192.168.2.40x54d4No error (0)www.google.com65IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:45.395853043 CEST1.1.1.1192.168.2.40x55c4No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
            Apr 17, 2024 02:51:57.834933996 CEST1.1.1.1192.168.2.40xa44eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 17, 2024 02:51:57.834933996 CEST1.1.1.1192.168.2.40xa44eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 17, 2024 02:52:10.859788895 CEST1.1.1.1192.168.2.40x6730No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 17, 2024 02:52:10.859788895 CEST1.1.1.1192.168.2.40x6730No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 17, 2024 02:52:34.325823069 CEST1.1.1.1192.168.2.40x2943No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 17, 2024 02:52:34.325823069 CEST1.1.1.1192.168.2.40x2943No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 17, 2024 02:52:54.014220953 CEST1.1.1.1192.168.2.40xb629No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 17, 2024 02:52:54.014220953 CEST1.1.1.1192.168.2.40xb629No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • prod.sf.vfcarbon.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.4497363.234.113.634432696C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-17 00:51:43 UTC663OUTGET / HTTP/1.1
            Host: prod.sf.vfcarbon.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-17 00:51:43 UTC145INHTTP/1.1 400 Bad Request
            Server: nginx
            Date: Wed, 17 Apr 2024 00:51:43 GMT
            Content-Type: text/html
            Content-Length: 632
            Connection: close
            2024-04-17 00:51:43 UTC632INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 4e 6f 20 72 65 71 75 69 72 65 64 20 53 53 4c 20 63 65 72 74 69 66 69 63 61 74 65 20 77 61 73 20 73 65 6e 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 63 65 6e 74 65 72 3e 4e 6f 20 72 65 71 75 69 72 65 64 20 53 53 4c 20 63 65 72 74 69 66 69 63 61 74 65 20 77 61 73 20 73 65 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65
            Data Ascii: <html><head><title>400 No required SSL certificate was sent</title></head><body><center><h1>400 Bad Request</h1></center><center>No required SSL certificate was sent</center><hr><center>nginx</center></body></html>... a padding to disable


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.4497353.234.113.634432696C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-17 00:51:43 UTC596OUTGET /favicon.ico HTTP/1.1
            Host: prod.sf.vfcarbon.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://prod.sf.vfcarbon.com/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-17 00:51:44 UTC145INHTTP/1.1 400 Bad Request
            Server: nginx
            Date: Wed, 17 Apr 2024 00:51:43 GMT
            Content-Type: text/html
            Content-Length: 632
            Connection: close
            2024-04-17 00:51:44 UTC632INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 4e 6f 20 72 65 71 75 69 72 65 64 20 53 53 4c 20 63 65 72 74 69 66 69 63 61 74 65 20 77 61 73 20 73 65 6e 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 63 65 6e 74 65 72 3e 4e 6f 20 72 65 71 75 69 72 65 64 20 53 53 4c 20 63 65 72 74 69 66 69 63 61 74 65 20 77 61 73 20 73 65 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65
            Data Ascii: <html><head><title>400 No required SSL certificate was sent</title></head><body><center><h1>400 Bad Request</h1></center><center>No required SSL certificate was sent</center><hr><center>nginx</center></body></html>... a padding to disable


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974023.63.206.91443
            TimestampBytes transferredDirectionData
            2024-04-17 00:51:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-17 00:51:47 UTC468INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/079C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=108711
            Date: Wed, 17 Apr 2024 00:51:47 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974123.63.206.91443
            TimestampBytes transferredDirectionData
            2024-04-17 00:51:47 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-17 00:51:47 UTC531INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=108721
            Date: Wed, 17 Apr 2024 00:51:47 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-17 00:51:47 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:02:51:36
            Start date:17/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:02:51:39
            Start date:17/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2016,i,16729827099064400818,9882852457364780708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:02:51:41
            Start date:17/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prod.sf.vfcarbon.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly