Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254

Overview

General Information

Sample URL:https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254
Analysis ID:1427701
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 3288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6100 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=2016,i,7530579221741751524,7087754184749486332,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254SlashNext: detection malicious, Label: Scareware type: Phishing & Social Engineering
Source: https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@2/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=2016,i,7530579221741751524,7087754184749486332,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=2016,i,7530579221741751524,7087754184749486332,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254100%SlashNextScareware type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    www.google.com
    74.125.136.106
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        74.125.136.106
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1427701
        Start date and time:2024-04-18 01:07:14 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 15s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@16/4@2/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 64.233.185.94, 173.194.219.100, 173.194.219.101, 173.194.219.102, 173.194.219.113, 173.194.219.138, 173.194.219.139, 172.217.215.84, 34.104.35.123, 20.150.116.4, 20.114.59.183, 199.232.214.172, 20.3.187.198, 192.229.211.108, 13.95.31.18, 64.233.177.94
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
        Category:downloaded
        Size (bytes):321
        Entropy (8bit):5.092463443765969
        Encrypted:false
        SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOM8EcuAcUDR2p04SEMo5E:hax0rKRHkhzRH/Un2i2GprK5YWOccuAB
        MD5:441F5C668055E02801C14C9E1AA35E1B
        SHA1:E859A017DF4028B78F85B5E857732E0697715D0F
        SHA-256:D86D571A0197E36A93FC1740C9AD17835FFA99C889D205BC79184C3777D3957A
        SHA-512:7EE0605964004469BBBBDE70654AC024C22130082CD31F10AE34909EB2AE8BFD158C976199494438E88D41D7E92FA561B40124F61512741577881B4BD91E1730
        Malicious:false
        Reputation:low
        URL:https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254
        Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : bc038c65-901e-0027-2b1c-91593e000000</li><li>TimeStamp : 2024-04-17T23:08:10.2743087Z</li></ul></p></body></html>
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
        Category:downloaded
        Size (bytes):321
        Entropy (8bit):5.0695920471099765
        Encrypted:false
        SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOJdAvliR2p04SEBR5E:hax0rKRHkhzRH/Un2i2GprK5YWOJdHe+
        MD5:0128F474A5EA51D00A155D1542C5BF8E
        SHA1:6B2F19868A15341113422CF715ED226E6048E85C
        SHA-256:1BB7F2FF6411FF1AB40666A9A8FCE72A5890E988E63B22420AE10F2A2AC9B38C
        SHA-512:4B646B5C3213BC13487357AAD3AA902531D249E8BFE221D73D05620424C6B9F856B75860642340B6FACC489A5F303070C3E9CAD7B30C44F502E50B92BE270AA4
        Malicious:false
        Reputation:low
        URL:https://wwx3-secondary.z1.web.core.windows.net/favicon.ico
        Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : 5e288e80-401e-0069-0d1c-9177b6000000</li><li>TimeStamp : 2024-04-17T23:08:10.5502845Z</li></ul></p></body></html>
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 18, 2024 01:08:00.142770052 CEST49675443192.168.2.4173.222.162.32
        Apr 18, 2024 01:08:09.752722025 CEST49675443192.168.2.4173.222.162.32
        Apr 18, 2024 01:08:12.378340006 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.378398895 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.378505945 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.379940987 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.379975080 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.608598948 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.609355927 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.609411955 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.611047029 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.611119986 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.612777948 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.612868071 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.657073021 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.657092094 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:12.703958988 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:12.750394106 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:12.750432968 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:12.750564098 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:12.754189968 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:12.754205942 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:12.986505985 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:12.986568928 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:12.993233919 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:12.993249893 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:12.994146109 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.047679901 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.096229076 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.140156031 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.208626032 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.208704948 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.208794117 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.208827972 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.208842039 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.208842039 CEST49740443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.208852053 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.208859921 CEST4434974023.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.239757061 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.239819050 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.239975929 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.240236998 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.240257978 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.455744982 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.455806017 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.457034111 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.457040071 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.457257032 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.458190918 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.500161886 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.665457010 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.665647984 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:13.666124105 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.666881084 CEST49741443192.168.2.423.201.212.130
        Apr 18, 2024 01:08:13.666908026 CEST4434974123.201.212.130192.168.2.4
        Apr 18, 2024 01:08:22.626616955 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:22.626756907 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:08:22.629476070 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:24.332591057 CEST49739443192.168.2.474.125.136.106
        Apr 18, 2024 01:08:24.332659960 CEST4434973974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.307233095 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:12.307260990 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.307326078 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:12.307532072 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:12.307544947 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.523902893 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.524286032 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:12.524296999 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.524743080 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.525049925 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:12.525125980 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:12.579958916 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:22.521812916 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:22.521884918 CEST4434974974.125.136.106192.168.2.4
        Apr 18, 2024 01:09:22.521924973 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:24.300225019 CEST49749443192.168.2.474.125.136.106
        Apr 18, 2024 01:09:24.300251007 CEST4434974974.125.136.106192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 18, 2024 01:08:07.887530088 CEST53557201.1.1.1192.168.2.4
        Apr 18, 2024 01:08:07.896271944 CEST53501651.1.1.1192.168.2.4
        Apr 18, 2024 01:08:08.520747900 CEST53583541.1.1.1192.168.2.4
        Apr 18, 2024 01:08:12.253500938 CEST6071853192.168.2.41.1.1.1
        Apr 18, 2024 01:08:12.254337072 CEST6099153192.168.2.41.1.1.1
        Apr 18, 2024 01:08:12.358474016 CEST53607181.1.1.1192.168.2.4
        Apr 18, 2024 01:08:12.358846903 CEST53609911.1.1.1192.168.2.4
        Apr 18, 2024 01:08:25.622684956 CEST53537201.1.1.1192.168.2.4
        Apr 18, 2024 01:08:28.130286932 CEST138138192.168.2.4192.168.2.255
        Apr 18, 2024 01:08:44.434778929 CEST53520581.1.1.1192.168.2.4
        Apr 18, 2024 01:09:06.873330116 CEST53505671.1.1.1192.168.2.4
        Apr 18, 2024 01:09:07.754718065 CEST53561301.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 18, 2024 01:08:12.253500938 CEST192.168.2.41.1.1.10xcdeeStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.254337072 CEST192.168.2.41.1.1.10xb4afStandard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358474016 CEST1.1.1.1192.168.2.40xcdeeNo error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:12.358846903 CEST1.1.1.1192.168.2.40xb4afNo error (0)www.google.com65IN (0x0001)false
        Apr 18, 2024 01:08:23.258339882 CEST1.1.1.1192.168.2.40xac67No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:23.258339882 CEST1.1.1.1192.168.2.40xac67No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:24.258508921 CEST1.1.1.1192.168.2.40x3c5bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 18, 2024 01:08:24.258508921 CEST1.1.1.1192.168.2.40x3c5bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:40.792520046 CEST1.1.1.1192.168.2.40x40f4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 18, 2024 01:08:40.792520046 CEST1.1.1.1192.168.2.40x40f4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 18, 2024 01:08:59.530397892 CEST1.1.1.1192.168.2.40x4537No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 18, 2024 01:08:59.530397892 CEST1.1.1.1192.168.2.40x4537No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 18, 2024 01:09:20.485750914 CEST1.1.1.1192.168.2.40x59dbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 18, 2024 01:09:20.485750914 CEST1.1.1.1192.168.2.40x59dbNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44974023.201.212.130443
        TimestampBytes transferredDirectionData
        2024-04-17 23:08:13 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-17 23:08:13 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/079C)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus2-z1
        Cache-Control: public, max-age=28476
        Date: Wed, 17 Apr 2024 23:08:13 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974123.201.212.130443
        TimestampBytes transferredDirectionData
        2024-04-17 23:08:13 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-17 23:08:13 UTC530INHTTP/1.1 200 OK
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Content-Type: application/octet-stream
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
        Cache-Control: public, max-age=28519
        Date: Wed, 17 Apr 2024 23:08:13 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-17 23:08:13 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:01:08:03
        Start date:18/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:01:08:06
        Start date:18/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=2016,i,7530579221741751524,7087754184749486332,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:01:08:08
        Start date:18/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://wwx3-secondary.z1.web.core.windows.net/werrx01USAHTML/?bcda=1-844-308-7254"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly