Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://45.128.232.135

Overview

General Information

Sample URL:https://45.128.232.135
Analysis ID:1427731
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 7104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,5691008142892956070,8059891884247667552,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://45.128.232.135" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://45.128.232.135Virustotal: Detection: 5%Perma Link
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 45.128.232.135
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713399705070&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: classification engineClassification label: mal48.win@17/6@2/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,5691008142892956070,8059891884247667552,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://45.128.232.135"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,5691008142892956070,8059891884247667552,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://45.128.232.1355%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
74.125.138.104
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    74.125.138.104
    www.google.comUnited States
    15169GOOGLEUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    45.128.232.135
    unknownUnited Kingdom
    208861RACKTECHRUfalse
    IP
    192.168.2.5
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1427731
    Start date and time:2024-04-18 02:21:11 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 2m 1s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:https://45.128.232.135
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:6
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal48.win@17/6@2/4
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • URL browsing timeout or error
    • URL not reachable
    • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 74.125.136.94, 172.217.215.101, 172.217.215.138, 172.217.215.100, 172.217.215.102, 172.217.215.113, 172.217.215.139, 172.217.215.84, 34.104.35.123, 74.125.138.94, 23.63.157.166, 52.165.165.26, 72.21.81.240, 192.229.211.108, 13.95.31.18
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, www.gstatic.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 17 23:22:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2677
    Entropy (8bit):3.978694661726783
    Encrypted:false
    SSDEEP:48:83dUTYgSH0idAKZdA19ehwiZUklqeh2y+3:8OfBBy
    MD5:7BBD0A4E8BFD867345647B62F21124E1
    SHA1:D19EABB50B117F8DEAA9FCDA0FB2EC116F3D34D4
    SHA-256:39192230A0293EF36B2B91ACB253AFDCC747B58C26B01BCC529DB60AB8F26316
    SHA-512:385DA285F63A1A65B1DBDF86492330EE9EE5D0DFE673658211A46B2533E2BD0716C92B19238F031E5DB7615844E034870A6D56C290C65D569B37840E7E0A5EB1
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....:Jen&...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 17 23:22:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2679
    Entropy (8bit):3.996407220083157
    Encrypted:false
    SSDEEP:48:8udUTYgSH0idAKZdA1weh/iZUkAQkqehxy+2:8Bfz9QEy
    MD5:238BCF3FF076A73023429BFD57A351B1
    SHA1:E0033410EFF2B3206FC65163816B948A4E64BA31
    SHA-256:CF24C645857F06EA9D9F160D470AF3F98D01EF6B13C49526467451D3C73A0DE6
    SHA-512:38C93D7CC5805C915BCB8F5899C0CDC64E6B5D2878BB21CCF47A369CA1C825006E08EFCD595BEB9F7FEF3356C0BF0E479FB2EFD11A25986A92F4019C0836C9E3
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....~.Yn&...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2693
    Entropy (8bit):4.007872968041347
    Encrypted:false
    SSDEEP:48:8xxdUTYgsH0idAKZdA14tseh7sFiZUkmgqeh7sny+BX:8xgf5ndy
    MD5:2B043DE51E21AE70C802C52AD8498D58
    SHA1:BDAD6ED936A9EE4C1B306013EAB95DC7AE16A80A
    SHA-256:A75DAD2C91B7476184ABA586AF4AF755D0BDAFEBCFDC71EC9F7AF256CF853157
    SHA-512:0F3C87DF70BCFECA9A4A213F7E312166BB3A2B96552F8D01FAB92AFB5F60F29BED0186BE0F1711625FADB51CB3D74F5E31DCC288705886AD2146886A06B5B6DD
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 17 23:22:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2681
    Entropy (8bit):3.993352837202413
    Encrypted:false
    SSDEEP:48:8OdUTYgSH0idAKZdA1vehDiZUkwqehFy+R:8hfwvy
    MD5:24F59CA7006FE402003D2B414FF75739
    SHA1:C5090904DC6A9FA70B06373FDE9847AF478673C4
    SHA-256:AC95C8925D1612ECF86E6A8E890115F2AEF27D7F8E6941FBCCC6BC9862DDCC16
    SHA-512:460CAE13790012A2E11B7874CEFF959DEB6FFFF83B869F313950834DB9CC3A4BFD55EF5B6CC516FCF1092DA63AD40159FF0E4F53A5C577CFCA26BE3EF7379B1E
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....g.Pn&...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 17 23:22:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2681
    Entropy (8bit):3.982601630722492
    Encrypted:false
    SSDEEP:48:8HcdUTYgSH0idAKZdA1hehBiZUk1W1qehTy+C:8H/fw9zy
    MD5:52B9EFDC66A30E4EF837D8DE861637E4
    SHA1:DF9932902EC2F3DDA65D1017BBFE74032F2DA171
    SHA-256:18EFAEAE7534C27DE198BED62895269E3E224B6B59118939C0BD421ED65D0559
    SHA-512:AFFA9DE04785DBC2B4986342C138468DDACEFC62A9B6949ACDA5709E493C943D08352E4BC123DE5DACD7423D5058E8C2EBDEC528014EE64683C02528D8AF8FB4
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,..../A`n&...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 17 23:22:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2683
    Entropy (8bit):3.9954405778584663
    Encrypted:false
    SSDEEP:48:8HrOdUTYgSH0idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbdy+yT+:8Hrhf+T/TbxWOvTbdy7T
    MD5:E956345B7F23C6205BD5B6F3B34E165A
    SHA1:24FDAE1F5A50D67A523A89DC6BE183EB0ED240D4
    SHA-256:1AD183B52FFA51AE81CA5DC4AC3C8945FF41055C4B6A37218320C33200D987B6
    SHA-512:50B6A4D41F97E60E5AB96990D930CA401022905C83FE515F5B5ACEA450D356F3A9A0BFA04E6A6A6A31AC196A5C15EB5362DA9E4032D0F5A89B5557D36F0A29E1
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,.....Gn&...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........M........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    No static file info
    TimestampSource PortDest PortSource IPDest IP
    Apr 18, 2024 02:21:55.379607916 CEST49675443192.168.2.523.1.237.91
    Apr 18, 2024 02:21:55.379725933 CEST49674443192.168.2.523.1.237.91
    Apr 18, 2024 02:21:55.519896984 CEST49673443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:01.431193113 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431262970 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:01.431353092 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431364059 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431447983 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:01.431523085 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431689978 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431732893 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:01.431896925 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:01.431936026 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:02.093362093 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:02.094418049 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:02.094489098 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:02.096198082 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:02.096393108 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:02.103008032 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:02.103157043 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:02.103216887 CEST4434971145.128.232.135192.168.2.5
    Apr 18, 2024 02:22:02.103293896 CEST49711443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.161742926 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:03.162321091 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.162358999 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:03.166007996 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:03.166083097 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.167294979 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.167598009 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.167696953 CEST4434971045.128.232.135192.168.2.5
    Apr 18, 2024 02:22:03.167757034 CEST49710443192.168.2.545.128.232.135
    Apr 18, 2024 02:22:03.983023882 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:03.983066082 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:03.984812021 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:03.985374928 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:03.985390902 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.212692022 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.238840103 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:04.238859892 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.240575075 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.241236925 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:04.244255066 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:04.244363070 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.299141884 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:04.299156904 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:04.346033096 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:04.986641884 CEST49674443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:04.986723900 CEST49675443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:05.127286911 CEST49673443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:06.502305031 CEST4434970323.1.237.91192.168.2.5
    Apr 18, 2024 02:22:06.502424955 CEST49703443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:14.195909977 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:14.195966005 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:14.196187019 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:15.916552067 CEST49715443192.168.2.574.125.138.104
    Apr 18, 2024 02:22:15.916582108 CEST4434971574.125.138.104192.168.2.5
    Apr 18, 2024 02:22:16.717585087 CEST49703443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:16.717678070 CEST49703443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:16.718410969 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:16.718461037 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:16.718538046 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:16.718956947 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:16.718976974 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:16.870842934 CEST4434970323.1.237.91192.168.2.5
    Apr 18, 2024 02:22:16.870861053 CEST4434970323.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.041968107 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.042036057 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.093574047 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.093616962 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.094679117 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.094752073 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.095385075 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.095451117 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.095710039 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.095724106 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.394237995 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.394330025 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.394670010 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.394716024 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.394747972 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.394787073 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.480935097 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.480963945 CEST4434972223.1.237.91192.168.2.5
    Apr 18, 2024 02:22:17.480986118 CEST49722443192.168.2.523.1.237.91
    Apr 18, 2024 02:22:17.481038094 CEST49722443192.168.2.523.1.237.91
    TimestampSource PortDest PortSource IPDest IP
    Apr 18, 2024 02:21:59.613804102 CEST53573861.1.1.1192.168.2.5
    Apr 18, 2024 02:21:59.669698954 CEST53593691.1.1.1192.168.2.5
    Apr 18, 2024 02:22:00.268132925 CEST53624351.1.1.1192.168.2.5
    Apr 18, 2024 02:22:02.280534029 CEST53613401.1.1.1192.168.2.5
    Apr 18, 2024 02:22:03.877100945 CEST5909453192.168.2.51.1.1.1
    Apr 18, 2024 02:22:03.877100945 CEST5000853192.168.2.51.1.1.1
    Apr 18, 2024 02:22:03.981693983 CEST53500081.1.1.1192.168.2.5
    Apr 18, 2024 02:22:03.981713057 CEST53590941.1.1.1192.168.2.5
    Apr 18, 2024 02:22:18.297019958 CEST53563321.1.1.1192.168.2.5
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Apr 18, 2024 02:22:03.877100945 CEST192.168.2.51.1.1.10x4315Standard query (0)www.google.com65IN (0x0001)false
    Apr 18, 2024 02:22:03.877100945 CEST192.168.2.51.1.1.10x6a7dStandard query (0)www.google.comA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.104A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.99A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.106A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.105A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.103A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981693983 CEST1.1.1.1192.168.2.50x6a7dNo error (0)www.google.com74.125.138.147A (IP address)IN (0x0001)false
    Apr 18, 2024 02:22:03.981713057 CEST1.1.1.1192.168.2.50x4315No error (0)www.google.com65IN (0x0001)false
    Apr 18, 2024 02:22:16.347484112 CEST1.1.1.1192.168.2.50x6675No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Apr 18, 2024 02:22:16.347484112 CEST1.1.1.1192.168.2.50x6675No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    • https:
      • www.bing.com
    Session IDSource IPSource PortDestination IPDestination Port
    0192.168.2.54972223.1.237.91443
    TimestampBytes transferredDirectionData
    2024-04-18 00:22:17 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
    Origin: https://www.bing.com
    Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
    Accept: */*
    Accept-Language: en-CH
    Content-type: text/xml
    X-Agent-DeviceId: 01000A410900D492
    X-BM-CBT: 1696428841
    X-BM-DateFormat: dd/MM/yyyy
    X-BM-DeviceDimensions: 784x984
    X-BM-DeviceDimensionsLogical: 784x984
    X-BM-DeviceScale: 100
    X-BM-DTZ: 120
    X-BM-Market: CH
    X-BM-Theme: 000000;0078d7
    X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
    X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
    X-Device-isOptin: false
    X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
    X-Device-OSSKU: 48
    X-Device-Touch: false
    X-DeviceID: 01000A410900D492
    X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
    X-MSEdge-ExternalExpType: JointCoord
    X-PositionerType: Desktop
    X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
    X-Search-CortanaAvailableCapabilities: None
    X-Search-SafeSearch: Moderate
    X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
    X-UserAgeClass: Unknown
    Accept-Encoding: gzip, deflate, br
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
    Host: www.bing.com
    Content-Length: 2484
    Connection: Keep-Alive
    Cache-Control: no-cache
    Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713399705070&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
    2024-04-18 00:22:17 UTC1OUTData Raw: 3c
    Data Ascii: <
    2024-04-18 00:22:17 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
    Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
    2024-04-18 00:22:17 UTC479INHTTP/1.1 204 No Content
    Access-Control-Allow-Origin: *
    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
    X-MSEdge-Ref: Ref A: 6F837F529826474096119AEAB3C87C74 Ref B: LAX311000115017 Ref C: 2024-04-18T00:22:17Z
    Date: Thu, 18 Apr 2024 00:22:17 GMT
    Connection: close
    Alt-Svc: h3=":443"; ma=93600
    X-CDN-TraceID: 0.57ed0117.1713399737.83500b0


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:02:21:55
    Start date:18/04/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:1
    Start time:02:21:57
    Start date:18/04/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,5691008142892956070,8059891884247667552,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:3
    Start time:02:22:00
    Start date:18/04/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://45.128.232.135"
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    No disassembly