Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://bestprizerhere.life/

Overview

General Information

Sample URL:http://bestprizerhere.life/
Analysis ID:1428698
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 4888 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1972,i,13668315710344348326,18032711157042731209,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6516 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestprizerhere.life/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: bestprizerhere.lifeVirustotal: Detection: 11%Perma Link
Source: https://bestprizerhere.life/favicon.icoVirustotal: Detection: 12%Perma Link
Source: http://bestprizerhere.life/Virustotal: Detection: 11%Perma Link
Source: https://bestprizerhere.life/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestprizerhere.lifeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bestprizerhere.lifeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bestprizerhere.life/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: sid=t1~o0uzeksyf2zweh13bxmmuyyd
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestprizerhere.lifeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: bestprizerhere.life
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal56.win@17/2@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1972,i,13668315710344348326,18032711157042731209,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestprizerhere.life/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1972,i,13668315710344348326,18032711157042731209,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bestprizerhere.life/12%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bestprizerhere.life12%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://bestprizerhere.life/favicon.ico12%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
bestprizerhere.life
185.155.184.85
truefalseunknown
www.google.com
64.233.185.104
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://bestprizerhere.life/false
      unknown
      https://bestprizerhere.life/favicon.icofalseunknown
      http://bestprizerhere.life/true
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        185.155.184.85
        bestprizerhere.lifeSwitzerland
        44160INTERNETONEInternetServicesProviderITfalse
        64.233.185.104
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1428698
        Start date and time:2024-04-19 12:04:29 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 16s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://bestprizerhere.life/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@17/2@6/4
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 64.233.176.94, 64.233.176.139, 64.233.176.113, 64.233.176.100, 64.233.176.101, 64.233.176.138, 64.233.176.102, 142.250.9.84, 34.104.35.123, 40.68.123.157, 72.21.81.240, 13.85.23.206, 192.229.211.108, 20.166.126.56, 74.125.138.94
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):676
        Entropy (8bit):5.726407140154804
        Encrypted:false
        SSDEEP:12:lnMEwuiuX4w4voq4Wh4C5/KenJeOEloEw1qT7e4rMjHYeeOEuGPXEuGjl3M5A6CK:lMNmMvx4Wr5wOEloE0o/oAOEuQEuq1MX
        MD5:7487BABB4AE0C683067EFEB914BE2831
        SHA1:69C0D8B3C5A531770CCD99A28B1E3EDD1966C6C2
        SHA-256:B8CA6EE257BF567AACA013DA0A78839E079F6105264272444516D3F789749669
        SHA-512:E00B8763B68DC0FBC7D124D088924FB188EF1D987B65B2CA2053C4190BE022E88CD4604322DB6CB2DCE94EA506B8FB812BC6E63D7F4C6B73D3E9BE273BC3DD8A
        Malicious:false
        Reputation:low
        URL:https://bestprizerhere.life/
        Preview:....<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">....<html xmlns="http://www.w3.org/1999/xhtml">..<head><title>....</title></head>..<body >.. <form method="post" action="404.aspx" id="form1">..<div class="aspNetHidden">..<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="xzRL5m+djYe6Ax4xVmrrUUQ2KNba5iIEZ5Grkfu9mb143+lzOrBs6XpPeMcPF5szOi/OT/8FXtLRovqjbB6GK9jOzPykaKNYPB3SmiHwMcw=" />..</div>....<div class="aspNetHidden">.....<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="193A34DB" />..</div>....Under construction.. </form>..</body>..</html>..
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 19, 2024 12:05:15.792108059 CEST49675443192.168.2.4173.222.162.32
        Apr 19, 2024 12:05:25.397249937 CEST49675443192.168.2.4173.222.162.32
        Apr 19, 2024 12:05:25.432151079 CEST4973580192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:25.432799101 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:25.644292116 CEST8049736185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:25.644421101 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:25.644742966 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:25.646403074 CEST8049735185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:25.646501064 CEST4973580192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:25.854099989 CEST8049736185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:25.854131937 CEST8049736185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:25.905643940 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.047007084 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.047046900 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.047178030 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.047468901 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.047477007 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.304145098 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.304181099 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.304272890 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.304594040 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.304605007 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.522330999 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.523207903 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.523221970 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.524257898 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.524343967 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.529093027 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.529160976 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.574614048 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.574629068 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:26.619795084 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:26.686728954 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.687246084 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.687263966 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.688278913 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.688344002 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.691390038 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.691448927 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.692898989 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:26.692904949 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:26.732868910 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.052139997 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.052222967 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.052284002 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.153698921 CEST49739443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.153729916 CEST44349739185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.280065060 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.280106068 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.280208111 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.280586004 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.280600071 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.707587957 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.708184004 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.708210945 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.708579063 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.713499069 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.713557005 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:27.714220047 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:27.756176949 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:28.155941963 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.155980110 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.156069040 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.158520937 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.158540010 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.180253983 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:28.180424929 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:28.180521011 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:28.180979967 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:28.181006908 CEST44349741185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:28.181030989 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:28.181097031 CEST49741443192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:28.381285906 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.381371975 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.386920929 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.386929989 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.387322903 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.431576967 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.444041014 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.488118887 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.584956884 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.585025072 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.585094929 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.630801916 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.630868912 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.630930901 CEST49742443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.630949974 CEST4434974223.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.886404037 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.886471033 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:28.886775970 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.888978958 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:28.889004946 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.106933117 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.107151031 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:29.112540960 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:29.112574100 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.112925053 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.117090940 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:29.164119005 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.314066887 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.314208984 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:29.314373970 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:29.318208933 CEST49743443192.168.2.423.63.206.91
        Apr 19, 2024 12:05:29.318252087 CEST4434974323.63.206.91192.168.2.4
        Apr 19, 2024 12:05:36.561602116 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:36.561672926 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:36.561837912 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:37.382385015 CEST49672443192.168.2.4173.222.162.32
        Apr 19, 2024 12:05:37.382431984 CEST44349672173.222.162.32192.168.2.4
        Apr 19, 2024 12:05:37.661469936 CEST49740443192.168.2.464.233.185.104
        Apr 19, 2024 12:05:37.661498070 CEST4434974064.233.185.104192.168.2.4
        Apr 19, 2024 12:05:41.356122971 CEST4972380192.168.2.4199.232.214.172
        Apr 19, 2024 12:05:41.459707975 CEST8049723199.232.214.172192.168.2.4
        Apr 19, 2024 12:05:41.459745884 CEST8049723199.232.214.172192.168.2.4
        Apr 19, 2024 12:05:41.459841013 CEST4972380192.168.2.4199.232.214.172
        Apr 19, 2024 12:05:55.854255915 CEST8049736185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:55.854329109 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:55.859390020 CEST8049735185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:55.859488010 CEST4973580192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:57.519828081 CEST4973580192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:57.520224094 CEST4973680192.168.2.4185.155.184.85
        Apr 19, 2024 12:05:57.729590893 CEST8049736185.155.184.85192.168.2.4
        Apr 19, 2024 12:05:57.732027054 CEST8049735185.155.184.85192.168.2.4
        Apr 19, 2024 12:06:26.262044907 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:26.262077093 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.262145042 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:26.262542009 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:26.262557983 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.476097107 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.476557970 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:26.476581097 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.477044106 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.477514029 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:26.477596998 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:26.541325092 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:30.791547060 CEST4972480192.168.2.4199.232.214.172
        Apr 19, 2024 12:06:30.895751953 CEST8049724199.232.214.172192.168.2.4
        Apr 19, 2024 12:06:30.895812035 CEST8049724199.232.214.172192.168.2.4
        Apr 19, 2024 12:06:30.896075010 CEST4972480192.168.2.4199.232.214.172
        Apr 19, 2024 12:06:36.496792078 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:36.496953964 CEST4434975164.233.185.104192.168.2.4
        Apr 19, 2024 12:06:36.497123957 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:37.655755997 CEST49751443192.168.2.464.233.185.104
        Apr 19, 2024 12:06:37.655783892 CEST4434975164.233.185.104192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 19, 2024 12:05:23.009962082 CEST53621071.1.1.1192.168.2.4
        Apr 19, 2024 12:05:23.077853918 CEST53530381.1.1.1192.168.2.4
        Apr 19, 2024 12:05:23.812009096 CEST53605451.1.1.1192.168.2.4
        Apr 19, 2024 12:05:25.153721094 CEST5366653192.168.2.41.1.1.1
        Apr 19, 2024 12:05:25.153903008 CEST5924353192.168.2.41.1.1.1
        Apr 19, 2024 12:05:25.429930925 CEST53536661.1.1.1192.168.2.4
        Apr 19, 2024 12:05:25.431000948 CEST53592431.1.1.1192.168.2.4
        Apr 19, 2024 12:05:25.858712912 CEST6382853192.168.2.41.1.1.1
        Apr 19, 2024 12:05:25.858935118 CEST6202453192.168.2.41.1.1.1
        Apr 19, 2024 12:05:25.966170073 CEST53620241.1.1.1192.168.2.4
        Apr 19, 2024 12:05:26.045999050 CEST53638281.1.1.1192.168.2.4
        Apr 19, 2024 12:05:26.198286057 CEST4936353192.168.2.41.1.1.1
        Apr 19, 2024 12:05:26.198488951 CEST5194753192.168.2.41.1.1.1
        Apr 19, 2024 12:05:26.302686930 CEST53519471.1.1.1192.168.2.4
        Apr 19, 2024 12:05:26.302761078 CEST53493631.1.1.1192.168.2.4
        Apr 19, 2024 12:05:41.178600073 CEST53517711.1.1.1192.168.2.4
        Apr 19, 2024 12:05:42.375952005 CEST138138192.168.2.4192.168.2.255
        Apr 19, 2024 12:05:59.975680113 CEST53504931.1.1.1192.168.2.4
        Apr 19, 2024 12:06:22.660178900 CEST53526131.1.1.1192.168.2.4
        Apr 19, 2024 12:06:22.661397934 CEST53633321.1.1.1192.168.2.4
        Apr 19, 2024 12:06:50.054639101 CEST53535091.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 19, 2024 12:05:25.153721094 CEST192.168.2.41.1.1.10xb65dStandard query (0)bestprizerhere.lifeA (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:25.153903008 CEST192.168.2.41.1.1.10x8d7fStandard query (0)bestprizerhere.life65IN (0x0001)false
        Apr 19, 2024 12:05:25.858712912 CEST192.168.2.41.1.1.10x93c4Standard query (0)bestprizerhere.lifeA (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:25.858935118 CEST192.168.2.41.1.1.10xddb7Standard query (0)bestprizerhere.life65IN (0x0001)false
        Apr 19, 2024 12:05:26.198286057 CEST192.168.2.41.1.1.10xaf49Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.198488951 CEST192.168.2.41.1.1.10xded5Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 19, 2024 12:05:25.429930925 CEST1.1.1.1192.168.2.40xb65dNo error (0)bestprizerhere.life185.155.184.85A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.045999050 CEST1.1.1.1192.168.2.40x93c4No error (0)bestprizerhere.life185.155.184.85A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302686930 CEST1.1.1.1192.168.2.40xded5No error (0)www.google.com65IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.104A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.106A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.147A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.105A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.103A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:26.302761078 CEST1.1.1.1192.168.2.40xaf49No error (0)www.google.com64.233.185.99A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:40.551928997 CEST1.1.1.1192.168.2.40x3bebNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 19, 2024 12:05:40.551928997 CEST1.1.1.1192.168.2.40x3bebNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 19, 2024 12:05:56.255983114 CEST1.1.1.1192.168.2.40x3905No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 19, 2024 12:05:56.255983114 CEST1.1.1.1192.168.2.40x3905No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 19, 2024 12:06:15.053014040 CEST1.1.1.1192.168.2.40xe37aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 19, 2024 12:06:15.053014040 CEST1.1.1.1192.168.2.40xe37aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 19, 2024 12:06:35.519736052 CEST1.1.1.1192.168.2.40x958eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 19, 2024 12:06:35.519736052 CEST1.1.1.1192.168.2.40x958eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • bestprizerhere.life
        • https:
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449736185.155.184.85802992C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 19, 2024 12:05:25.644742966 CEST434OUTGET / HTTP/1.1
        Host: bestprizerhere.life
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Apr 19, 2024 12:05:25.854131937 CEST387INHTTP/1.1 301 Moved Permanently
        Server: nginx
        Date: Fri, 19 Apr 2024 10:05:25 GMT
        Content-Type: text/html
        Content-Length: 162
        Connection: keep-alive
        Location: https://bestprizerhere.life/
        Cache-Control: no-transform
        Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
        Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449739185.155.184.854432992C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-19 10:05:26 UTC662OUTGET / HTTP/1.1
        Host: bestprizerhere.life
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-04-19 10:05:27 UTC236INHTTP/1.1 200 OK
        Server: nginx
        Date: Fri, 19 Apr 2024 10:05:26 GMT
        Content-Type: text/html; charset=utf-8
        Connection: close
        cache-control: private
        set-cookie: sid=t1~o0uzeksyf2zweh13bxmmuyyd; path=/
        Cache-Control: no-transform
        2024-04-19 10:05:27 UTC676INData Raw: 0d 0a 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 74 72 61 6e 73 69 74 69 6f 6e 61 6c 2e 64 74 64 22 3e 0d 0a 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 3e 0d 0a 20 20 20 20 3c 66 6f 72 6d 20 6d 65 74 68 6f 64 3d 22 70 6f 73 74 22 20 61 63 74 69 6f 6e 3d 22 34 30 34 2e 61 73
        Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title></title></head><body > <form method="post" action="404.as


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449741185.155.184.854432992C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-19 10:05:27 UTC635OUTGET /favicon.ico HTTP/1.1
        Host: bestprizerhere.life
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://bestprizerhere.life/
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        Cookie: sid=t1~o0uzeksyf2zweh13bxmmuyyd
        2024-04-19 10:05:28 UTC127INHTTP/1.1 204 No Content
        Server: nginx
        Date: Fri, 19 Apr 2024 10:05:28 GMT
        Connection: close
        Cache-Control: no-transform


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.44974223.63.206.91443
        TimestampBytes transferredDirectionData
        2024-04-19 10:05:28 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-19 10:05:28 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/073D)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus-z1
        Cache-Control: public, max-age=161900
        Date: Fri, 19 Apr 2024 10:05:28 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.44974323.63.206.91443
        TimestampBytes transferredDirectionData
        2024-04-19 10:05:29 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-19 10:05:29 UTC531INHTTP/1.1 200 OK
        Content-Type: application/octet-stream
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
        Cache-Control: public, max-age=161884
        Date: Fri, 19 Apr 2024 10:05:29 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-19 10:05:29 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:12:05:18
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:12:05:20
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1972,i,13668315710344348326,18032711157042731209,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:12:05:24
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestprizerhere.life/"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly