Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0

Overview

General Information

Sample URL:https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLH
Analysis ID:1428855
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6752 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6400 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2380,i,4104228946034906261,12428065614040649030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3040 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnYHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49719 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49719 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY HTTP/1.1Host: u43944338.ct.sendgrid.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: u43944338.ct.sendgrid.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnYAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: u43944338.ct.sendgrid.net
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713542733027&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Fri, 19 Apr 2024 16:05:51 GMTContent-Type: text/htmlContent-Length: 564Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/8@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2380,i,4104228946034906261,12428065614040649030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2380,i,4104228946034906261,12428065614040649030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    u43944338.ct.sendgrid.net
    167.89.115.147
    truefalse
      high
      www.google.com
      64.233.176.104
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://u43944338.ct.sendgrid.net/favicon.icofalse
            high
            https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnYfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              167.89.115.147
              u43944338.ct.sendgrid.netUnited States
              11377SENDGRIDUSfalse
              64.233.176.104
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.5
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1428855
              Start date and time:2024-04-19 18:04:56 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 26s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean1.win@16/8@4/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 74.125.136.94, 142.251.15.138, 142.251.15.139, 142.251.15.100, 142.251.15.113, 142.251.15.101, 142.251.15.102, 64.233.177.84, 34.104.35.123, 40.68.123.157, 192.229.211.108, 199.232.210.172, 13.95.31.18, 20.3.187.198, 23.47.204.56, 23.47.204.45, 23.47.204.72, 23.47.204.52, 23.47.204.44, 23.47.204.82, 64.233.177.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:05:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.9841581968946316
              Encrypted:false
              SSDEEP:48:80dcTgkKHqidAKZdA19ehwiZUklqehQy+3:8zf//y
              MD5:EAAE0A7F25156FDFD4B6A2EE28D91E1B
              SHA1:F908EF42563C3200EE0FBDC5E6F8F39A09DFA80C
              SHA-256:00CBC47985C9DA2FA647900C1670F0AFD2E75521D1FA3DC7C1AEC37032AC5FFB
              SHA-512:6BCC617B295EC56BCEF581E5A2CDBFD7306081F2ABD701D32FEF212E7114B4CE944E79BBDD4693323210BF47CABFDE0F2EEAE36FB8A95F75B9509DFFC8A90B62
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.......rs...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:05:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2679
              Entropy (8bit):3.999025985794534
              Encrypted:false
              SSDEEP:48:8NdcTgkKHqidAKZdA1weh/iZUkAQkqehvy+2:8cfF9QWy
              MD5:147A75CCE0F45BF504BA81EF1BBEF026
              SHA1:8A5863371CD05BE10EEE76FC4A3DD537FA6E0FE1
              SHA-256:FD1B365AEC630DC75A2B1B5584A10E6C1B032BF48E6B0FA1314493BB7A7FC6DE
              SHA-512:628DB8A11EB2A4EB72FAB3AEF1D51EAC448EA295FA8CFFD1BA37EBF255951D6B700CA5E47B29AFF153D45839DBD7651953FAF3D25C65AE3DA1E2E814C33E4CBA
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....@..rs...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2693
              Entropy (8bit):4.011292057871481
              Encrypted:false
              SSDEEP:48:8xldcTgksHqidAKZdA14tseh7sFiZUkmgqeh7sdy+BX:8xUfTnLy
              MD5:B70962128691746E82AED2A4B420437A
              SHA1:9486130CDED5B2513C75C5204C9066905E43912C
              SHA-256:AA869F72C1FD90B1B596D3344FB7F39B24BB1D5087C3F3C943E471BE3E8A5201
              SHA-512:4740EE82467CAB489003B172396E40E3637D45EEEB43B7262EFAF9816C69D1B4217E274B41E2E0A6AF3A9A3E44A6DB07DDAB91BE8DECA88FE41C4BB4C42902E6
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:05:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.999467682581118
              Encrypted:false
              SSDEEP:48:8edcTgkKHqidAKZdA1vehDiZUkwqehjy+R:8lfGVy
              MD5:FF615C2B65716C05B121534C14F69C62
              SHA1:1F0F5A952DA011B495C53DD0146C1C8F8D32877A
              SHA-256:41FFAA13A80C614CD253CD5FB30521DF58E9654E8A904F28DD75D725C2404B01
              SHA-512:80D17B0636A35EBB1F5560BE2B84E13E44025ECA69730FBEDAC19AB257AC7E35A68A514B6F09F9C883B998D89B532EB8165399795AF91FB048F54649F47B7CFB
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.......rs...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:05:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.9862301289004036
              Encrypted:false
              SSDEEP:48:8WdcTgkKHqidAKZdA1hehBiZUk1W1qehJy+C:8dfG9py
              MD5:27A68A407262F46DE8AAB359C79DE324
              SHA1:898DD82D9370BC9DE69ABB53F5658226DFF47DD5
              SHA-256:62115E284E79AA9BFEB49A6B60BE48FDCBB8165555DCA6CAB17EFEDB22F8C97B
              SHA-512:132CEF759806CAEB90B10CCEA658953DF2299F5EF24ED7D9BB9AD79CABD91893A3F2086807EE23F6FDFDA52CE9D636C5D58EA75519AD3968804D13DED7157DCB
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....P#.rs...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:05:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2683
              Entropy (8bit):3.996905800283309
              Encrypted:false
              SSDEEP:48:8xdcTgkKHqidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8ofYT/TbxWOvTbLy7T
              MD5:C7FD98BF5A183A01FE9C7A6C2C3FBAC5
              SHA1:0658E585036D523F042BDF20DC61C6EF1E315D42
              SHA-256:2AA4F0D11DA7E70CE00EA0EF1AC820B0355CEFF2FA9B4AD0E4E5259BAE3CBF8E
              SHA-512:DB4F3182272A5F089404C08D1123508F8C95F951BF63966962DBFEDCF4178E2C848D7F605E8DB5267DF441BDB4FED3C58B34F707414ED6BE64DA5CDFCA1CEB84
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.......rs...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........{Qn......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):564
              Entropy (8bit):4.72971822420855
              Encrypted:false
              SSDEEP:12:TjeRHdHiHZdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH988DTPTPTPTPTPTc
              MD5:8E325DC2FEA7C8900FC6C4B8C6C394FE
              SHA1:1B3291D4EEA179C84145B2814CB53E6A506EC201
              SHA-256:0B52C5338AF355699530A47683420E48C7344E779D3E815FF9943CBFDC153CF2
              SHA-512:084C608F1F860FB08EF03B155658EA9988B3628D3C0F0E9561FDFF930E5912004CDDBCC43B1FA90C21FE7F5A481AC47C64B8CAA066C2BDF3CF533E152BF96C14
              Malicious:false
              Reputation:low
              URL:https://u43944338.ct.sendgrid.net/favicon.ico
              Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 19, 2024 18:05:42.982888937 CEST49674443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:42.982918024 CEST49675443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:43.092272997 CEST49673443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:50.354609013 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.354667902 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.354734898 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.355253935 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.355341911 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.355350971 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.355366945 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.355433941 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.355595112 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.355633020 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.726322889 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.726653099 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.726712942 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.728183031 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.728264093 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.729291916 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.729441881 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.729536057 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.729728937 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.729789972 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.729846954 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.729865074 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.731359959 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.731434107 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.732351065 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.732455969 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:50.771362066 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.926958084 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:50.927018881 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.005528927 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.005650043 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.005739927 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.006706953 CEST49710443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.006742954 CEST44349710167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.028152943 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.052437067 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.100121975 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.170547009 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.170722008 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:51.171186924 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.171375990 CEST49711443192.168.2.5167.89.115.147
              Apr 19, 2024 18:05:51.171415091 CEST44349711167.89.115.147192.168.2.5
              Apr 19, 2024 18:05:52.234642029 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.234690905 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.234782934 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.235044956 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.235059977 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.455684900 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.456928015 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.456947088 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.458363056 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.458457947 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.460551977 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.460628986 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.503222942 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.503252983 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:05:52.543795109 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:05:52.583066940 CEST49674443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:52.583076954 CEST49675443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:52.691905975 CEST49673443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:54.031857014 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.031902075 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.031956911 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.034086943 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.034113884 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.067894936 CEST4434970323.1.237.91192.168.2.5
              Apr 19, 2024 18:05:54.068010092 CEST49703443192.168.2.523.1.237.91
              Apr 19, 2024 18:05:54.256432056 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.256644011 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.263320923 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.263350964 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.263659954 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.316797972 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.389223099 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.436136961 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.494494915 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.494684935 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.494930029 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.494997978 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.495032072 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.495032072 CEST49715443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.495054960 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.495074987 CEST4434971523.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.548618078 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.548664093 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.548945904 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.549197912 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.549211979 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.764888048 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.765095949 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.769341946 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.769351959 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.769692898 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:54.773642063 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:54.816123962 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:55.033399105 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:55.033519983 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:55.033970118 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:55.035514116 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:55.035515070 CEST49716443192.168.2.523.216.69.213
              Apr 19, 2024 18:05:55.035541058 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:05:55.035552979 CEST4434971623.216.69.213192.168.2.5
              Apr 19, 2024 18:06:02.450376034 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:06:02.450469971 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:06:02.450565100 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:03.507008076 CEST49714443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:03.507035017 CEST4434971464.233.176.104192.168.2.5
              Apr 19, 2024 18:06:04.630641937 CEST49703443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:04.630846024 CEST49703443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:04.632780075 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:04.632827997 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:04.633155107 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:04.634984970 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:04.634999990 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:04.782871962 CEST4434970323.1.237.91192.168.2.5
              Apr 19, 2024 18:06:04.782900095 CEST4434970323.1.237.91192.168.2.5
              Apr 19, 2024 18:06:04.947026968 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:04.947134972 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.024261951 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.024292946 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.024647951 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.026021957 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.028570890 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.028595924 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.030247927 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.030256987 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.341173887 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.341262102 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.341506958 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.341562986 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.341578007 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.341651917 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.342221975 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.342261076 CEST4434971923.1.237.91192.168.2.5
              Apr 19, 2024 18:06:05.342293024 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:05.342345953 CEST49719443192.168.2.523.1.237.91
              Apr 19, 2024 18:06:52.183286905 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.183391094 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.183471918 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.184315920 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.184353113 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.396903038 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.427185059 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.427221060 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.427704096 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.471390963 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.483184099 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:06:52.483349085 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:06:52.535182953 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:07:02.400391102 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:07:02.400458097 CEST4434972564.233.176.104192.168.2.5
              Apr 19, 2024 18:07:02.400585890 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:07:03.527929068 CEST49725443192.168.2.564.233.176.104
              Apr 19, 2024 18:07:03.528002977 CEST4434972564.233.176.104192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              Apr 19, 2024 18:05:49.212177038 CEST53629471.1.1.1192.168.2.5
              Apr 19, 2024 18:05:49.384795904 CEST53621221.1.1.1192.168.2.5
              Apr 19, 2024 18:05:49.981959105 CEST53653261.1.1.1192.168.2.5
              Apr 19, 2024 18:05:50.245131969 CEST5377253192.168.2.51.1.1.1
              Apr 19, 2024 18:05:50.245980978 CEST6501053192.168.2.51.1.1.1
              Apr 19, 2024 18:05:50.353142023 CEST53650101.1.1.1192.168.2.5
              Apr 19, 2024 18:05:50.353756905 CEST53537721.1.1.1192.168.2.5
              Apr 19, 2024 18:05:52.128397942 CEST6075053192.168.2.51.1.1.1
              Apr 19, 2024 18:05:52.128572941 CEST5811053192.168.2.51.1.1.1
              Apr 19, 2024 18:05:52.233300924 CEST53607501.1.1.1192.168.2.5
              Apr 19, 2024 18:05:52.233361959 CEST53581101.1.1.1192.168.2.5
              Apr 19, 2024 18:06:07.076360941 CEST53618051.1.1.1192.168.2.5
              Apr 19, 2024 18:06:25.983191013 CEST53611811.1.1.1192.168.2.5
              Apr 19, 2024 18:06:48.561397076 CEST53494021.1.1.1192.168.2.5
              Apr 19, 2024 18:06:48.593549967 CEST53590841.1.1.1192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 19, 2024 18:05:50.245131969 CEST192.168.2.51.1.1.10xcb66Standard query (0)u43944338.ct.sendgrid.netA (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.245980978 CEST192.168.2.51.1.1.10xce1aStandard query (0)u43944338.ct.sendgrid.net65IN (0x0001)false
              Apr 19, 2024 18:05:52.128397942 CEST192.168.2.51.1.1.10x9511Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.128572941 CEST192.168.2.51.1.1.10x38e5Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.115.147A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.118.35A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.118.118A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.123.147A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.123.122A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.118.28A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.115.54A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.123.16A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:50.353756905 CEST1.1.1.1192.168.2.50xcb66No error (0)u43944338.ct.sendgrid.net167.89.115.121A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.104A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.103A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.147A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.99A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.105A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233300924 CEST1.1.1.1192.168.2.50x9511No error (0)www.google.com64.233.176.106A (IP address)IN (0x0001)false
              Apr 19, 2024 18:05:52.233361959 CEST1.1.1.1192.168.2.50x38e5No error (0)www.google.com65IN (0x0001)false
              Apr 19, 2024 18:06:04.276115894 CEST1.1.1.1192.168.2.50x74eaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 19, 2024 18:06:04.276115894 CEST1.1.1.1192.168.2.50x74eaNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 19, 2024 18:06:04.883416891 CEST1.1.1.1192.168.2.50x35aeNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:06:04.883416891 CEST1.1.1.1192.168.2.50x35aeNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:06:18.310401917 CEST1.1.1.1192.168.2.50x5467No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:06:18.310401917 CEST1.1.1.1192.168.2.50x5467No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:07:01.312519073 CEST1.1.1.1192.168.2.50x8d1dNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:07:01.312519073 CEST1.1.1.1192.168.2.50x8d1dNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:07:04.999056101 CEST1.1.1.1192.168.2.50xf0dfNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 19, 2024 18:07:04.999056101 CEST1.1.1.1192.168.2.50xf0dfNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              • u43944338.ct.sendgrid.net
              • https:
                • www.bing.com
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.549710167.89.115.1474436400C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-19 16:05:50 UTC959OUTGET /wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY HTTP/1.1
              Host: u43944338.ct.sendgrid.net
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-19 16:05:51 UTC287INHTTP/1.1 200 OK
              Server: nginx
              Date: Fri, 19 Apr 2024 16:05:50 GMT
              Content-Type: image/gif
              Content-Length: 43
              Connection: close
              Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
              Expires: Sat, 15 Jul 2000 05:00:00 GMT
              X-Robots-Tag: noindex, nofollow
              2024-04-19 16:05:51 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 ff ff ff 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
              Data Ascii: GIF89a!,D;


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.549711167.89.115.1474436400C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-19 16:05:51 UTC897OUTGET /favicon.ico HTTP/1.1
              Host: u43944338.ct.sendgrid.net
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-19 16:05:51 UTC143INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Fri, 19 Apr 2024 16:05:51 GMT
              Content-Type: text/html
              Content-Length: 564
              Connection: close
              2024-04-19 16:05:51 UTC564INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20
              Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.54971523.216.69.213443
              TimestampBytes transferredDirectionData
              2024-04-19 16:05:54 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-19 16:05:54 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0758)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=140227
              Date: Fri, 19 Apr 2024 16:05:54 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.54971623.216.69.213443
              TimestampBytes transferredDirectionData
              2024-04-19 16:05:54 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-19 16:05:55 UTC531INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0oq75YgAAAAAYL/6cwgY8QpNw2UWojohPQ0hHRURHRTE2MTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=140267
              Date: Fri, 19 Apr 2024 16:05:54 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-19 16:05:55 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination Port
              4192.168.2.54971923.1.237.91443
              TimestampBytes transferredDirectionData
              2024-04-19 16:06:05 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
              Origin: https://www.bing.com
              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
              Accept: */*
              Accept-Language: en-CH
              Content-type: text/xml
              X-Agent-DeviceId: 01000A410900D492
              X-BM-CBT: 1696428841
              X-BM-DateFormat: dd/MM/yyyy
              X-BM-DeviceDimensions: 784x984
              X-BM-DeviceDimensionsLogical: 784x984
              X-BM-DeviceScale: 100
              X-BM-DTZ: 120
              X-BM-Market: CH
              X-BM-Theme: 000000;0078d7
              X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
              X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
              X-Device-isOptin: false
              X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
              X-Device-OSSKU: 48
              X-Device-Touch: false
              X-DeviceID: 01000A410900D492
              X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
              X-MSEdge-ExternalExpType: JointCoord
              X-PositionerType: Desktop
              X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
              X-Search-CortanaAvailableCapabilities: None
              X-Search-SafeSearch: Moderate
              X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
              X-UserAgeClass: Unknown
              Accept-Encoding: gzip, deflate, br
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
              Host: www.bing.com
              Content-Length: 2484
              Connection: Keep-Alive
              Cache-Control: no-cache
              Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713542733027&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
              2024-04-19 16:06:05 UTC1OUTData Raw: 3c
              Data Ascii: <
              2024-04-19 16:06:05 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
              Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
              2024-04-19 16:06:05 UTC480INHTTP/1.1 204 No Content
              Access-Control-Allow-Origin: *
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              X-MSEdge-Ref: Ref A: 64AFA75176BF47B7AE95038F7B25F9B3 Ref B: LAX311000108047 Ref C: 2024-04-19T16:06:05Z
              Date: Fri, 19 Apr 2024 16:06:05 GMT
              Connection: close
              Alt-Svc: h3=":443"; ma=93600
              X-CDN-TraceID: 0.57ed0117.1713542765.1214510e


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:18:05:43
              Start date:19/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:18:05:47
              Start date:19/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2380,i,4104228946034906261,12428065614040649030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:18:05:49
              Start date:19/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u43944338.ct.sendgrid.net/wf/open?upn=u001.uGit3LLDnkBni-2BP2GH-2BECq-2B3XEFai1gZfAqIUMBfWthopnnKKtQfDmyw-2BIIjj0Pt79IGGDk7e4-2BedU8Ww55KoKWofBxax4AbFyyURLS7DQWRrGnd-2Bo1Snp8G9FtiIH9K7lv-2BKLHWDsHpqGmni2eqKqduMkMsfg8o1oveldTdnSkjlc14phe6zNTs1zx79RPf-2FqT0LfT7fHJPYnHRofFriOZpNXCh8gDAWeueRKMj0HGQ9AQHe1o7djG-2BrqZnoTnY"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly