Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989

Overview

General Information

Sample URL:https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989
Analysis ID:1428856
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5100 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1692 --field-trial-handle=2032,i,10411871364476025621,2517455805364260529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6512 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=kAoP1pgTGSGy8Uc&MD=nKDYz6+2 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=kAoP1pgTGSGy8Uc&MD=nKDYz6+2 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: www.olocheckout.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1692 --field-trial-handle=2032,i,10411871364476025621,2517455805364260529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1692 --field-trial-handle=2032,i,10411871364476025621,2517455805364260529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
108.177.122.104
truefalse
    high
    www.olocheckout.com
    unknown
    unknownfalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      about:blankfalse
        low
        https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          108.177.122.104
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1428856
          Start date and time:2024-04-19 18:11:49 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 16s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/4@6/3
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.9.94, 142.250.105.102, 142.250.105.138, 142.250.105.101, 142.250.105.113, 142.250.105.100, 142.250.105.139, 142.250.9.84, 34.104.35.123, 104.18.32.68, 172.64.155.188, 199.232.210.172, 192.229.211.108, 142.251.15.94
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.olocheckout.com.cdn.cloudflare.net, fe3cr.delivery.mp.microsoft.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (7892), with no line terminators
          Category:downloaded
          Size (bytes):7892
          Entropy (8bit):5.785248342291941
          Encrypted:false
          SSDEEP:192:KttF4HC1qDCdMesGKXbZoUkK2DLK1Vqw2:KtiHC1qDCdMesLr2dKueKw2
          MD5:02853CB0D4C22BF7FABEC12645679131
          SHA1:07927E5F3E43063DDC8FFDD357A19B1B772ACF15
          SHA-256:F7332A0C6F71E42087C815027BBE839294079F2254CFD79DB962C55136EF7923
          SHA-512:4675F0341D9598E294A84F8D6A67C94419906F9F6D07E573AB69364ADD5160E459F0AEE73B1596036E6F5BABE789A745A1E49E58D0FF741FD1F13F0F39747F69
          Malicious:false
          Reputation:low
          URL:https://www.olocheckout.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/471dc2adc340/main.js
          Preview:window._cf_chl_opt={cFPWv:'b'};~function(V,g,h,i,j,k,o,s){V=b,function(c,e,U,f,C){for(U=b,f=c();!![];)try{if(C=parseInt(U(448))/1*(parseInt(U(443))/2)+-parseInt(U(360))/3*(parseInt(U(436))/4)+-parseInt(U(432))/5*(-parseInt(U(402))/6)+-parseInt(U(366))/7+-parseInt(U(431))/8+parseInt(U(362))/9*(parseInt(U(420))/10)+-parseInt(U(444))/11*(-parseInt(U(458))/12),e===C)break;else f.push(f.shift())}catch(D){f.push(f.shift())}}(a,860891),g=this||self,h=g[V(365)],i=function(W,e,f,C){return W=V,e=String[W(414)],f={'h':function(D){return null==D?'':f.g(D,6,function(E,X){return X=b,X(441)[X(392)](E)})},'g':function(D,E,F,Y,G,H,I,J,K,L,M,N,O,P,Q,R,S,T){if(Y=W,null==D)return'';for(H={},I={},J='',K=2,L=3,M=2,N=[],O=0,P=0,Q=0;Q<D[Y(386)];Q+=1)if(R=D[Y(392)](Q),Object[Y(367)][Y(418)][Y(382)](H,R)||(H[R]=L++,I[R]=!0),S=J+R,Object[Y(367)][Y(418)][Y(382)](H,S))J=S;else{if(Object[Y(367)][Y(418)][Y(382)](I,J)){if(256>J[Y(423)](0)){for(G=0;G<M;O<<=1,E-1==P?(P=0,N[Y(404)](F(O)),O=0):P++,G++);for(T=J[Y(423)](0)
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):1245
          Entropy (8bit):5.462849750105637
          Encrypted:false
          SSDEEP:24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
          MD5:5343C1A8B203C162A3BF3870D9F50FD4
          SHA1:04B5B886C20D88B57EEA6D8FF882624A4AC1E51D
          SHA-256:DC1D54DAB6EC8C00F70137927504E4F222C8395F10760B6BEECFCFA94E08249F
          SHA-512:E0F50ACB6061744E825A4051765CEBF23E8C489B55B190739409D8A79BB08DAC8F919247A4E5F65A015EA9C57D326BBEF7EA045163915129E01F316C4958D949
          Malicious:false
          Reputation:low
          URL:https://www.olocheckout.com/favicon.ico
          Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>..<title>404 - File or directory not found.</title>..<style type="text/css">.. ..body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px 10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..background-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}..-->..</style>..</head>..<body>..<div id="header"><h1>Server Error</h1></div>..<div id="content">.. <div class="co
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 19, 2024 18:12:32.225032091 CEST49678443192.168.2.4104.46.162.224
          Apr 19, 2024 18:12:33.709311008 CEST49675443192.168.2.4173.222.162.32
          Apr 19, 2024 18:12:43.323796988 CEST49675443192.168.2.4173.222.162.32
          Apr 19, 2024 18:12:45.116672993 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.116705894 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.116771936 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.117276907 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.117286921 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.193237066 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.193315029 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.193389893 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.197032928 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.197067022 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.346995115 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.347443104 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.347450018 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.349159956 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.349232912 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.350785017 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.350881100 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.395711899 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.395719051 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:45.415370941 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.415436983 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.418564081 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.418591022 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.418838024 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.442569971 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:45.458211899 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.481640100 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.528142929 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.619210005 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.619267941 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.619316101 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.620800972 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.620843887 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.620903015 CEST49745443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.620918989 CEST4434974523.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.670361996 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.670444965 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.670700073 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.671045065 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.671092033 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.883915901 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.884066105 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.885603905 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.885628939 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.885873079 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:45.887034893 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:45.928188086 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:46.091861963 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:46.091926098 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:46.092113972 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:46.092744112 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:46.092744112 CEST49746443192.168.2.423.63.206.91
          Apr 19, 2024 18:12:46.092775106 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:46.092789888 CEST4434974623.63.206.91192.168.2.4
          Apr 19, 2024 18:12:55.335403919 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:55.335566998 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:55.335665941 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:55.459402084 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:55.459430933 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:55.460692883 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:55.461850882 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:55.461869001 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:55.880377054 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:55.880652905 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:55.882827997 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:55.882837057 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:55.883234024 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:55.927061081 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.267463923 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.312114000 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531161070 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531188965 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531198978 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531215906 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531240940 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.531259060 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531270981 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531285048 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.531306982 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.531315088 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531403065 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.531502962 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.531615973 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.758770943 CEST49744443192.168.2.4108.177.122.104
          Apr 19, 2024 18:12:56.758799076 CEST44349744108.177.122.104192.168.2.4
          Apr 19, 2024 18:12:56.774380922 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.774394989 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:12:56.774406910 CEST49747443192.168.2.413.85.23.86
          Apr 19, 2024 18:12:56.774413109 CEST4434974713.85.23.86192.168.2.4
          Apr 19, 2024 18:13:33.185625076 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.185708046 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:33.185796976 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.186343908 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.186408997 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:33.602102995 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:33.602332115 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.608186007 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.608257055 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:33.608676910 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:33.623903990 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:33.664128065 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.007992983 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008053064 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008095980 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008198977 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.008265018 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008312941 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.008332968 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008368015 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008403063 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.008403063 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.008433104 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008546114 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.008585930 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.009051085 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.015559912 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.015619040 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:34.015664101 CEST49753443192.168.2.452.165.165.26
          Apr 19, 2024 18:13:34.015681028 CEST4434975352.165.165.26192.168.2.4
          Apr 19, 2024 18:13:45.308836937 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:45.308876991 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.308945894 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:45.309205055 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:45.309216976 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.524760008 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.530107021 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:45.530133963 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.530633926 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.531325102 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:45.531409025 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:45.582658052 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:51.161746979 CEST4972380192.168.2.4199.232.214.172
          Apr 19, 2024 18:13:51.161900043 CEST4972480192.168.2.4199.232.214.172
          Apr 19, 2024 18:13:51.265816927 CEST8049724199.232.214.172192.168.2.4
          Apr 19, 2024 18:13:51.265865088 CEST8049724199.232.214.172192.168.2.4
          Apr 19, 2024 18:13:51.265899897 CEST8049723199.232.214.172192.168.2.4
          Apr 19, 2024 18:13:51.265934944 CEST8049723199.232.214.172192.168.2.4
          Apr 19, 2024 18:13:51.265973091 CEST4972480192.168.2.4199.232.214.172
          Apr 19, 2024 18:13:51.265988111 CEST4972380192.168.2.4199.232.214.172
          Apr 19, 2024 18:13:55.526510954 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:55.526669025 CEST44349755108.177.122.104192.168.2.4
          Apr 19, 2024 18:13:55.526793957 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:56.756864071 CEST49755443192.168.2.4108.177.122.104
          Apr 19, 2024 18:13:56.756891966 CEST44349755108.177.122.104192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Apr 19, 2024 18:12:40.472615004 CEST53537301.1.1.1192.168.2.4
          Apr 19, 2024 18:12:40.487799883 CEST53584901.1.1.1192.168.2.4
          Apr 19, 2024 18:12:41.172698975 CEST53518761.1.1.1192.168.2.4
          Apr 19, 2024 18:12:42.059171915 CEST5959453192.168.2.41.1.1.1
          Apr 19, 2024 18:12:42.059303045 CEST5608853192.168.2.41.1.1.1
          Apr 19, 2024 18:12:43.968839884 CEST6547153192.168.2.41.1.1.1
          Apr 19, 2024 18:12:43.969393969 CEST6388953192.168.2.41.1.1.1
          Apr 19, 2024 18:12:45.009335041 CEST5566553192.168.2.41.1.1.1
          Apr 19, 2024 18:12:45.009536028 CEST5239953192.168.2.41.1.1.1
          Apr 19, 2024 18:12:45.114773035 CEST53523991.1.1.1192.168.2.4
          Apr 19, 2024 18:12:45.114835978 CEST53556651.1.1.1192.168.2.4
          Apr 19, 2024 18:12:58.205936909 CEST53498351.1.1.1192.168.2.4
          Apr 19, 2024 18:13:02.763681889 CEST138138192.168.2.4192.168.2.255
          Apr 19, 2024 18:13:17.003220081 CEST53641351.1.1.1192.168.2.4
          Apr 19, 2024 18:13:39.753523111 CEST53503321.1.1.1192.168.2.4
          Apr 19, 2024 18:13:40.285139084 CEST53647401.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 19, 2024 18:12:42.059171915 CEST192.168.2.41.1.1.10xc3bStandard query (0)www.olocheckout.comA (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:42.059303045 CEST192.168.2.41.1.1.10xa310Standard query (0)www.olocheckout.com65IN (0x0001)false
          Apr 19, 2024 18:12:43.968839884 CEST192.168.2.41.1.1.10xce9eStandard query (0)www.olocheckout.comA (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:43.969393969 CEST192.168.2.41.1.1.10x6608Standard query (0)www.olocheckout.com65IN (0x0001)false
          Apr 19, 2024 18:12:45.009335041 CEST192.168.2.41.1.1.10xd497Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.009536028 CEST192.168.2.41.1.1.10x5183Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 19, 2024 18:12:42.168207884 CEST1.1.1.1192.168.2.40xa310No error (0)www.olocheckout.comwww.olocheckout.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
          Apr 19, 2024 18:12:42.168519020 CEST1.1.1.1192.168.2.40xc3bNo error (0)www.olocheckout.comwww.olocheckout.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
          Apr 19, 2024 18:12:44.078022957 CEST1.1.1.1192.168.2.40x6608No error (0)www.olocheckout.comwww.olocheckout.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
          Apr 19, 2024 18:12:44.079765081 CEST1.1.1.1192.168.2.40xce9eNo error (0)www.olocheckout.comwww.olocheckout.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
          Apr 19, 2024 18:12:45.114773035 CEST1.1.1.1192.168.2.40x5183No error (0)www.google.com65IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.104A (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.105A (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.106A (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.99A (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.147A (IP address)IN (0x0001)false
          Apr 19, 2024 18:12:45.114835978 CEST1.1.1.1192.168.2.40xd497No error (0)www.google.com108.177.122.103A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • slscr.update.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44974523.63.206.91443
          TimestampBytes transferredDirectionData
          2024-04-19 16:12:45 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-19 16:12:45 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/073D)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=139863
          Date: Fri, 19 Apr 2024 16:12:45 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44974623.63.206.91443
          TimestampBytes transferredDirectionData
          2024-04-19 16:12:45 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-19 16:12:46 UTC531INHTTP/1.1 200 OK
          Content-Type: application/octet-stream
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=139847
          Date: Fri, 19 Apr 2024 16:12:46 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-19 16:12:46 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.44974713.85.23.86443
          TimestampBytes transferredDirectionData
          2024-04-19 16:12:56 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=kAoP1pgTGSGy8Uc&MD=nKDYz6+2 HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
          Host: slscr.update.microsoft.com
          2024-04-19 16:12:56 UTC560INHTTP/1.1 200 OK
          Cache-Control: no-cache
          Pragma: no-cache
          Content-Type: application/octet-stream
          Expires: -1
          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
          ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
          MS-CorrelationId: 86951582-ddca-4948-9657-d0afcd8d2625
          MS-RequestId: 6b82bc6f-4fac-4bbc-b1bd-e0c89127b8c5
          MS-CV: PE270psymUiZPV8u.0
          X-Microsoft-SLSClientCache: 2880
          Content-Disposition: attachment; filename=environment.cab
          X-Content-Type-Options: nosniff
          Date: Fri, 19 Apr 2024 16:12:56 GMT
          Connection: close
          Content-Length: 24490
          2024-04-19 16:12:56 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
          Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
          2024-04-19 16:12:56 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
          Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.44975352.165.165.26443
          TimestampBytes transferredDirectionData
          2024-04-19 16:13:33 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=kAoP1pgTGSGy8Uc&MD=nKDYz6+2 HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
          Host: slscr.update.microsoft.com
          2024-04-19 16:13:34 UTC560INHTTP/1.1 200 OK
          Cache-Control: no-cache
          Pragma: no-cache
          Content-Type: application/octet-stream
          Expires: -1
          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
          ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
          MS-CorrelationId: 1b52e088-6152-4638-b40b-d6e41dfb5984
          MS-RequestId: a8686976-106a-4575-9f8b-30cf707910c3
          MS-CV: fld/34l3pU6IwDr+.0
          X-Microsoft-SLSClientCache: 2160
          Content-Disposition: attachment; filename=environment.cab
          X-Content-Type-Options: nosniff
          Date: Fri, 19 Apr 2024 16:13:33 GMT
          Connection: close
          Content-Length: 25457
          2024-04-19 16:13:34 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
          Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
          2024-04-19 16:13:34 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
          Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:18:12:35
          Start date:19/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:18:12:38
          Start date:19/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1692 --field-trial-handle=2032,i,10411871364476025621,2517455805364260529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:18:12:40
          Start date:19/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.olocheckout.com/checkout?brandaccessid=_5-oyxhachgzbaleemezfwqed79pp64e&fieldtype=cardnumber&frameid=57xrvcm69qd&version=2.4.0&basketguid=9c85ab6e-3b5f-491c-bb69-0e9d94a3e989"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly