Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f

Overview

General Information

Sample URL:http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f
Analysis ID:1428873
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 5416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2164,i,10803920880633017169,8689222890076807710,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3948 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49717 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49717 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: google.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713545394781&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: classification engineClassification label: unknown1.win@19/6@4/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2164,i,10803920880633017169,8689222890076807710,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2164,i,10803920880633017169,8689222890076807710,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1428873 URL: http://6743431bef3d4ab5dccb... Startdate: 19/04/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 8 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49703, 49712 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 173.194.219.105, 443, 49712 GOOGLEUS United States 10->17 19 google.com 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.11.100
truefalse
    high
    www.google.com
    173.194.219.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        173.194.219.105
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.5
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1428873
        Start date and time:2024-04-19 18:49:13 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 17s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:6
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown1.win@19/6@4/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 64.233.176.100, 64.233.176.113, 64.233.176.101, 64.233.176.102, 64.233.176.138, 64.233.176.139, 142.250.9.94, 64.233.185.84, 34.104.35.123, 23.197.2.6, 13.85.23.86, 199.232.214.172, 192.229.211.108, 23.40.205.9, 23.40.205.26, 23.40.205.8, 23.40.205.16, 23.40.205.11, 23.40.205.48, 23.40.205.32, 23.40.205.80, 23.40.205.83, 20.3.187.198
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:50:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2677
        Entropy (8bit):3.978567228129121
        Encrypted:false
        SSDEEP:48:8KdGTiS2HzidAKZdA19ehwiZUklqehNy+3:8LTKKy
        MD5:D77703C494175845935680DA383BE8ED
        SHA1:DBBBF04545C5199062B07D7E09DB23484DECFF4B
        SHA-256:BEFB4AC57865769CF81CC6368A8AAE57AD220C2B82C44A69A72AA67799DB50A1
        SHA-512:37455AF5836AA23FA4F6D7869049DFF7BFB7F9B407BE775AB05913B2651196DC7C4B343B3B4F2E7C504567D20CBCF36EF16DC7D328CDB347E7FF596AE690DF28
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....$M.y...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XH............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:50:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2679
        Entropy (8bit):3.9918444215011326
        Encrypted:false
        SSDEEP:48:8pBdGTiS2HzidAKZdA1weh/iZUkAQkqeh6y+2:88TA9Q/y
        MD5:E3AF4FE54B7D405CD8B2D15D9E2BEDE6
        SHA1:694CC46731D16D809712B58B55A2F3219400C7CD
        SHA-256:26CF20545A0FAAFCA0B156483DB282DD010D30AB31330F5B094F3648B9182B74
        SHA-512:D700306541548C5595B8D7CAE46DF2C7A35EA998C87AB82C3F6E7BBCB208ED1C921FA49A398E6D184BCD2C292BB4810123FC4507E2A91098979B9E14AA6D30E5
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,......C.y...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XH............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2693
        Entropy (8bit):4.005016511528137
        Encrypted:false
        SSDEEP:48:8xbdGTiSsHzidAKZdA14tseh7sFiZUkmgqeh7s8y+BX:8xgT2n2y
        MD5:2B89DF36CFD5D3BA427338059B949BF7
        SHA1:1894746197B4AAB0FAE4A4BD12A4DEDA52EF4441
        SHA-256:74A117C951B58B085EA05049113E192713C3371601882D38C8FDCDEDB67A9401
        SHA-512:D45A874D8CDC86BD39A30F0A6F76EF193751FF3717F0FF5342A01154224FC6375ACA8922D7C0574145A3B998EBAC9A935F2EE4CF46BCFFF750FE0630B5CE5DD6
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:50:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2681
        Entropy (8bit):3.991490079277591
        Encrypted:false
        SSDEEP:48:8PcdGTiS2HzidAKZdA1vehDiZUkwqehOy+R:8RTL0y
        MD5:AFCDF0E1506C0705AF7E257614333AFF
        SHA1:199E85B3EF2752EF02AE1688A702BD49671F9D94
        SHA-256:E43C6EFA9FB1ADA33575BD4AB9D4D9C4F78287E8E5FD9A8A18A674886E9FDD01
        SHA-512:2E8DCFA3A80F555977CEA56BDBB60FADA01A7CB42FE56C41EEF45BADBC04CBE62F8EC6D1799AA7CDB694EE7C3E9DA65ABA7D2DD75DC1C650F5AD15088F28623D
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....t<.y...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XH............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:50:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2681
        Entropy (8bit):3.979128276727101
        Encrypted:false
        SSDEEP:48:81dGTiS2HzidAKZdA1hehBiZUk1W1qehYy+C:8uTL94y
        MD5:7485094D78AC81E685B3E38DB0C10DB4
        SHA1:CA2654A5D545991F5B66F6F9DCE7B30B41B58EA0
        SHA-256:2706172D1E7F3051944203C73B0E6342C7010732D622451E20BFC8D66A2B65DE
        SHA-512:5B5CB618B26EFD3CC40B513F13E4AC5147FBCD583689320696EF3232B4CA975240CA69C53BD4FCC3CADE78A57D22FCFC86980F4C86A784C72EB5764388049DEE
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,....4`H.y...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XH............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 15:50:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2683
        Entropy (8bit):3.9915052105156197
        Encrypted:false
        SSDEEP:48:8OdGTiS2HzidAKZdA1duT+ehOuTbbiZUk5OjqehOuTb2y+yT+:8/TrT/TbxWOvTb2y7T
        MD5:857FBC32A7A6FD18D93282E645C3CF0B
        SHA1:3DEC78111D711906F55922B4C79A53BAAECAF1A3
        SHA-256:F70DE4CEAFA5931B1939928922C9A91C287407328527BE03B8CF600B6E90314D
        SHA-512:20B53C411BF859B229998EBE5154B12F90156EDC6C43141D27D4B019C88A25DE87F8A460807E0A665365B6675F56733C65995E1821A636EABF6459B13B1DC776
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....6.y...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XF.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XF.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XF.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XF............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XH............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........5........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 19, 2024 18:50:05.398732901 CEST49675443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:05.399199963 CEST49674443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:05.555238962 CEST49673443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:15.053359032 CEST49675443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:15.147089005 CEST49674443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:15.256477118 CEST49673443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:16.635338068 CEST4434970323.1.237.91192.168.2.5
        Apr 19, 2024 18:50:16.635464907 CEST49703443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:19.078232050 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.078293085 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.078902960 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.079561949 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.079592943 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.296900988 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.307178020 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.307215929 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.308278084 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.308371067 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.353173018 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.353251934 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.397778988 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:19.397799015 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:19.444694042 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:26.514095068 CEST49703443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.514292955 CEST49703443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.514915943 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.514993906 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.515188932 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.516477108 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.516511917 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.666560888 CEST4434970323.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.666620970 CEST4434970323.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.834458113 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.834549904 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.851793051 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.851826906 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.852257967 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.852320910 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.852840900 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.852883101 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:26.853094101 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:26.853106022 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:27.189277887 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:27.189367056 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:27.189493895 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:27.189552069 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:27.189615965 CEST4434971723.1.237.91192.168.2.5
        Apr 19, 2024 18:50:27.189699888 CEST49717443192.168.2.523.1.237.91
        Apr 19, 2024 18:50:29.296776056 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:29.296834946 CEST44349712173.194.219.105192.168.2.5
        Apr 19, 2024 18:50:29.297122002 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:30.964648962 CEST49712443192.168.2.5173.194.219.105
        Apr 19, 2024 18:50:30.964678049 CEST44349712173.194.219.105192.168.2.5
        TimestampSource PortDest PortSource IPDest IP
        Apr 19, 2024 18:50:14.870491028 CEST53589191.1.1.1192.168.2.5
        Apr 19, 2024 18:50:14.871144056 CEST53623671.1.1.1192.168.2.5
        Apr 19, 2024 18:50:15.494775057 CEST53525891.1.1.1192.168.2.5
        Apr 19, 2024 18:50:16.436615944 CEST5887753192.168.2.58.8.8.8
        Apr 19, 2024 18:50:16.437033892 CEST5050953192.168.2.51.1.1.1
        Apr 19, 2024 18:50:16.542118073 CEST53588778.8.8.8192.168.2.5
        Apr 19, 2024 18:50:16.542232037 CEST53505091.1.1.1192.168.2.5
        Apr 19, 2024 18:50:18.970662117 CEST5706553192.168.2.51.1.1.1
        Apr 19, 2024 18:50:18.971514940 CEST5680653192.168.2.51.1.1.1
        Apr 19, 2024 18:50:19.075773001 CEST53570651.1.1.1192.168.2.5
        Apr 19, 2024 18:50:19.076010942 CEST53568061.1.1.1192.168.2.5
        Apr 19, 2024 18:50:32.451009989 CEST53625351.1.1.1192.168.2.5
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 19, 2024 18:50:16.436615944 CEST192.168.2.58.8.8.80xf94cStandard query (0)google.comA (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.437033892 CEST192.168.2.51.1.1.10x8c94Standard query (0)google.comA (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:18.970662117 CEST192.168.2.51.1.1.10x4af1Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:18.971514940 CEST192.168.2.51.1.1.10xc61Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.100A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.101A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.102A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.138A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.113A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542118073 CEST8.8.8.8192.168.2.50xf94cNo error (0)google.com142.250.11.139A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.102A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.138A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.139A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.100A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.101A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:16.542232037 CEST1.1.1.1192.168.2.50x8c94No error (0)google.com172.253.124.113A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.105A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.147A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.104A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.103A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.99A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.075773001 CEST1.1.1.1192.168.2.50x4af1No error (0)www.google.com173.194.219.106A (IP address)IN (0x0001)false
        Apr 19, 2024 18:50:19.076010942 CEST1.1.1.1192.168.2.50xc61No error (0)www.google.com65IN (0x0001)false
        Apr 19, 2024 18:50:26.297297955 CEST1.1.1.1192.168.2.50xc93eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 19, 2024 18:50:26.297297955 CEST1.1.1.1192.168.2.50xc93eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • https:
          • www.bing.com
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.54971723.1.237.91443
        TimestampBytes transferredDirectionData
        2024-04-19 16:50:26 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
        Origin: https://www.bing.com
        Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
        Accept: */*
        Accept-Language: en-CH
        Content-type: text/xml
        X-Agent-DeviceId: 01000A410900D492
        X-BM-CBT: 1696428841
        X-BM-DateFormat: dd/MM/yyyy
        X-BM-DeviceDimensions: 784x984
        X-BM-DeviceDimensionsLogical: 784x984
        X-BM-DeviceScale: 100
        X-BM-DTZ: 120
        X-BM-Market: CH
        X-BM-Theme: 000000;0078d7
        X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
        X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
        X-Device-isOptin: false
        X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
        X-Device-OSSKU: 48
        X-Device-Touch: false
        X-DeviceID: 01000A410900D492
        X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
        X-MSEdge-ExternalExpType: JointCoord
        X-PositionerType: Desktop
        X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
        X-Search-CortanaAvailableCapabilities: None
        X-Search-SafeSearch: Moderate
        X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
        X-UserAgeClass: Unknown
        Accept-Encoding: gzip, deflate, br
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
        Host: www.bing.com
        Content-Length: 2484
        Connection: Keep-Alive
        Cache-Control: no-cache
        Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713545394781&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
        2024-04-19 16:50:26 UTC1OUTData Raw: 3c
        Data Ascii: <
        2024-04-19 16:50:26 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
        Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
        2024-04-19 16:50:27 UTC480INHTTP/1.1 204 No Content
        Access-Control-Allow-Origin: *
        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
        X-MSEdge-Ref: Ref A: 34A991FF7F6D4F21B50595CF897F1658 Ref B: LAX311000111033 Ref C: 2024-04-19T16:50:27Z
        Date: Fri, 19 Apr 2024 16:50:27 GMT
        Connection: close
        Alt-Svc: h3=":443"; ma=93600
        X-CDN-TraceID: 0.57ed0117.1713545426.124d6bf2


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:18:50:08
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:18:50:12
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2164,i,10803920880633017169,8689222890076807710,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:18:50:14
        Start date:19/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://6743431bef3d4ab5dccbaa0f238647ee109ddfe4167e3f1e737ca36138a54d7f"
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly