Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2

Overview

General Information

Sample URL:https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2
Analysis ID:1428879
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6256 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2352,i,4671588504332305712,13636946270834276244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5988 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownHTTPS traffic detected: 184.24.36.112:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.24.36.112:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 184.24.36.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2 HTTP/1.1Host: sales.sganalytics.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sales.sganalytics.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sales.sganalytics.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: sales.sganalytics.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713546418051&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.24.36.112:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.24.36.112:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/9@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2352,i,4671588504332305712,13636946270834276244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2352,i,4671588504332305712,13636946270834276244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    www.google.com
    173.194.219.104
    truefalse
      high
      us1-cx.outplayhq.com
      35.82.218.25
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          sales.sganalytics.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2false
              unknown
              https://sales.sganalytics.com/favicon.icofalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                44.233.6.157
                unknownUnited States
                16509AMAZON-02USfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                173.194.219.104
                www.google.comUnited States
                15169GOOGLEUSfalse
                35.82.218.25
                us1-cx.outplayhq.comUnited States
                237MERIT-AS-14USfalse
                IP
                192.168.2.4
                192.168.2.5
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1428879
                Start date and time:2024-04-19 19:06:25 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 14s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean1.win@16/9@6/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 173.194.219.94, 172.217.215.113, 172.217.215.100, 172.217.215.101, 172.217.215.102, 172.217.215.139, 172.217.215.138, 74.125.136.84, 34.104.35.123, 40.127.169.103, 23.40.205.32, 23.40.205.26, 23.40.205.16, 23.40.205.34, 23.40.205.43, 23.40.205.18, 23.40.205.49, 23.40.205.17, 23.40.205.66, 23.40.205.73, 192.229.211.108, 20.3.187.198, 64.233.185.94, 199.232.214.172
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 16:07:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.991189734644556
                Encrypted:false
                SSDEEP:48:8ZRdUTYsYH2idAKZdA19ehwiZUklqehAy+3:8ZgfN/y
                MD5:21CB1B54888A3D8716E017385DA48272
                SHA1:7F179E4CC1E989077D7ED7615EDFAF27607097E5
                SHA-256:E7F82E314C3F6E9A88BFC7F60CEC7F607A33D405BF827C87B28E9C3E0E5FB3DD
                SHA-512:5B015EAD6CDA43C9894675342ED01ACE025F262E081F97F07A606643807E2AD87595681C823103F9BFEA4C14E87BE1137C31B914AEFA3EBD481A1BA4CF785DD9
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....7q.|...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 16:07:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):4.00430593664778
                Encrypted:false
                SSDEEP:48:8YdUTYsYH2idAKZdA1weh/iZUkAQkqehvy+2:8nfn9QKy
                MD5:7597810EF41C04F2D0048580142F904B
                SHA1:C5665F70773DE7F03F754F219DBCF00DC14FCB4C
                SHA-256:8F683DD194DFD343CAB93708195C1453E97FB501A2D0A413FAEF95E695D1B1DB
                SHA-512:92F6F34A5A9449DDA8110038916097E06858AEC8DCFFD6E3FC5F0FC4375DABE16C4DAF15F2DBA2021BA2C108AF3B5FCED858FC87A030676E31348E154349B121
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......a.|...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2693
                Entropy (8bit):4.01397051596128
                Encrypted:false
                SSDEEP:48:8xNdUTYssH2idAKZdA14tseh7sFiZUkmgqeh7spy+BX:8xUfLnLy
                MD5:FF07EEFB35661D0E199EC615E50CC8E0
                SHA1:B171FA97754B0A04CB7043004BE590B39D92630E
                SHA-256:B48B832019FC6EE69A54D17196B3A8EBE258D6C1D0FCEB084A59C2642F4D4555
                SHA-512:16865AFE4F87496D547E1351AF70C1707AB1283A0F61DC0075618A6069B96CEE995B4A4EEEF28F211DBE309C0E60F1440A1862A653CF1ADE235B486C632C7833
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 16:07:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):4.004669683826471
                Encrypted:false
                SSDEEP:48:8H8RdUTYsYH2idAKZdA1vehDiZUkwqehzy+R:8HHfExy
                MD5:019028AA22D5BE1119A77A1508AF0E21
                SHA1:52D57B9296227A240CCBAFE5BD524AE3CCFE3502
                SHA-256:52B0946ED1B26FF5363F20969FD50DBA6188EB93F99930DDCB908B5599B813CA
                SHA-512:B4E33CEA1A1932F73030745C3E6E214E3640DF45D6ECA76657BBB627D39EA783E842B97C7645B9C86DF346E4BECFD240FB010561E393308AD741122069D25488
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,..../.Y.|...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 16:07:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.99169782792546
                Encrypted:false
                SSDEEP:48:8TdUTYsYH2idAKZdA1hehBiZUk1W1qehVy+C:8CfE91y
                MD5:AFED7EAABC99A45042297D4B918A662D
                SHA1:5658C98A09792CBE75BE55190EDB3BD4F2843993
                SHA-256:7A592D593118C66306B7473C42F1B1C75A5F03636DAE21337B173AA256105ABC
                SHA-512:DF02FD845E23567ED1C46F24AA4556A29C747F769E30350B9AD1D28D907AB5A5763D8D0C52F6737CB6D4770172C085D5DA045824294345A3F6CF1B2CF7ABBF2D
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....Rh.|...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 16:07:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2683
                Entropy (8bit):4.0053392289711205
                Encrypted:false
                SSDEEP:48:8adUTYsYH2idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8hfqT/TbxWOvTbLy7T
                MD5:5FE290F713559F08FEC376EA1B469957
                SHA1:7B2894C8D63611A80445E8FDBCF3E9F94FA4A9A0
                SHA-256:F8949C983F13C3B79175F6B078F50A14C338A3027FFE0025BB5CEDEBD97BA07F
                SHA-512:E3CAA2340628DEE21298EAEFDA835410851C74E6C8EE5C54E4A2A5648661282B466AD73BE84D74937773B69ABBA43A0527662078312A1926DD527D579FBEDF01
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......O.|...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
                Category:dropped
                Size (bytes):5430
                Entropy (8bit):5.292542388562385
                Encrypted:false
                SSDEEP:96:cr+NYnzNJKil6fxxRJxfCoIfCOmcdCRfbNgFsLT+joiM4S:GnKEKxxLI0bcslyFsedMx
                MD5:9200225B96881264E6481C77D69C622C
                SHA1:27608D84E28F926B740038252240F715EEB9D2BD
                SHA-256:26DC5FF4BFB9213291735808465E156D4A4691135F3815E3613761243E1F69C3
                SHA-512:B236B79924C705DCA8B60FE07C886B3AF2DF0BCC13BE6B915063FCDF691775A941DE3EEE5B59068508B55A7A9F5EC07D19792946D9F04B8B0CB95CB73EE10236
                Malicious:false
                Reputation:low
                Preview:...... .... .....&......... .h.......(... ...@..... .................................................................................((()...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................C..G..A..B................................................................................................................J..P..X..X................................................................................................................I..\..N..K................................................................................................................L..^..N..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
                Category:downloaded
                Size (bytes):5430
                Entropy (8bit):5.292542388562385
                Encrypted:false
                SSDEEP:96:cr+NYnzNJKil6fxxRJxfCoIfCOmcdCRfbNgFsLT+joiM4S:GnKEKxxLI0bcslyFsedMx
                MD5:9200225B96881264E6481C77D69C622C
                SHA1:27608D84E28F926B740038252240F715EEB9D2BD
                SHA-256:26DC5FF4BFB9213291735808465E156D4A4691135F3815E3613761243E1F69C3
                SHA-512:B236B79924C705DCA8B60FE07C886B3AF2DF0BCC13BE6B915063FCDF691775A941DE3EEE5B59068508B55A7A9F5EC07D19792946D9F04B8B0CB95CB73EE10236
                Malicious:false
                Reputation:low
                URL:https://sales.sganalytics.com/favicon.ico
                Preview:...... .... .....&......... .h.......(... ...@..... .................................................................................((()...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................C..G..A..B................................................................................................................J..P..X..X................................................................................................................I..\..N..K................................................................................................................L..^..N..
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 19, 2024 19:07:07.871143103 CEST49674443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:07.871156931 CEST49675443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:07.968724966 CEST49673443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:15.053056002 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.053102970 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.053174973 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.053659916 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.053668976 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.053723097 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.053991079 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.054008961 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.054147005 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.054158926 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.421319008 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.421986103 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.437465906 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.437536001 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.439117908 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.439230919 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.440126896 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.440144062 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.440912008 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.440994024 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.441772938 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.441862106 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.441914082 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.441971064 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.443084955 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.443286896 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.443299055 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.443644047 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.443824053 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.486814976 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.486814976 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.486880064 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.486922026 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.534451962 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.534452915 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.765434027 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.765930891 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.766094923 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.773549080 CEST49711443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.773593903 CEST4434971135.82.218.25192.168.2.5
                Apr 19, 2024 19:07:15.907969952 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:15.952121019 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.086118937 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.086174965 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.086288929 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:16.086355925 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.086407900 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.086424112 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:16.086457014 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:16.090651035 CEST49712443192.168.2.535.82.218.25
                Apr 19, 2024 19:07:16.090686083 CEST4434971235.82.218.25192.168.2.5
                Apr 19, 2024 19:07:16.380125999 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.380151987 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:16.380213022 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.380969048 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.380981922 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:16.516432047 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.516510963 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.516587973 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.526159048 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.526197910 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.608973026 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:16.658457041 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.662663937 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.662671089 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:16.666549921 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:16.666618109 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:16.882817984 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.889446020 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.889506102 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.890093088 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.890167952 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.891088963 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.891164064 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.895210981 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.895298958 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.895422935 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:16.895437956 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:16.939743042 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:17.156086922 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:17.156260967 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:17.205456972 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:17.205476046 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:17.237191916 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.237288952 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.241347075 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.244705915 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.244744062 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.248522997 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.248544931 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.248697042 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.248724937 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:17.248754025 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.248778105 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.248784065 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:17.248904943 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:17.252238989 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:17.265058994 CEST49714443192.168.2.544.233.6.157
                Apr 19, 2024 19:07:17.265089989 CEST4434971444.233.6.157192.168.2.5
                Apr 19, 2024 19:07:17.464850903 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.465176105 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.469512939 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.469527006 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.469927073 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.473052025 CEST49674443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:17.489039898 CEST49675443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:17.517870903 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.558816910 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.580512047 CEST49673443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:17.600159883 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.665528059 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.665721893 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.665857077 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.666038990 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.666038990 CEST49715443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.666060925 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.666066885 CEST44349715184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.713048935 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.713083029 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.717216015 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.717672110 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.717688084 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.929409981 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.929594040 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.932395935 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.932403088 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.932604074 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:17.935161114 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:17.976109028 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:18.137777090 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:18.137840986 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:18.137907028 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:18.138712883 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:18.138751030 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:18.138781071 CEST49716443192.168.2.5184.24.36.112
                Apr 19, 2024 19:07:18.138797045 CEST44349716184.24.36.112192.168.2.5
                Apr 19, 2024 19:07:18.955483913 CEST4434970323.1.237.91192.168.2.5
                Apr 19, 2024 19:07:18.955595016 CEST49703443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:26.591867924 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:26.592004061 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:26.592472076 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:26.802141905 CEST49713443192.168.2.5173.194.219.104
                Apr 19, 2024 19:07:26.802201986 CEST44349713173.194.219.104192.168.2.5
                Apr 19, 2024 19:07:29.383306980 CEST49703443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.383495092 CEST49703443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.384088039 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.384141922 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.384211063 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.384502888 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.384521008 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.539139986 CEST4434970323.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.539160967 CEST4434970323.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.712706089 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.712779045 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.845992088 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.846018076 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.846611023 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.846664906 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.847312927 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.847361088 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:29.847677946 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:29.847686052 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:30.109481096 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:30.109622002 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:30.109666109 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:30.109726906 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:30.109740019 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:30.109800100 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:30.283283949 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:30.283332109 CEST4434972223.1.237.91192.168.2.5
                Apr 19, 2024 19:07:30.283361912 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:07:30.283396959 CEST49722443192.168.2.523.1.237.91
                Apr 19, 2024 19:08:16.332483053 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:16.332537889 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.332616091 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:16.333000898 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:16.333014965 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.555907011 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.556229115 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:16.556247950 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.556710958 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.557018995 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:16.557092905 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:16.596688032 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:26.562959909 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:26.563152075 CEST44349727173.194.219.104192.168.2.5
                Apr 19, 2024 19:08:26.563224077 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:27.089170933 CEST49727443192.168.2.5173.194.219.104
                Apr 19, 2024 19:08:27.089251041 CEST44349727173.194.219.104192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Apr 19, 2024 19:07:12.605889082 CEST53551981.1.1.1192.168.2.5
                Apr 19, 2024 19:07:12.615453959 CEST53569021.1.1.1192.168.2.5
                Apr 19, 2024 19:07:13.222343922 CEST53556191.1.1.1192.168.2.5
                Apr 19, 2024 19:07:14.449368000 CEST6028153192.168.2.51.1.1.1
                Apr 19, 2024 19:07:14.449517012 CEST6358453192.168.2.51.1.1.1
                Apr 19, 2024 19:07:15.032963991 CEST53635841.1.1.1192.168.2.5
                Apr 19, 2024 19:07:15.051974058 CEST53602811.1.1.1192.168.2.5
                Apr 19, 2024 19:07:16.106029034 CEST6254753192.168.2.51.1.1.1
                Apr 19, 2024 19:07:16.106462955 CEST5425453192.168.2.51.1.1.1
                Apr 19, 2024 19:07:16.272366047 CEST5400753192.168.2.51.1.1.1
                Apr 19, 2024 19:07:16.272917032 CEST5622153192.168.2.51.1.1.1
                Apr 19, 2024 19:07:16.376977921 CEST53540071.1.1.1192.168.2.5
                Apr 19, 2024 19:07:16.377697945 CEST53562211.1.1.1192.168.2.5
                Apr 19, 2024 19:07:16.440660954 CEST53625471.1.1.1192.168.2.5
                Apr 19, 2024 19:07:16.698317051 CEST53542541.1.1.1192.168.2.5
                Apr 19, 2024 19:07:31.014817953 CEST53587221.1.1.1192.168.2.5
                Apr 19, 2024 19:07:49.969783068 CEST53595001.1.1.1192.168.2.5
                Apr 19, 2024 19:08:11.826966047 CEST53559321.1.1.1192.168.2.5
                Apr 19, 2024 19:08:12.714426041 CEST53542501.1.1.1192.168.2.5
                TimestampSource IPDest IPChecksumCodeType
                Apr 19, 2024 19:07:16.698435068 CEST192.168.2.51.1.1.1c284(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 19, 2024 19:07:14.449368000 CEST192.168.2.51.1.1.10xdc1eStandard query (0)sales.sganalytics.comA (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:14.449517012 CEST192.168.2.51.1.1.10x9a0eStandard query (0)sales.sganalytics.com65IN (0x0001)false
                Apr 19, 2024 19:07:16.106029034 CEST192.168.2.51.1.1.10xc550Standard query (0)sales.sganalytics.comA (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.106462955 CEST192.168.2.51.1.1.10x8d7bStandard query (0)sales.sganalytics.com65IN (0x0001)false
                Apr 19, 2024 19:07:16.272366047 CEST192.168.2.51.1.1.10x3686Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.272917032 CEST192.168.2.51.1.1.10x83e4Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 19, 2024 19:07:15.032963991 CEST1.1.1.1192.168.2.50x9a0eNo error (0)sales.sganalytics.comsganalytics.us1.outplayr.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:15.032963991 CEST1.1.1.1192.168.2.50x9a0eNo error (0)sganalytics.us1.outplayr.comus1-cx.outplayhq.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:15.051974058 CEST1.1.1.1192.168.2.50xdc1eNo error (0)sales.sganalytics.comsganalytics.us1.outplayr.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:15.051974058 CEST1.1.1.1192.168.2.50xdc1eNo error (0)sganalytics.us1.outplayr.comus1-cx.outplayhq.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:15.051974058 CEST1.1.1.1192.168.2.50xdc1eNo error (0)us1-cx.outplayhq.com35.82.218.25A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:15.051974058 CEST1.1.1.1192.168.2.50xdc1eNo error (0)us1-cx.outplayhq.com44.233.6.157A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:15.051974058 CEST1.1.1.1192.168.2.50xdc1eNo error (0)us1-cx.outplayhq.com35.167.48.6A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.104A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.106A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.99A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.105A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.103A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.376977921 CEST1.1.1.1192.168.2.50x3686No error (0)www.google.com173.194.219.147A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.377697945 CEST1.1.1.1192.168.2.50x83e4No error (0)www.google.com65IN (0x0001)false
                Apr 19, 2024 19:07:16.440660954 CEST1.1.1.1192.168.2.50xc550No error (0)sales.sganalytics.comsganalytics.us1.outplayr.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:16.440660954 CEST1.1.1.1192.168.2.50xc550No error (0)sganalytics.us1.outplayr.comus1-cx.outplayhq.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:16.440660954 CEST1.1.1.1192.168.2.50xc550No error (0)us1-cx.outplayhq.com44.233.6.157A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.440660954 CEST1.1.1.1192.168.2.50xc550No error (0)us1-cx.outplayhq.com35.167.48.6A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.440660954 CEST1.1.1.1192.168.2.50xc550No error (0)us1-cx.outplayhq.com35.82.218.25A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:16.698317051 CEST1.1.1.1192.168.2.50x8d7bNo error (0)sales.sganalytics.comsganalytics.us1.outplayr.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:16.698317051 CEST1.1.1.1192.168.2.50x8d7bNo error (0)sganalytics.us1.outplayr.comus1-cx.outplayhq.comCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:29.156176090 CEST1.1.1.1192.168.2.50x7897No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:29.156176090 CEST1.1.1.1192.168.2.50x7897No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 19:07:42.492870092 CEST1.1.1.1192.168.2.50x3f8fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:07:42.492870092 CEST1.1.1.1192.168.2.50x3f8fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 19:08:05.094746113 CEST1.1.1.1192.168.2.50xa607No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:08:05.094746113 CEST1.1.1.1192.168.2.50xa607No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 19:08:24.577888966 CEST1.1.1.1192.168.2.50x84b8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 19:08:24.577888966 CEST1.1.1.1192.168.2.50x84b8No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 19:08:30.149144888 CEST1.1.1.1192.168.2.50x6e9aNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 19, 2024 19:08:30.149144888 CEST1.1.1.1192.168.2.50x6e9aNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                • sales.sganalytics.com
                • https:
                  • www.bing.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.54971135.82.218.254435740C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:15 UTC749OUTGET /trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2 HTTP/1.1
                Host: sales.sganalytics.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-19 17:07:15 UTC502INHTTP/1.1 200 OK
                Date: Fri, 19 Apr 2024 17:07:15 GMT
                Content-Type: image/png
                Transfer-Encoding: chunked
                Connection: close
                Cache-Control: no-cache, no-store, must-revalidate, max-age=0
                Permissions-Policy: accelerometer=(), gyroscope=(), magnetometer=(), payment=(), usb=()
                Referrer-Policy: strict-origin-when-cross-origin
                Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                X-Content-Type-Options: nosniff
                X-Robots-Tag: noindex, nofollow
                X-Xss-Protection: 1; mode=block
                2024-04-19 17:07:15 UTC74INData Raw: 34 34 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 01 00 00 00 01 08 06 00 00 00 1f 15 c4 89 00 00 00 0b 49 44 41 54 18 19 63 60 00 02 00 00 05 00 01 2a a6 ff 42 00 00 00 00 49 45 4e 44 ae 42 60 82 0d 0a
                Data Ascii: 44PNGIHDRIDATc`*BIENDB`
                2024-04-19 17:07:15 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.54971235.82.218.254435740C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:15 UTC683OUTGET /favicon.ico HTTP/1.1
                Host: sales.sganalytics.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-19 17:07:16 UTC723INHTTP/1.1 200 OK
                Date: Fri, 19 Apr 2024 17:07:16 GMT
                Content-Type: image/x-icon
                Content-Length: 5430
                Connection: close
                Accept-Ranges: bytes
                Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
                Access-Control-Allow-Origin: *
                Cache-Control: public, max-age=604800
                Etag: "1da921b71b057b6"
                Last-Modified: Fri, 19 Apr 2024 05:35:53 GMT
                Permissions-Policy: accelerometer=(), gyroscope=(), magnetometer=(), payment=(), usb=()
                Referrer-Policy: strict-origin-when-cross-origin
                Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                X-Content-Type-Options: nosniff
                X-Frame-Options: DENY
                X-Op-Machine: production-cx-core-us1-67885988cf-znlm4
                X-Xss-Protection: 1; mode=block
                2024-04-19 17:07:16 UTC3392INData Raw: 00 00 01 00 02 00 20 20 00 00 01 00 20 00 a8 10 00 00 26 00 00 00 10 10 00 00 01 00 20 00 68 04 00 00 ce 10 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 20 00 00 00 00 00 80 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 28 28 28 29 af ae ad bb af ad ad b9 ae ad ac b9 ae ad ac b9 ae ac aa b9 ae ab a9 b9 ad aa a8 b9 ad a9 a7 b9 ad a8 a7 b9 af a9 a7 b7 ae a9 a7 b7 ae a8 a6 b7 ae a8 a5 b7 ae a8 a5 b7 ae a8 a5 b7 ae a8 a6 b7 84 80 7f 8b db da d9 ff d9 d6 d5 ff d8 d6 d5 ff d8 d6 d4 ff d8 d6 d4 ff d8 d5 d4 ff d8 d5 d4 ff d8 d5 d3 ff d8 d5 d3 ff d8 d4 d3 ff d7 d4 d3 ff d7 d4 d2 ff d7
                Data Ascii: & h( @ ((()
                2024-04-19 17:07:16 UTC2038INData Raw: e3 ff cf cf cf ff da da da 7f ff ff ff 01 e7 e7 e7 ff ff ff ff ff ee d6 b7 ff dc a8 69 ff dd ab 6c ff dc a9 69 ff dc a9 6a ff d5 bd 9d ff ff ff ff ff ff ff ff ff ff ff ff ff f6 f4 f3 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff eb e8 e5 ff ea e7 e4 ff ea e7 e4 ff ea e7 e4 ff c2 c0 bf ff be be be ff bf bf bf ff ba ba ba ff be be be ff db db db bf ff ff ff 01 ff ff ff 01 e7 e7 e7 ff ff ff ff ff f6 eb dc ff ee d5 b7 ff ee d6 b8 ff ee d6 b7 ff ee d6 b8 ff df d3 c4 ff ff ff ff ff ff ff ff ff ff ff ff ff f6 f4 f3 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff eb e7 e5 ff ea e7 e4 ff eb e7 e5 ff eb e7 e5 ff c0 be bd ff fe fe fe ff f7 f7 f7 ff e1 e2 e2 ff e2
                Data Ascii: ilij


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.54971444.233.6.1574435740C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:16 UTC356OUTGET /favicon.ico HTTP/1.1
                Host: sales.sganalytics.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: */*
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: cors
                Sec-Fetch-Dest: empty
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-19 17:07:17 UTC723INHTTP/1.1 200 OK
                Date: Fri, 19 Apr 2024 17:07:17 GMT
                Content-Type: image/x-icon
                Content-Length: 5430
                Connection: close
                Accept-Ranges: bytes
                Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept
                Access-Control-Allow-Origin: *
                Cache-Control: public, max-age=604800
                Etag: "1da921b71b057b6"
                Last-Modified: Fri, 19 Apr 2024 05:35:53 GMT
                Permissions-Policy: accelerometer=(), gyroscope=(), magnetometer=(), payment=(), usb=()
                Referrer-Policy: strict-origin-when-cross-origin
                Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                X-Content-Type-Options: nosniff
                X-Frame-Options: DENY
                X-Op-Machine: production-cx-core-us1-67885988cf-znlm4
                X-Xss-Protection: 1; mode=block
                2024-04-19 17:07:17 UTC3392INData Raw: 00 00 01 00 02 00 20 20 00 00 01 00 20 00 a8 10 00 00 26 00 00 00 10 10 00 00 01 00 20 00 68 04 00 00 ce 10 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 20 00 00 00 00 00 80 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 00 00 00 0b 28 28 28 29 af ae ad bb af ad ad b9 ae ad ac b9 ae ad ac b9 ae ac aa b9 ae ab a9 b9 ad aa a8 b9 ad a9 a7 b9 ad a8 a7 b9 af a9 a7 b7 ae a9 a7 b7 ae a8 a6 b7 ae a8 a5 b7 ae a8 a5 b7 ae a8 a5 b7 ae a8 a6 b7 84 80 7f 8b db da d9 ff d9 d6 d5 ff d8 d6 d5 ff d8 d6 d4 ff d8 d6 d4 ff d8 d5 d4 ff d8 d5 d4 ff d8 d5 d3 ff d8 d5 d3 ff d8 d4 d3 ff d7 d4 d3 ff d7 d4 d2 ff d7
                Data Ascii: & h( @ ((()
                2024-04-19 17:07:17 UTC2038INData Raw: e3 ff cf cf cf ff da da da 7f ff ff ff 01 e7 e7 e7 ff ff ff ff ff ee d6 b7 ff dc a8 69 ff dd ab 6c ff dc a9 69 ff dc a9 6a ff d5 bd 9d ff ff ff ff ff ff ff ff ff ff ff ff ff f6 f4 f3 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff eb e8 e5 ff ea e7 e4 ff ea e7 e4 ff ea e7 e4 ff c2 c0 bf ff be be be ff bf bf bf ff ba ba ba ff be be be ff db db db bf ff ff ff 01 ff ff ff 01 e7 e7 e7 ff ff ff ff ff f6 eb dc ff ee d5 b7 ff ee d6 b8 ff ee d6 b7 ff ee d6 b8 ff df d3 c4 ff ff ff ff ff ff ff ff ff ff ff ff ff f6 f4 f3 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff ed ea e7 ff eb e7 e5 ff ea e7 e4 ff eb e7 e5 ff eb e7 e5 ff c0 be bd ff fe fe fe ff f7 f7 f7 ff e1 e2 e2 ff e2
                Data Ascii: ilij


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.549715184.24.36.112443
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:17 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-19 17:07:17 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=136532
                Date: Fri, 19 Apr 2024 17:07:17 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.549716184.24.36.112443
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:17 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-19 17:07:18 UTC531INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=136522
                Date: Fri, 19 Apr 2024 17:07:18 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-19 17:07:18 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Session IDSource IPSource PortDestination IPDestination Port
                5192.168.2.54972223.1.237.91443
                TimestampBytes transferredDirectionData
                2024-04-19 17:07:29 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
                Origin: https://www.bing.com
                Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                Accept: */*
                Accept-Language: en-CH
                Content-type: text/xml
                X-Agent-DeviceId: 01000A410900D492
                X-BM-CBT: 1696428841
                X-BM-DateFormat: dd/MM/yyyy
                X-BM-DeviceDimensions: 784x984
                X-BM-DeviceDimensionsLogical: 784x984
                X-BM-DeviceScale: 100
                X-BM-DTZ: 120
                X-BM-Market: CH
                X-BM-Theme: 000000;0078d7
                X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
                X-Device-isOptin: false
                X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                X-Device-OSSKU: 48
                X-Device-Touch: false
                X-DeviceID: 01000A410900D492
                X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
                X-MSEdge-ExternalExpType: JointCoord
                X-PositionerType: Desktop
                X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                X-Search-CortanaAvailableCapabilities: None
                X-Search-SafeSearch: Moderate
                X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
                X-UserAgeClass: Unknown
                Accept-Encoding: gzip, deflate, br
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                Host: www.bing.com
                Content-Length: 2484
                Connection: Keep-Alive
                Cache-Control: no-cache
                Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1713546418051&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
                2024-04-19 17:07:29 UTC1OUTData Raw: 3c
                Data Ascii: <
                2024-04-19 17:07:29 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
                Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
                2024-04-19 17:07:30 UTC480INHTTP/1.1 204 No Content
                Access-Control-Allow-Origin: *
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                X-MSEdge-Ref: Ref A: 9D6FDB3FDACB476E92EE8D53D72BD46C Ref B: SN4AA2022403025 Ref C: 2024-04-19T17:07:29Z
                Date: Fri, 19 Apr 2024 17:07:30 GMT
                Connection: close
                Alt-Svc: h3=":443"; ma=93600
                X-CDN-TraceID: 0.57ed0117.1713546449.1262992f


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:19:07:08
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:19:07:10
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2352,i,4671588504332305712,13636946270834276244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:19:07:13
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sales.sganalytics.com/trc2/0274a04c069a33bf9e4112d6a6155855786181d03f72d767796c3ab031c2e4c23679b040607e58b2"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly