Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38

Overview

General Information

Sample URL:http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38
Analysis ID:1429024
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3060 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1996,i,6093095050722377371,5309599969872023129,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6540 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 185.169.252.52
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38 HTTP/1.1Host: 185.169.252.52Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 185.169.252.52Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Sat, 20 Apr 2024 02:24:43 GMTServer: Apache/2.4.52 (Ubuntu)Content-Length: 276Keep-Alive: timeout=5, max=99Connection: Keep-AliveContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 31 38 35 2e 31 36 39 2e 32 35 32 2e 35 32 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at 185.169.252.52 Port 80</address></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1996,i,6093095050722377371,5309599969872023129,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1996,i,6093095050722377371,5309599969872023129,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
74.125.136.106
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38false
        unknown
        http://185.169.252.52/favicon.icofalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          185.169.252.52
          unknownGermany
          21769AS-COLOAMUSfalse
          74.125.136.106
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1429024
          Start date and time:2024-04-20 04:23:45 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 23s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/2@2/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 173.194.219.94, 64.233.176.102, 64.233.176.138, 64.233.176.139, 64.233.176.100, 64.233.176.113, 64.233.176.101, 64.233.177.84, 34.104.35.123, 13.85.23.86, 23.40.207.209, 23.40.207.225, 192.229.211.108, 13.95.31.18, 172.217.215.94
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):276
          Entropy (8bit):5.262584653357745
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoIRCwmAbGAgcXaoD:J0+oxBeRmR9etdzRxGezHtVbpgma+
          MD5:88099231A54FED320A3E26356C1079A8
          SHA1:EBE4E00BECB78D511A246C22C4FF56C7CFFA3B47
          SHA-256:4CA2D944AD8A7FCE5A6D362072958775094DA8EA2D4CDFC7B95F0D125C1E9ED3
          SHA-512:F894696FB1E3E81A9023E136D5B51C6BEF05D2A13C85674526D14DC8AB56D5324D73D58D596A9E679DAB0AF00BE02BCBEF80867F8D81C4312678482CB935E9A9
          Malicious:false
          Reputation:low
          URL:http://185.169.252.52/favicon.ico
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<hr>.<address>Apache/2.4.52 (Ubuntu) Server at 185.169.252.52 Port 80</address>.</body></html>.
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 20, 2024 04:24:32.734584093 CEST49675443192.168.2.4173.222.162.32
          Apr 20, 2024 04:24:42.342376947 CEST49675443192.168.2.4173.222.162.32
          Apr 20, 2024 04:24:43.092478991 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.094166040 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.302921057 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:43.303469896 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.303740978 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.303777933 CEST8049736185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:43.304163933 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.513457060 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:43.680315018 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:43.723860025 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.735394955 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:43.971913099 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:43.971976042 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:44.124878883 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:44.223161936 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.223207951 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.223282099 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.223556995 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.223568916 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.445179939 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.445568085 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.445575953 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.447197914 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.447287083 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.448616982 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.448704004 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.498701096 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:44.498708010 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:44.545566082 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:47.109013081 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.109102964 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.109184027 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.112510920 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.112545967 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.328567028 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.328660011 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.332920074 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.332940102 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.333161116 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.373851061 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.398709059 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.444145918 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.534092903 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.534149885 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.534216881 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.535578966 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.535614967 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.535648108 CEST49741443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.535664082 CEST4434974123.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.644284964 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.644325018 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.644397020 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.644700050 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.644710064 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.857125044 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.857201099 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.858767986 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.858773947 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.859014988 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:47.860132933 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:47.904120922 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:48.066386938 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:48.066456079 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:48.066528082 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:48.067611933 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:48.067630053 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:48.067642927 CEST49742443192.168.2.423.33.136.127
          Apr 20, 2024 04:24:48.067648888 CEST4434974223.33.136.127192.168.2.4
          Apr 20, 2024 04:24:48.987193108 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:48.987284899 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:50.377918959 CEST4973580192.168.2.4185.169.252.52
          Apr 20, 2024 04:24:50.593435049 CEST8049735185.169.252.52192.168.2.4
          Apr 20, 2024 04:24:54.482449055 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:54.482608080 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:54.482913017 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:56.599561930 CEST49738443192.168.2.474.125.136.106
          Apr 20, 2024 04:24:56.599581957 CEST4434973874.125.136.106192.168.2.4
          Apr 20, 2024 04:24:57.639369011 CEST4972380192.168.2.472.21.81.240
          Apr 20, 2024 04:24:57.743161917 CEST804972372.21.81.240192.168.2.4
          Apr 20, 2024 04:24:57.743374109 CEST4972380192.168.2.472.21.81.240
          Apr 20, 2024 04:25:14.818056107 CEST8049736185.169.252.52192.168.2.4
          Apr 20, 2024 04:25:14.818111897 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:25:28.304336071 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:25:28.531265020 CEST8049736185.169.252.52192.168.2.4
          Apr 20, 2024 04:25:35.067696095 CEST8049736185.169.252.52192.168.2.4
          Apr 20, 2024 04:25:35.067760944 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:25:36.367703915 CEST4973680192.168.2.4185.169.252.52
          Apr 20, 2024 04:25:36.585719109 CEST8049736185.169.252.52192.168.2.4
          Apr 20, 2024 04:25:44.167468071 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:44.167574883 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.167941093 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:44.169522047 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:44.169559002 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.390319109 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.390722036 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:44.390741110 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.391376972 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.394917965 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:44.394996881 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:44.436659098 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:47.007637024 CEST4972480192.168.2.472.21.81.240
          Apr 20, 2024 04:25:47.111463070 CEST804972472.21.81.240192.168.2.4
          Apr 20, 2024 04:25:47.111596107 CEST4972480192.168.2.472.21.81.240
          Apr 20, 2024 04:25:54.385771036 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:54.385920048 CEST4434975074.125.136.106192.168.2.4
          Apr 20, 2024 04:25:54.385984898 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:56.375884056 CEST49750443192.168.2.474.125.136.106
          Apr 20, 2024 04:25:56.375950098 CEST4434975074.125.136.106192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Apr 20, 2024 04:24:41.597352982 CEST53519161.1.1.1192.168.2.4
          Apr 20, 2024 04:24:41.734827042 CEST53545391.1.1.1192.168.2.4
          Apr 20, 2024 04:24:42.454437971 CEST53654841.1.1.1192.168.2.4
          Apr 20, 2024 04:24:44.116871119 CEST5334053192.168.2.41.1.1.1
          Apr 20, 2024 04:24:44.117065907 CEST5199753192.168.2.41.1.1.1
          Apr 20, 2024 04:24:44.221746922 CEST53519971.1.1.1192.168.2.4
          Apr 20, 2024 04:24:44.222176075 CEST53533401.1.1.1192.168.2.4
          Apr 20, 2024 04:24:58.521122932 CEST138138192.168.2.4192.168.2.255
          Apr 20, 2024 04:24:59.386231899 CEST53577131.1.1.1192.168.2.4
          Apr 20, 2024 04:25:18.499912024 CEST53598681.1.1.1192.168.2.4
          Apr 20, 2024 04:25:41.153768063 CEST53588901.1.1.1192.168.2.4
          Apr 20, 2024 04:25:41.371107101 CEST53497181.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 20, 2024 04:24:44.116871119 CEST192.168.2.41.1.1.10x3a8cStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.117065907 CEST192.168.2.41.1.1.10x34d5Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 20, 2024 04:24:44.221746922 CEST1.1.1.1192.168.2.40x34d5No error (0)www.google.com65IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:44.222176075 CEST1.1.1.1192.168.2.40x3a8cNo error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
          Apr 20, 2024 04:24:57.175781012 CEST1.1.1.1192.168.2.40xf35fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 20, 2024 04:24:57.175781012 CEST1.1.1.1192.168.2.40xf35fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 20, 2024 04:25:09.542404890 CEST1.1.1.1192.168.2.40x940No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 20, 2024 04:25:09.542404890 CEST1.1.1.1192.168.2.40x940No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 20, 2024 04:25:33.582127094 CEST1.1.1.1192.168.2.40x11d8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 20, 2024 04:25:33.582127094 CEST1.1.1.1192.168.2.40x11d8No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 20, 2024 04:25:53.901675940 CEST1.1.1.1192.168.2.40xee0fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 20, 2024 04:25:53.901675940 CEST1.1.1.1192.168.2.40xee0fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • 185.169.252.52
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449735185.169.252.52805440C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 20, 2024 04:24:43.303740978 CEST507OUTGET /.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38 HTTP/1.1
          Host: 185.169.252.52
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Apr 20, 2024 04:24:43.680315018 CEST472INHTTP/1.1 200 OK
          Date: Sat, 20 Apr 2024 02:24:43 GMT
          Server: Apache/2.4.52 (Ubuntu)
          X-XSS-Protection: 1; mode=block
          Expires: Mon, 26 Jul 1997 05:00:00 GMT
          Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
          P3P: CP="OTI DSP COR CUR IVD CONi OTPi OUR IND UNI STA PRE"
          Pragma: no-cache
          Last-Modified: Sat, 20 Apr 2024 02:24:43 GMT
          Content-Length: 0
          Keep-Alive: timeout=5, max=100
          Connection: Keep-Alive
          Content-Type: application/json
          Apr 20, 2024 04:24:43.735394955 CEST450OUTGET /favicon.ico HTTP/1.1
          Host: 185.169.252.52
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Apr 20, 2024 04:24:43.971976042 CEST492INHTTP/1.1 404 Not Found
          Date: Sat, 20 Apr 2024 02:24:43 GMT
          Server: Apache/2.4.52 (Ubuntu)
          Content-Length: 276
          Keep-Alive: timeout=5, max=99
          Connection: Keep-Alive
          Content-Type: text/html; charset=iso-8859-1
          Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 31 38 35 2e 31 36 39 2e 32 35 32 2e 35 32 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at 185.169.252.52 Port 80</address></body></html>


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449736185.169.252.52805440C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 20, 2024 04:25:28.304336071 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44974123.33.136.127443
          TimestampBytes transferredDirectionData
          2024-04-20 02:24:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-20 02:24:47 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0758)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=103179
          Date: Sat, 20 Apr 2024 02:24:47 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44974223.33.136.127443
          TimestampBytes transferredDirectionData
          2024-04-20 02:24:47 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-20 02:24:48 UTC531INHTTP/1.1 200 OK
          Content-Type: application/octet-stream
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=103128
          Date: Sat, 20 Apr 2024 02:24:48 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-20 02:24:48 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:04:24:35
          Start date:20/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:04:24:38
          Start date:20/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1996,i,6093095050722377371,5309599969872023129,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:04:24:42
          Start date:20/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.169.252.52/.admin/mw/latest/index.php/campaigns/ge036dexd7b93/track-opening/xs64003t67c38"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly