Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://mssoutlookt.com

Overview

General Information

Sample URL:http://mssoutlookt.com
Analysis ID:1429044
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

Analysis Advice

Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
  • System is w10x64
  • chrome.exe (PID: 1016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 348 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=1968,i,13896041122332992229,2483790936214408877,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mssoutlookt.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.34
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: mssoutlookt.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: unknown0.win@19/0@12/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=1968,i,13896041122332992229,2483790936214408877,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mssoutlookt.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=1968,i,13896041122332992229,2483790936214408877,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1429044 URL: http://mssoutlookt.com Startdate: 20/04/2024 Architecture: WINDOWS Score: 0 14 mssoutlookt.com 2->14 16 fp2e7a.wpc.phicdn.net 2->16 18 2 other IPs or domains 2->18 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 20 192.168.2.4, 138, 443, 49332 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 11 chrome.exe 6->11         started        process5 dnsIp6 24 www.google.com 74.125.136.147, 443, 49738 GOOGLEUS United States 11->24 26 mssoutlookt.com 11->26 28 google.com 11->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://mssoutlookt.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    google.com
    108.177.122.139
    truefalse
      high
      www.google.com
      74.125.136.147
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          mssoutlookt.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            74.125.136.147
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1429044
            Start date and time:2024-04-20 11:19:40 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 12s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://mssoutlookt.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@12/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 173.194.219.94, 142.251.15.100, 142.251.15.113, 142.251.15.101, 142.251.15.138, 142.251.15.139, 142.251.15.102, 142.250.105.84, 34.104.35.123, 23.55.253.34, 40.127.169.103, 199.232.214.172, 52.165.164.15, 192.229.211.108
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 20, 2024 11:20:31.741617918 CEST49675443192.168.2.4173.222.162.32
            Apr 20, 2024 11:20:41.349364996 CEST49675443192.168.2.4173.222.162.32
            Apr 20, 2024 11:20:44.009931087 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.010004997 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.010113955 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.010771990 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.010799885 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.239244938 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.239774942 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.239836931 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.241403103 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.241493940 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.243248940 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.243349075 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.287259102 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:44.287285089 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:44.334134102 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:54.273452997 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:54.273602009 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:54.274040937 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:55.757767916 CEST49738443192.168.2.474.125.136.147
            Apr 20, 2024 11:20:55.757816076 CEST4434973874.125.136.147192.168.2.4
            Apr 20, 2024 11:20:55.822175026 CEST4972380192.168.2.423.40.205.34
            Apr 20, 2024 11:20:55.926862955 CEST804972323.40.205.34192.168.2.4
            Apr 20, 2024 11:20:55.927058935 CEST4972380192.168.2.423.40.205.34
            TimestampSource PortDest PortSource IPDest IP
            Apr 20, 2024 11:20:39.421610117 CEST53535971.1.1.1192.168.2.4
            Apr 20, 2024 11:20:39.485003948 CEST53516821.1.1.1192.168.2.4
            Apr 20, 2024 11:20:40.140834093 CEST53518381.1.1.1192.168.2.4
            Apr 20, 2024 11:20:41.447901964 CEST6067453192.168.2.41.1.1.1
            Apr 20, 2024 11:20:41.448132038 CEST6247053192.168.2.41.1.1.1
            Apr 20, 2024 11:20:41.554785013 CEST53606741.1.1.1192.168.2.4
            Apr 20, 2024 11:20:41.566215992 CEST53624701.1.1.1192.168.2.4
            Apr 20, 2024 11:20:41.567120075 CEST5519653192.168.2.41.1.1.1
            Apr 20, 2024 11:20:41.685965061 CEST53551961.1.1.1192.168.2.4
            Apr 20, 2024 11:20:41.718262911 CEST5986253192.168.2.48.8.8.8
            Apr 20, 2024 11:20:41.718544960 CEST5479553192.168.2.41.1.1.1
            Apr 20, 2024 11:20:41.823097944 CEST53547951.1.1.1192.168.2.4
            Apr 20, 2024 11:20:41.823430061 CEST53598628.8.8.8192.168.2.4
            Apr 20, 2024 11:20:42.717994928 CEST5301553192.168.2.41.1.1.1
            Apr 20, 2024 11:20:42.718255043 CEST5044753192.168.2.41.1.1.1
            Apr 20, 2024 11:20:42.827272892 CEST53504471.1.1.1192.168.2.4
            Apr 20, 2024 11:20:42.837174892 CEST53530151.1.1.1192.168.2.4
            Apr 20, 2024 11:20:43.455641031 CEST4933253192.168.2.41.1.1.1
            Apr 20, 2024 11:20:43.456393003 CEST5224453192.168.2.41.1.1.1
            Apr 20, 2024 11:20:43.560517073 CEST53493321.1.1.1192.168.2.4
            Apr 20, 2024 11:20:43.561095953 CEST53522441.1.1.1192.168.2.4
            Apr 20, 2024 11:20:47.892060995 CEST6220453192.168.2.41.1.1.1
            Apr 20, 2024 11:20:47.892699957 CEST5551553192.168.2.41.1.1.1
            Apr 20, 2024 11:20:47.997211933 CEST53622041.1.1.1192.168.2.4
            Apr 20, 2024 11:20:48.011204958 CEST53555151.1.1.1192.168.2.4
            Apr 20, 2024 11:20:48.012306929 CEST5724253192.168.2.41.1.1.1
            Apr 20, 2024 11:20:48.117718935 CEST53572421.1.1.1192.168.2.4
            Apr 20, 2024 11:20:53.855201006 CEST138138192.168.2.4192.168.2.255
            Apr 20, 2024 11:20:57.158164978 CEST53546251.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 20, 2024 11:20:41.447901964 CEST192.168.2.41.1.1.10xebb5Standard query (0)mssoutlookt.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.448132038 CEST192.168.2.41.1.1.10xf4e4Standard query (0)mssoutlookt.com65IN (0x0001)false
            Apr 20, 2024 11:20:41.567120075 CEST192.168.2.41.1.1.10xd4c1Standard query (0)mssoutlookt.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.718262911 CEST192.168.2.48.8.8.80x74cbStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.718544960 CEST192.168.2.41.1.1.10x17ffStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:42.717994928 CEST192.168.2.41.1.1.10xbf18Standard query (0)mssoutlookt.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:42.718255043 CEST192.168.2.41.1.1.10xdcbeStandard query (0)mssoutlookt.com65IN (0x0001)false
            Apr 20, 2024 11:20:43.455641031 CEST192.168.2.41.1.1.10xbd3aStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.456393003 CEST192.168.2.41.1.1.10xf862Standard query (0)www.google.com65IN (0x0001)false
            Apr 20, 2024 11:20:47.892060995 CEST192.168.2.41.1.1.10xefdaStandard query (0)mssoutlookt.comA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:47.892699957 CEST192.168.2.41.1.1.10x6c19Standard query (0)mssoutlookt.com65IN (0x0001)false
            Apr 20, 2024 11:20:48.012306929 CEST192.168.2.41.1.1.10x3b9aStandard query (0)mssoutlookt.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 20, 2024 11:20:41.554785013 CEST1.1.1.1192.168.2.40xebb5Name error (3)mssoutlookt.comnonenoneA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.566215992 CEST1.1.1.1192.168.2.40xf4e4Name error (3)mssoutlookt.comnonenone65IN (0x0001)false
            Apr 20, 2024 11:20:41.685965061 CEST1.1.1.1192.168.2.40xd4c1Name error (3)mssoutlookt.comnonenoneA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.139A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.101A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.102A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.100A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.138A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823097944 CEST1.1.1.1192.168.2.40x17ffNo error (0)google.com108.177.122.113A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.102A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.101A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.138A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.139A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.113A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:41.823430061 CEST8.8.8.8192.168.2.40x74cbNo error (0)google.com172.253.113.100A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:42.827272892 CEST1.1.1.1192.168.2.40xdcbeName error (3)mssoutlookt.comnonenone65IN (0x0001)false
            Apr 20, 2024 11:20:42.837174892 CEST1.1.1.1192.168.2.40xbf18Name error (3)mssoutlookt.comnonenoneA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.560517073 CEST1.1.1.1192.168.2.40xbd3aNo error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:43.561095953 CEST1.1.1.1192.168.2.40xf862No error (0)www.google.com65IN (0x0001)false
            Apr 20, 2024 11:20:47.997211933 CEST1.1.1.1192.168.2.40xefdaName error (3)mssoutlookt.comnonenoneA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:48.011204958 CEST1.1.1.1192.168.2.40x6c19Name error (3)mssoutlookt.comnonenone65IN (0x0001)false
            Apr 20, 2024 11:20:48.117718935 CEST1.1.1.1192.168.2.40x3b9aName error (3)mssoutlookt.comnonenoneA (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:55.524312019 CEST1.1.1.1192.168.2.40xf957No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:55.524312019 CEST1.1.1.1192.168.2.40xf957No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 20, 2024 11:20:56.496738911 CEST1.1.1.1192.168.2.40xefa4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 20, 2024 11:20:56.496738911 CEST1.1.1.1192.168.2.40xefa4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:11:20:34
            Start date:20/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:11:20:37
            Start date:20/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=1968,i,13896041122332992229,2483790936214408877,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:11:20:40
            Start date:20/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mssoutlookt.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly