Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://p.ksrndkehqnwntyxlhgto.com

Overview

General Information

Sample URL:http://p.ksrndkehqnwntyxlhgto.com
Analysis ID:1430632
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 3608 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6512 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2208,i,2730006000010268455,14252049337749835231,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://p.ksrndkehqnwntyxlhgto.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: p.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: p.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://p.ksrndkehqnwntyxlhgto.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: p.ksrndkehqnwntyxlhgto.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 23 Apr 2024 23:15:28 GMTContent-Type: text/html; charset=iso-8859-1Content-Length: 315Connection: keep-aliveServer: ApacheData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/8@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2208,i,2730006000010268455,14252049337749835231,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://p.ksrndkehqnwntyxlhgto.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2208,i,2730006000010268455,14252049337749835231,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://p.ksrndkehqnwntyxlhgto.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://p.ksrndkehqnwntyxlhgto.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.141.106
    truefalse
      high
      p.ksrndkehqnwntyxlhgto.com
      13.248.238.122
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://p.ksrndkehqnwntyxlhgto.com/false
            unknown
            http://p.ksrndkehqnwntyxlhgto.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            13.248.238.122
            p.ksrndkehqnwntyxlhgto.comUnited States
            16509AMAZON-02USfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.141.106
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.5
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1430632
            Start date and time:2024-04-24 01:14:35 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 16s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://p.ksrndkehqnwntyxlhgto.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean1.win@16/8@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.101, 142.251.2.139, 142.251.2.102, 142.251.2.100, 142.251.2.138, 142.251.2.113, 142.251.2.84, 34.104.35.123, 40.68.123.157, 199.232.214.172, 192.229.211.108, 23.32.1.150, 23.32.1.155, 20.242.39.171, 142.250.101.94, 23.32.1.212
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://p.ksrndkehqnwntyxlhgto.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 22:15:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.980430531814876
            Encrypted:false
            SSDEEP:48:81odsQTM0BDbycHeidAKZdA19ehwiZUklqehOy+3:8kXy9By
            MD5:F182A2D1D24F7C7E40F3FD7514A2DEAA
            SHA1:43FEC82BD2A9D315B8DA342C5079D25F6D6336EE
            SHA-256:4E6E01AEF3A95BCCF81B5C412FF96039BF352171BBE86740F8847C271A2F9620
            SHA-512:BAD1B7B1F5224FB2C3F51BC2C6258A8DC066CE3922FFEBD485CF5D0FF45DF6C9C34C8E392E9EDE767409B14B93514350EACD6D730E0F3C8C3CC119830D6A99C0
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......S ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 22:15:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.996386698308828
            Encrypted:false
            SSDEEP:48:8yodsQTM0BDbycHeidAKZdA1weh/iZUkAQkqehxy+2:8VXy39Qgy
            MD5:70F089E37845F47E39DC81E8EC925E1A
            SHA1:F2C9824F57488FAF686FF9B91DA7CEA490B931E6
            SHA-256:CEA52EE37FB6F56778DB573859479100C54A91578F278DCC64D2919D8BC994B0
            SHA-512:379F1AA877516B944DD73922CBF7FDBD6A451CDFD1AA7C5C61ABC0BD9383C7D1F9CD6A96A64DF30F4FCD2A604E56E19FA6902251514CC9FEAF9B9038B7779971
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....<.: ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2693
            Entropy (8bit):4.00780680648309
            Encrypted:false
            SSDEEP:48:8xJodsQTM0BDbsHeidAKZdA14tseh7sFiZUkmgqeh7sby+BX:8x4Xnn1y
            MD5:099815A225EB035B4A6DDC551D8B1D64
            SHA1:940FA071508FFC50A2F448A04D2673BFE2D5BF2A
            SHA-256:BA2FC6B2D26E29E600ED16169422A5FA3E7BE5F3CA73B0058BF18C34AF6EBC33
            SHA-512:386AD6555E73EB399EEDACE328015CFFB33F247E012CBDBA246DCCB6C7F1F46681C4C4FF78BA4296AAE788997C9F1F1E76B6E3E6585D591B5B70794BCDC8A006
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 22:15:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.993603845314759
            Encrypted:false
            SSDEEP:48:86odsQTM0BDbycHeidAKZdA1vehDiZUkwqehty+R:8NXy0Ty
            MD5:64C3CDDDF2B3EA3DA7849EB1E18A0977
            SHA1:EEFB89575C302FEFE4119947A0C766C1FD2DEB0E
            SHA-256:0F297C1A36580BBAE916A3436F323B6B238D1392AA6110860025816E278D79F4
            SHA-512:03E9AE9854D3B31C11C59015D2E65CD3FD7221A700D945D9F421D22200D707C69B1134E4385562BB13C242D55AF4BA5AA503C478BB81BBD7B9F191493CE01EA3
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....H,2 ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 22:15:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.982378193682603
            Encrypted:false
            SSDEEP:48:8sodsQTM0BDbycHeidAKZdA1hehBiZUk1W1qehvy+C:8HXyU9Py
            MD5:2B461DF5513293A0A2E1C1113BCDBC99
            SHA1:9A6FF8048E0D3342B8208FBDEAB47C092CC68D3E
            SHA-256:8D1DDBC14FAEA6B2FEAA9E25CFE93E77F85C429FC16F5A01F792EBFC5230F2BC
            SHA-512:97026C06A3E7AE5C6862982E87B8224EB35EE569FDB906AD7C4C4B72BDD052A220AA348D47811A7CE7317E24CAFBAC3D293A51B33B4FCB34AA2F5EABC457AFCD
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......L ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 22:15:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2683
            Entropy (8bit):3.9966532376197326
            Encrypted:false
            SSDEEP:48:8GodsQTM0BDbycHeidAKZdA1duT+ehOuTbbiZUk5OjqehOuTb1y+yT+:8ZXy6T/TbxWOvTb1y7T
            MD5:0B0D49F284BA57E20B2C07B6523C0D58
            SHA1:10B0017262AA59CB984951E556F61E74AFDBB44E
            SHA-256:419BA855C2A36939E59BFD14F0CABD3268261B3BD50D9F22A02E5BCF330CE58F
            SHA-512:486B155D84CB3CCBB3E24BD6E0A421470BE6448FB48596DBD197E20D290805D11523279D0579C7A850292EE502C524C40E9CD1EBB1339B2722FEB41E91A718D0
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....( ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........$..`.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):315
            Entropy (8bit):5.0572271090563765
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
            MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
            SHA1:A82190FC530C265AA40A045C21770D967F4767B8
            SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
            SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
            Malicious:false
            Reputation:low
            URL:http://p.ksrndkehqnwntyxlhgto.com/favicon.ico
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 01:15:19.543275118 CEST49674443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:19.543286085 CEST49675443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:19.652642965 CEST49673443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:28.164321899 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.164839029 CEST4971080192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.219120979 CEST4971380192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.323646069 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.323754072 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.324191093 CEST804971013.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.324285984 CEST4971080192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.326514959 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.378549099 CEST804971313.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.378654003 CEST4971380192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.485863924 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.545061111 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.607194901 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.749753952 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.749815941 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:28.758910894 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:28.758999109 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:28.759118080 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:28.759326935 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:28.759351015 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:28.766567945 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.824656963 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:15:28.869565010 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:15:29.130522013 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:29.130935907 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:29.130974054 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:29.132446051 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:29.132534981 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:29.133944988 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:29.134033918 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:29.228689909 CEST49675443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:29.228689909 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:29.228761911 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:29.259924889 CEST49674443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:29.416208982 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:29.416215897 CEST49673443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:30.648600101 CEST4434970323.1.237.91192.168.2.5
            Apr 24, 2024 01:15:30.648741007 CEST49703443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:32.801091909 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:32.801146030 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:32.801292896 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:32.804156065 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:32.804182053 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.162877083 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.163295031 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.170905113 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.170921087 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.171288967 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.212680101 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.269201994 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.316118002 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.491257906 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.491470098 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.491554976 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.491662979 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.491692066 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.491729975 CEST49717443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.491738081 CEST4434971723.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.535043001 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.535126925 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.535372972 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.535979986 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.536026955 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.882724047 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.882812977 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.883915901 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.883934021 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.884300947 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:33.885915995 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:33.932112932 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:34.222758055 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:34.222915888 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:34.223004103 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:36.780684948 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:36.780684948 CEST49718443192.168.2.523.1.102.27
            Apr 24, 2024 01:15:36.780746937 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:36.780776024 CEST4434971823.1.102.27192.168.2.5
            Apr 24, 2024 01:15:39.121905088 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:39.122071028 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:39.122232914 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:40.330512047 CEST49715443192.168.2.5142.250.141.106
            Apr 24, 2024 01:15:40.330565929 CEST44349715142.250.141.106192.168.2.5
            Apr 24, 2024 01:15:40.829355001 CEST49703443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:40.829355001 CEST49703443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:40.829777956 CEST49721443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:40.829828978 CEST4434972123.1.237.91192.168.2.5
            Apr 24, 2024 01:15:40.829963923 CEST49721443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:40.830323935 CEST49721443192.168.2.523.1.237.91
            Apr 24, 2024 01:15:40.830342054 CEST4434972123.1.237.91192.168.2.5
            Apr 24, 2024 01:15:40.989443064 CEST4434970323.1.237.91192.168.2.5
            Apr 24, 2024 01:15:40.989500046 CEST4434970323.1.237.91192.168.2.5
            Apr 24, 2024 01:15:41.170775890 CEST4434972123.1.237.91192.168.2.5
            Apr 24, 2024 01:15:41.170861006 CEST49721443192.168.2.523.1.237.91
            Apr 24, 2024 01:16:00.322962999 CEST4434972123.1.237.91192.168.2.5
            Apr 24, 2024 01:16:00.323170900 CEST49721443192.168.2.523.1.237.91
            Apr 24, 2024 01:16:13.338332891 CEST4971080192.168.2.513.248.238.122
            Apr 24, 2024 01:16:13.385206938 CEST4971380192.168.2.513.248.238.122
            Apr 24, 2024 01:16:13.498219013 CEST804971013.248.238.122192.168.2.5
            Apr 24, 2024 01:16:13.544538975 CEST804971313.248.238.122192.168.2.5
            Apr 24, 2024 01:16:13.838326931 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:16:13.998004913 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.401750088 CEST4971080192.168.2.513.248.238.122
            Apr 24, 2024 01:16:28.402101994 CEST4971380192.168.2.513.248.238.122
            Apr 24, 2024 01:16:28.441410065 CEST804971013.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.441504002 CEST4971080192.168.2.513.248.238.122
            Apr 24, 2024 01:16:28.489835024 CEST804971313.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.490057945 CEST4971380192.168.2.513.248.238.122
            Apr 24, 2024 01:16:28.561717987 CEST804971313.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.561779976 CEST804971013.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.669855118 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:28.669898987 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:28.670017004 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:28.670764923 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:28.670780897 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:28.824839115 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:16:28.824917078 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:16:29.026184082 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:29.026874065 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:29.026905060 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:29.027188063 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:29.027801037 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:29.027856112 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:29.073163033 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:30.326179981 CEST4970980192.168.2.513.248.238.122
            Apr 24, 2024 01:16:30.486428022 CEST804970913.248.238.122192.168.2.5
            Apr 24, 2024 01:16:39.050260067 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:39.050335884 CEST44349728142.250.141.106192.168.2.5
            Apr 24, 2024 01:16:39.050437927 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:40.323946953 CEST49728443192.168.2.5142.250.141.106
            Apr 24, 2024 01:16:40.323975086 CEST44349728142.250.141.106192.168.2.5
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 01:15:25.915215969 CEST53582731.1.1.1192.168.2.5
            Apr 24, 2024 01:15:26.065486908 CEST53516941.1.1.1192.168.2.5
            Apr 24, 2024 01:15:27.920512915 CEST5144253192.168.2.51.1.1.1
            Apr 24, 2024 01:15:27.920733929 CEST5872453192.168.2.51.1.1.1
            Apr 24, 2024 01:15:28.162969112 CEST53514421.1.1.1192.168.2.5
            Apr 24, 2024 01:15:28.163711071 CEST53587241.1.1.1192.168.2.5
            Apr 24, 2024 01:15:28.603673935 CEST6300953192.168.2.51.1.1.1
            Apr 24, 2024 01:15:28.603884935 CEST5131453192.168.2.51.1.1.1
            Apr 24, 2024 01:15:28.655630112 CEST53515731.1.1.1192.168.2.5
            Apr 24, 2024 01:15:28.757242918 CEST53630091.1.1.1192.168.2.5
            Apr 24, 2024 01:15:28.757808924 CEST53513141.1.1.1192.168.2.5
            Apr 24, 2024 01:15:49.884933949 CEST53508961.1.1.1192.168.2.5
            Apr 24, 2024 01:16:11.208359003 CEST53604631.1.1.1192.168.2.5
            Apr 24, 2024 01:16:24.507251024 CEST53542351.1.1.1192.168.2.5
            Apr 24, 2024 01:16:36.686388016 CEST53649211.1.1.1192.168.2.5
            TimestampSource IPDest IPChecksumCodeType
            Apr 24, 2024 01:15:27.834512949 CEST192.168.2.51.1.1.1c262(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 24, 2024 01:15:27.920512915 CEST192.168.2.51.1.1.10x83a9Standard query (0)p.ksrndkehqnwntyxlhgto.comA (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:27.920733929 CEST192.168.2.51.1.1.10x75afStandard query (0)p.ksrndkehqnwntyxlhgto.com65IN (0x0001)false
            Apr 24, 2024 01:15:28.603673935 CEST192.168.2.51.1.1.10xb1fStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.603884935 CEST192.168.2.51.1.1.10x8214Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 24, 2024 01:15:28.162969112 CEST1.1.1.1192.168.2.50x83a9No error (0)p.ksrndkehqnwntyxlhgto.com13.248.238.122A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.162969112 CEST1.1.1.1192.168.2.50x83a9No error (0)p.ksrndkehqnwntyxlhgto.com76.223.116.242A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757242918 CEST1.1.1.1192.168.2.50xb1fNo error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
            Apr 24, 2024 01:15:28.757808924 CEST1.1.1.1192.168.2.50x8214No error (0)www.google.com65IN (0x0001)false
            Apr 24, 2024 01:15:40.500888109 CEST1.1.1.1192.168.2.50x1cbdNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 01:15:40.500888109 CEST1.1.1.1192.168.2.50x1cbdNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 01:16:07.368530035 CEST1.1.1.1192.168.2.50xa96fNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 24, 2024 01:16:07.368530035 CEST1.1.1.1192.168.2.50xa96fNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Apr 24, 2024 01:16:28.745172024 CEST1.1.1.1192.168.2.50xa490No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 24, 2024 01:16:28.745172024 CEST1.1.1.1192.168.2.50xa490No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • p.ksrndkehqnwntyxlhgto.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.54970913.248.238.122806512C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 24, 2024 01:15:28.326514959 CEST441OUTGET / HTTP/1.1
            Host: p.ksrndkehqnwntyxlhgto.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Apr 24, 2024 01:15:28.545061111 CEST172INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 23:15:28 GMT
            Content-Type: text/html; charset=UTF-8
            Content-Length: 0
            Connection: keep-alive
            Server: Apache
            Upgrade: h2,h2c
            Apr 24, 2024 01:15:28.607194901 CEST396OUTGET /favicon.ico HTTP/1.1
            Host: p.ksrndkehqnwntyxlhgto.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Referer: http://p.ksrndkehqnwntyxlhgto.com/
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Apr 24, 2024 01:15:28.749753952 CEST172INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 23:15:28 GMT
            Content-Type: text/html; charset=UTF-8
            Content-Length: 0
            Connection: keep-alive
            Server: Apache
            Upgrade: h2,h2c
            Apr 24, 2024 01:15:28.824656963 CEST484INHTTP/1.1 404 Not Found
            Date: Tue, 23 Apr 2024 23:15:28 GMT
            Content-Type: text/html; charset=iso-8859-1
            Content-Length: 315
            Connection: keep-alive
            Server: Apache
            Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
            Apr 24, 2024 01:16:13.838326931 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.54971013.248.238.122806512C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 24, 2024 01:16:13.338332891 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.54971313.248.238.122806512C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 24, 2024 01:16:13.385206938 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.54971723.1.102.27443
            TimestampBytes transferredDirectionData
            2024-04-23 23:15:33 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 23:15:33 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (sac/2518)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=28047
            Date: Tue, 23 Apr 2024 23:15:33 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.54971823.1.102.27443
            TimestampBytes transferredDirectionData
            2024-04-23 23:15:33 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 23:15:34 UTC530INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0Fz4RYwAAAACZW8dCTzveR7lI76J6Z2l5U0pDRURHRTA1MTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=28058
            Date: Tue, 23 Apr 2024 23:15:34 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-23 23:15:34 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:01:15:19
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:01:15:22
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2208,i,2730006000010268455,14252049337749835231,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:01:15:25
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://p.ksrndkehqnwntyxlhgto.com"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly