Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://42.193.223.169/extensioncompabilitynode.exe

Overview

General Information

Sample URL:http://42.193.223.169/extensioncompabilitynode.exe
Analysis ID:1430707
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3868 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2004,i,6530940214536987924,16773487107488982914,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://42.193.223.169/extensioncompabilitynode.exe" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://42.193.223.169/extensioncompabilitynode.exeAvira URL Cloud: detection malicious, Label: malware
Source: http://42.193.223.169/extensioncompabilitynode.exeVirustotal: Detection: 6%Perma Link
Source: http://42.193.223.169/extensioncompabilitynode.exeHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownTCP traffic detected without corresponding DNS query: 42.193.223.169
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /extensioncompabilitynode.exe HTTP/1.1Host: 42.193.223.169Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 42.193.223.169Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://42.193.223.169/extensioncompabilitynode.exeAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/html; charset=us-asciiServer: Microsoft-HTTPAPI/2.0Date: Wed, 24 Apr 2024 01:40:49 GMTConnection: closeContent-Length: 326Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 35 30 33 2e 20 54 68 65 20 73 65 72 76 69 63 65 20 69 73 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Service Unavailable</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Service Unavailable</h2><hr><p>HTTP Error 503. The service is unavailable.</p></BODY></HTML>
Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/html; charset=us-asciiServer: Microsoft-HTTPAPI/2.0Date: Wed, 24 Apr 2024 01:40:49 GMTConnection: closeContent-Length: 326Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 35 30 33 2e 20 54 68 65 20 73 65 72 76 69 63 65 20 69 73 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Service Unavailable</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Service Unavailable</h2><hr><p>HTTP Error 503. The service is unavailable.</p></BODY></HTML>
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal56.win@16/4@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2004,i,6530940214536987924,16773487107488982914,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://42.193.223.169/extensioncompabilitynode.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2004,i,6530940214536987924,16773487107488982914,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://42.193.223.169/extensioncompabilitynode.exe100%Avira URL Cloudmalware
http://42.193.223.169/extensioncompabilitynode.exe7%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://42.193.223.169/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.141.104
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://42.193.223.169/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      http://42.193.223.169/extensioncompabilitynode.exetrue
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        42.193.223.169
        unknownChina
        4249LILLY-ASUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.141.104
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1430707
        Start date and time:2024-04-24 03:39:55 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 15s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://42.193.223.169/extensioncompabilitynode.exe
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@16/4@2/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.101, 142.251.2.139, 142.251.2.113, 142.251.2.138, 142.251.2.102, 142.251.2.100, 142.251.2.84, 34.104.35.123, 20.12.23.50, 72.21.81.240, 192.229.211.108, 13.85.23.206, 13.95.31.18, 20.166.126.56, 142.250.101.94
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):326
        Entropy (8bit):5.432260125605187
        Encrypted:false
        SSDEEP:6:B8FQtuc4svmo9qvyDPdnTHpGW+q2Q8EevWR0NNEXW0YDBOeHHpS7GHXjNz5pHuoG:BMQt6o9qvyLJpGW+q2Q8EepfdfnpQGHe
        MD5:BF3231D7FAD0292D818AAC7D6D669F00
        SHA1:C29683B3788D729A5FC4504279D10E31DA60745C
        SHA-256:FB2D9F058C2010C57F86A05AE33D282F33E3825290C66B8B120CD177416C6BDF
        SHA-512:856F5087691EED24D717B4A28769D96E0E003588BDC4B3BEB3FA27AD81474B00BE00BCEDF1BC23C7A6F00947047E7C89EE07CC4F3087E7B76E219B3A068F0398
        Malicious:false
        Reputation:low
        URL:http://42.193.223.169/favicon.ico
        Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>Service Unavailable</TITLE>..<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>..<BODY><h2>Service Unavailable</h2>..<hr><p>HTTP Error 503. The service is unavailable.</p>..</BODY></HTML>..
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):326
        Entropy (8bit):5.432260125605187
        Encrypted:false
        SSDEEP:6:B8FQtuc4svmo9qvyDPdnTHpGW+q2Q8EevWR0NNEXW0YDBOeHHpS7GHXjNz5pHuoG:BMQt6o9qvyLJpGW+q2Q8EepfdfnpQGHe
        MD5:BF3231D7FAD0292D818AAC7D6D669F00
        SHA1:C29683B3788D729A5FC4504279D10E31DA60745C
        SHA-256:FB2D9F058C2010C57F86A05AE33D282F33E3825290C66B8B120CD177416C6BDF
        SHA-512:856F5087691EED24D717B4A28769D96E0E003588BDC4B3BEB3FA27AD81474B00BE00BCEDF1BC23C7A6F00947047E7C89EE07CC4F3087E7B76E219B3A068F0398
        Malicious:false
        Reputation:low
        URL:http://42.193.223.169/extensioncompabilitynode.exe
        Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>Service Unavailable</TITLE>..<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>..<BODY><h2>Service Unavailable</h2>..<hr><p>HTTP Error 503. The service is unavailable.</p>..</BODY></HTML>..
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 24, 2024 03:40:40.288347960 CEST49675443192.168.2.4173.222.162.32
        Apr 24, 2024 03:40:48.797257900 CEST4973580192.168.2.442.193.223.169
        Apr 24, 2024 03:40:48.797425985 CEST4973680192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.054656982 CEST4973780192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.133745909 CEST804973642.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.133797884 CEST804973542.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.133852959 CEST4973680192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.133876085 CEST4973580192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.134015083 CEST4973680192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.384723902 CEST804973742.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.384840012 CEST4973780192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.472042084 CEST804973642.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.472119093 CEST4973680192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.473151922 CEST4973680192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.557967901 CEST4973580192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.809287071 CEST804973642.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.889465094 CEST49675443192.168.2.4173.222.162.32
        Apr 24, 2024 03:40:49.894639015 CEST804973542.193.223.169192.168.2.4
        Apr 24, 2024 03:40:49.894742012 CEST4973580192.168.2.442.193.223.169
        Apr 24, 2024 03:40:49.896447897 CEST4973580192.168.2.442.193.223.169
        Apr 24, 2024 03:40:50.232814074 CEST804973542.193.223.169192.168.2.4
        Apr 24, 2024 03:40:50.688431025 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:50.688513041 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:50.688591957 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:50.689169884 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:50.689203024 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.054658890 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.054946899 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:51.055007935 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.056480885 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.056548119 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:51.231550932 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:51.231957912 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.287172079 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:51.287204981 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:40:51.334058046 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:40:51.634061098 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:51.634105921 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:51.634197950 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:51.636888027 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:51.636904001 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:51.989959002 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:51.990051985 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:51.995630980 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:51.995640993 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:51.995893002 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.037178040 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.165096045 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.212119102 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.349957943 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.350157976 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.350182056 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.350193024 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.350327969 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.350353956 CEST4434974123.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.350411892 CEST49741443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.385889053 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.385942936 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.386056900 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.386342049 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.386363983 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.733834982 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.733939886 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.736114979 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.736135006 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.736346960 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:52.738431931 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:52.780126095 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:53.077864885 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:53.085870981 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:53.085947037 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:53.092253923 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:53.092287064 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:40:53.092307091 CEST49742443192.168.2.423.40.26.94
        Apr 24, 2024 03:40:53.092314959 CEST4434974223.40.26.94192.168.2.4
        Apr 24, 2024 03:41:01.058554888 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:01.058624029 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:01.058909893 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:01.087049007 CEST49740443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:01.087109089 CEST44349740142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:34.396574020 CEST4973780192.168.2.442.193.223.169
        Apr 24, 2024 03:41:34.726661921 CEST804973742.193.223.169192.168.2.4
        Apr 24, 2024 03:41:49.419487000 CEST4973780192.168.2.442.193.223.169
        Apr 24, 2024 03:41:49.749152899 CEST804973742.193.223.169192.168.2.4
        Apr 24, 2024 03:41:50.824489117 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:50.824588060 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:50.824739933 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:50.826317072 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:50.826353073 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:51.187345982 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:51.200777054 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:51.200819969 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:51.202023983 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:51.202496052 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:51.202666998 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:41:51.256180048 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:41:56.975581884 CEST4972380192.168.2.4199.232.210.172
        Apr 24, 2024 03:41:56.975740910 CEST4972480192.168.2.4199.232.210.172
        Apr 24, 2024 03:41:57.135049105 CEST8049724199.232.210.172192.168.2.4
        Apr 24, 2024 03:41:57.135071993 CEST8049724199.232.210.172192.168.2.4
        Apr 24, 2024 03:41:57.135154009 CEST4972480192.168.2.4199.232.210.172
        Apr 24, 2024 03:41:57.135745049 CEST8049723199.232.210.172192.168.2.4
        Apr 24, 2024 03:41:57.135782003 CEST8049723199.232.210.172192.168.2.4
        Apr 24, 2024 03:41:57.136027098 CEST4972380192.168.2.4199.232.210.172
        Apr 24, 2024 03:42:01.199978113 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:42:01.200058937 CEST44349751142.250.141.104192.168.2.4
        Apr 24, 2024 03:42:01.200335026 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:42:03.086517096 CEST49751443192.168.2.4142.250.141.104
        Apr 24, 2024 03:42:03.086585045 CEST44349751142.250.141.104192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 24, 2024 03:40:46.687598944 CEST53622961.1.1.1192.168.2.4
        Apr 24, 2024 03:40:46.846620083 CEST53547451.1.1.1192.168.2.4
        Apr 24, 2024 03:40:47.812938929 CEST53550741.1.1.1192.168.2.4
        Apr 24, 2024 03:40:50.529705048 CEST5027653192.168.2.41.1.1.1
        Apr 24, 2024 03:40:50.530267954 CEST6275553192.168.2.41.1.1.1
        Apr 24, 2024 03:40:50.683136940 CEST53502761.1.1.1192.168.2.4
        Apr 24, 2024 03:40:50.683747053 CEST53627551.1.1.1192.168.2.4
        Apr 24, 2024 03:41:05.786964893 CEST53640071.1.1.1192.168.2.4
        Apr 24, 2024 03:41:08.558509111 CEST138138192.168.2.4192.168.2.255
        Apr 24, 2024 03:41:24.841824055 CEST53500661.1.1.1192.168.2.4
        Apr 24, 2024 03:41:46.200839996 CEST53526931.1.1.1192.168.2.4
        Apr 24, 2024 03:41:47.209129095 CEST53543251.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 24, 2024 03:40:50.529705048 CEST192.168.2.41.1.1.10xdef8Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.530267954 CEST192.168.2.41.1.1.10xa665Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683136940 CEST1.1.1.1192.168.2.40xdef8No error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
        Apr 24, 2024 03:40:50.683747053 CEST1.1.1.1192.168.2.40xa665No error (0)www.google.com65IN (0x0001)false
        Apr 24, 2024 03:41:04.074477911 CEST1.1.1.1192.168.2.40x3055No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 24, 2024 03:41:04.074477911 CEST1.1.1.1192.168.2.40x3055No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 24, 2024 03:41:17.052180052 CEST1.1.1.1192.168.2.40x618No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 24, 2024 03:41:17.052180052 CEST1.1.1.1192.168.2.40x618No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 24, 2024 03:41:39.973993063 CEST1.1.1.1192.168.2.40x3760No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 24, 2024 03:41:39.973993063 CEST1.1.1.1192.168.2.40x3760No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 24, 2024 03:41:59.178270102 CEST1.1.1.1192.168.2.40xccb5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 24, 2024 03:41:59.178270102 CEST1.1.1.1192.168.2.40xccb5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • fs.microsoft.com
        • 42.193.223.169
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973642.193.223.169803868C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 24, 2024 03:40:49.134015083 CEST457OUTGET /extensioncompabilitynode.exe HTTP/1.1
        Host: 42.193.223.169
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Apr 24, 2024 03:40:49.472042084 CEST513INHTTP/1.1 503 Service Unavailable
        Content-Type: text/html; charset=us-ascii
        Server: Microsoft-HTTPAPI/2.0
        Date: Wed, 24 Apr 2024 01:40:49 GMT
        Connection: close
        Content-Length: 326
        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 35 30 33 2e 20 54 68 65 20 73 65 72 76 69 63 65 20 69 73 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Service Unavailable</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Service Unavailable</h2><hr><p>HTTP Error 503. The service is unavailable.</p></BODY></HTML>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44973542.193.223.169803868C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 24, 2024 03:40:49.557967901 CEST400OUTGET /favicon.ico HTTP/1.1
        Host: 42.193.223.169
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://42.193.223.169/extensioncompabilitynode.exe
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Apr 24, 2024 03:40:49.894639015 CEST513INHTTP/1.1 503 Service Unavailable
        Content-Type: text/html; charset=us-ascii
        Server: Microsoft-HTTPAPI/2.0
        Date: Wed, 24 Apr 2024 01:40:49 GMT
        Connection: close
        Content-Length: 326
        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 35 30 33 2e 20 54 68 65 20 73 65 72 76 69 63 65 20 69 73 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Service Unavailable</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Service Unavailable</h2><hr><p>HTTP Error 503. The service is unavailable.</p></BODY></HTML>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.44973742.193.223.169803868C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 24, 2024 03:41:34.396574020 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44974123.40.26.94443
        TimestampBytes transferredDirectionData
        2024-04-24 01:40:52 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-24 01:40:52 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (sac/250E)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus2-z1
        Cache-Control: public, max-age=19357
        Date: Wed, 24 Apr 2024 01:40:52 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974223.40.26.94443
        TimestampBytes transferredDirectionData
        2024-04-24 01:40:52 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-24 01:40:53 UTC455INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (sac/2578)
        X-CID: 11
        Cache-Control: public, max-age=19334
        Date: Wed, 24 Apr 2024 01:40:52 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-24 01:40:53 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:03:40:42
        Start date:24/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:03:40:44
        Start date:24/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2004,i,6530940214536987924,16773487107488982914,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:03:40:47
        Start date:24/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://42.193.223.169/extensioncompabilitynode.exe"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly