Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://208.48.229.99

Overview

General Information

Sample URL:http://208.48.229.99
Analysis ID:1431000
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://208.48.229.99/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1924,i,16111623134245472612,15511103530334576046,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:04/24/24-12:54:07.309955
SID:2051023
Source Port:53948
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/24/24-12:54:07.310333
SID:2051023
Source Port:55642
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49724 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2051023 ET TROJAN SocGholish Domain in DNS Lookup (stake .libertariancounterpoint .com) 192.168.2.17:53948 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051023 ET TROJAN SocGholish Domain in DNS Lookup (stake .libertariancounterpoint .com) 192.168.2.17:55642 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.48.229.99
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XoH1sckWpD61SFd&MD=BDLYU7MP HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XoH1sckWpD61SFd&MD=BDLYU7MP HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: classification engineClassification label: mal48.win@18/6@2/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://208.48.229.99/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1924,i,16111623134245472612,15511103530334576046,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1924,i,16111623134245472612,15511103530334576046,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://208.48.229.990%Avira URL Cloudsafe
http://208.48.229.990%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.141.104
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    142.250.141.104
    www.google.comUnited States
    15169GOOGLEUSfalse
    208.48.229.99
    unknownUnited States
    3549LVLT-3549USfalse
    IP
    192.168.2.17
    192.168.2.16
    192.168.2.13
    192.168.2.23
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1431000
    Start date and time:2024-04-24 12:52:34 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 37s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:defaultwindowsinteractivecookbook.jbs
    Sample URL:http://208.48.229.99
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:14
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal48.win@18/6@2/7
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.251.2.94, 142.251.2.101, 142.251.2.139, 142.251.2.100, 142.251.2.102, 142.251.2.138, 142.251.2.113, 142.251.2.84, 34.104.35.123, 142.250.101.94, 74.125.137.139, 74.125.137.113, 74.125.137.100, 74.125.137.101, 74.125.137.138, 74.125.137.102
    • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 24 09:53:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2673
    Entropy (8bit):3.9909934595859524
    Encrypted:false
    SSDEEP:48:8TdcTggbHXidAKZdA1FehwiZUklqehiy+3:86/1hy
    MD5:5D7D03B4250117B99F56C6738EEAB0F0
    SHA1:2A9849FB6BA6CABDA990D20F33F808215626B2B7
    SHA-256:1ECD9F59078327B6840B4AB05A9681991B4443035283AE66EA57A0B51B1953E6
    SHA-512:51E17FBE544160DC36D4A4A3FE508D510FB09CADC309BE094EE02FF9F5D6F8F2B1D1A0422C739F838C6E8D79F39D2A9C17B29D67366D0AC11A7A40D2EBB668BB
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,......=.5...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.V...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 24 09:53:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2675
    Entropy (8bit):4.003640601450016
    Encrypted:false
    SSDEEP:48:8ndcTggbHXidAKZdA1seh/iZUkAQkqehRy+2:8m/r9QAy
    MD5:D59DAF1C71C26A060E5D412698A1AB48
    SHA1:9EAA8B114128073D796E39BFE7E6B330AB0476FC
    SHA-256:09DFE86C41813FD478F67A5FA979F39930C0D27F39B3DA3EACFF862042DE8A65
    SHA-512:1EC40F4AE770D64B3F4E3324C9358AF61A919B5D1D985929693EB96137760691A6953769FDAA44983676FF564D908160D6591A957269521D0EDDAD37D47D03D3
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....|12.5...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.V...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2689
    Entropy (8bit):4.010566552735004
    Encrypted:false
    SSDEEP:48:8WdcTggAHXidAKZdA14meh7sFiZUkmgqeh7sXy+BX:8x/qnVy
    MD5:976A5085ABEEDD6E0DC9B62F16AD0A7A
    SHA1:AA3757625406DDC9AF92559A39D4D7D9CE6E402F
    SHA-256:55F10B210A8A51FC8A6B741141876979AF6D63C9EBF1F1805F789C8DAF91732C
    SHA-512:6EF14DDF8B05392E13F8BA7CD570CFCC39C1BC8272E2A8DA7988D07AE83B8A7F3CCF62EEB239F37548072D634CF0FE5398FB940D5115CC8AC9C5E8AD2EA09274
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 24 09:53:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2677
    Entropy (8bit):4.001180388571555
    Encrypted:false
    SSDEEP:48:8AdcTggbHXidAKZdA1TehDiZUkwqehty+R:8r/4vy
    MD5:9A1EC9CE082B1DAA6FC1BFCB9E4B6780
    SHA1:19530FE2ADA8A9E4B5FD6ADDF27499B837E403DC
    SHA-256:ECB08E22DB00713B49394C8E95008B7A3E747F0589ED86273799669F3F9D7724
    SHA-512:FC02BA73F8419D0E4005E7AF954E0B1C3D2CDB54D122CC5621E380F6EA2F0D105772BA4D2CF35E1FA0A5BDC66ACB2CA83EE9F86EC1FAAFD506212A255F9C682F
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,.....e,.5...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.V...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 24 09:53:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2677
    Entropy (8bit):3.9935680023439453
    Encrypted:false
    SSDEEP:48:8tdcTggbHXidAKZdA1dehBiZUk1W1qeh7y+C:88/I9by
    MD5:DC0A774C4430C0B91CCFB80AB5B9BF5F
    SHA1:1F2805F792E8EA404073E493FD04D34FC55809A6
    SHA-256:00093EE609660A2BA90B54E4D63A4E65F7A66089EB73C5856DD947507F6D0235
    SHA-512:2AA9094E02024EC49B4BDDC9BF7A4BE5D60611003DEBAFF4C03ABCD253F6D25ED19EBDF5BBE098C4290EF86E15775177024EFD64288D1B1D3BB1099BD5503847
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,......7.5...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.V...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Apr 24 09:53:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2679
    Entropy (8bit):4.003143937955364
    Encrypted:false
    SSDEEP:48:8LAdcTggbHXidAKZdA1duTeehOuTbbiZUk5OjqehOuTbVy+yT+:8P/6TfTbxWOvTbVy7T
    MD5:9494C41FE5A94AFC8DD5F9E967D9AA93
    SHA1:1C7AC596F437C06A11BBC436FB7161F2F6A32950
    SHA-256:85C7C00C770122FDF9EE15C10DF2C58F7DE0BD60604CADC2FC4A9CB981CFFCB1
    SHA-512:D58A9BDE9EEB44C35DABBCF8476CAD2A626BD4DE4BDE405E06C8308101148883DA0526AF20CAB5F22A3D2A6698E33DF928A74DE83CF7A4E0317E938D258A6124
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,.....+".5...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.V....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.V....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.V....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.V..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.V...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    No static file info
    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
    04/24/24-12:54:07.309955UDP2051023ET TROJAN SocGholish Domain in DNS Lookup (stake .libertariancounterpoint .com)5394853192.168.2.171.1.1.1
    04/24/24-12:54:07.310333UDP2051023ET TROJAN SocGholish Domain in DNS Lookup (stake .libertariancounterpoint .com)5564253192.168.2.171.1.1.1
    TimestampSource PortDest PortSource IPDest IP
    Apr 24, 2024 12:53:05.787813902 CEST4970480192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:05.792391062 CEST4970580192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:06.042227030 CEST4970980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:06.790805101 CEST4970480192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:06.806775093 CEST4970580192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:07.046787024 CEST4970980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:08.804785013 CEST4970480192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:08.820792913 CEST4970580192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:08.884371042 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:09.058829069 CEST4970980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:09.183815956 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:09.786792994 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:10.620891094 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.620976925 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:10.621083975 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.621287107 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.621325970 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:10.992726088 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:10.993072033 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.993103027 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:10.993801117 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:10.994596004 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:10.994693041 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.996265888 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:10.996356964 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:11.039819956 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:11.039849997 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:11.087815046 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:11.234147072 CEST4968980192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:12.808901072 CEST4970480192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:12.823904991 CEST4970580192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:13.063837051 CEST4970980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:13.398793936 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:15.288619041 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.288664103 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.288781881 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.290786028 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.290808916 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.636425018 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.636528015 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.640114069 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.640135050 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.640588999 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.686925888 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.732120991 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.995601892 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.995675087 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.995737076 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.995805979 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.995826006 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:15.995847940 CEST49715443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:15.995855093 CEST4434971523.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.027798891 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:16.027848959 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:16.027935028 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:16.028956890 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:16.028966904 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:16.032454014 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.032476902 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.032558918 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.032767057 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.032776117 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.373429060 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.373517036 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.374758005 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.374763012 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.375072002 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.376328945 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.420120955 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.709500074 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.709575891 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.709635019 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.711213112 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.711231947 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.711249113 CEST49717443192.168.2.1623.206.6.29
    Apr 24, 2024 12:53:16.711255074 CEST4434971723.206.6.29192.168.2.16
    Apr 24, 2024 12:53:16.962007999 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:16.962131977 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:16.968384981 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:16.968424082 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:16.968789101 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.012923956 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.028660059 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.061223030 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:17.076117039 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.364808083 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:17.870522022 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870543003 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870549917 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870562077 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870600939 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870645046 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.870676041 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870701075 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.870722055 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.870732069 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870742083 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870785952 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.870799065 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870815992 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.870861053 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.882277012 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.882297993 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.882313967 CEST49716443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:17.882320881 CEST4434971640.68.123.157192.168.2.16
    Apr 24, 2024 12:53:17.967945099 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:18.206800938 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:19.180843115 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:20.823832035 CEST4970480192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:20.823868036 CEST4970580192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:20.995569944 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:20.995642900 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:20.995722055 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:21.078814983 CEST4970980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:21.519985914 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:21.584038019 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:21.822858095 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:21.968537092 CEST49711443192.168.2.16142.250.141.104
    Apr 24, 2024 12:53:21.968600035 CEST44349711142.250.141.104192.168.2.16
    Apr 24, 2024 12:53:22.426839113 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:23.640965939 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:26.050527096 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:26.398860931 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:27.811837912 CEST49673443192.168.2.16204.79.197.203
    Apr 24, 2024 12:53:27.866172075 CEST4971880192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:27.866309881 CEST4971980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:28.131200075 CEST4972080192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:28.877948046 CEST4971980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:28.877962112 CEST4971880192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:29.132936954 CEST4972080192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:30.851936102 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:30.883837938 CEST4971980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:30.883852959 CEST4971880192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:31.139862061 CEST4972080192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:34.897842884 CEST4971980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:34.897885084 CEST4971880192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:35.153839111 CEST4972080192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:36.000880957 CEST49678443192.168.2.1620.189.173.10
    Apr 24, 2024 12:53:40.456872940 CEST4968080192.168.2.16192.229.211.108
    Apr 24, 2024 12:53:42.900878906 CEST4971980192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:42.900881052 CEST4971880192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:43.156873941 CEST4972080192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:53.162102938 CEST4969880192.168.2.1623.1.234.57
    Apr 24, 2024 12:53:53.162206888 CEST4969980192.168.2.1623.1.234.57
    Apr 24, 2024 12:53:53.321870089 CEST804969823.1.234.57192.168.2.16
    Apr 24, 2024 12:53:53.321897984 CEST804969923.1.234.57192.168.2.16
    Apr 24, 2024 12:53:53.321996927 CEST4969880192.168.2.1623.1.234.57
    Apr 24, 2024 12:53:53.322021961 CEST4969980192.168.2.1623.1.234.57
    Apr 24, 2024 12:53:53.948997021 CEST4972180192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:53.949307919 CEST4972280192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:54.212268114 CEST4972380192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:54.442245007 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:54.442281008 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:54.442378044 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:54.442847013 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:54.442858934 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:54.962986946 CEST4972180192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:54.963088036 CEST4972280192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:55.216898918 CEST4972380192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:55.375853062 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:55.376008034 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:55.377492905 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:55.377501965 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:55.377782106 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:55.379352093 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:55.424114943 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282058954 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282085896 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282121897 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282350063 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.282363892 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282418013 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.282455921 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282500982 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282524109 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.282530069 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282560110 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.282589912 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.282603979 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.287775993 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.287791014 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.287810087 CEST49724443192.168.2.1640.68.123.157
    Apr 24, 2024 12:53:56.287813902 CEST4434972440.68.123.157192.168.2.16
    Apr 24, 2024 12:53:56.973927021 CEST4972180192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:56.973931074 CEST4972280192.168.2.16208.48.229.99
    Apr 24, 2024 12:53:57.228977919 CEST4972380192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:00.989001036 CEST4972280192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:00.989017010 CEST4972180192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:01.242939949 CEST4972380192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:08.995018005 CEST4972180192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:08.995088100 CEST4972280192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:09.253074884 CEST4972380192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:10.528707027 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:10.528758049 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.528904915 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:10.529247999 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:10.529263020 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.891848087 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.892185926 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:10.892205954 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.893296003 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.893635988 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:10.893806934 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:10.939927101 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:11.370024920 CEST49688443192.168.2.1613.107.21.200
    Apr 24, 2024 12:54:20.930339098 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:20.930419922 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:20.930496931 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:21.973459959 CEST49726443192.168.2.16142.250.141.104
    Apr 24, 2024 12:54:21.973490000 CEST44349726142.250.141.104192.168.2.16
    Apr 24, 2024 12:54:44.686856985 CEST4970180192.168.2.16192.229.211.108
    Apr 24, 2024 12:54:44.846370935 CEST8049701192.229.211.108192.168.2.16
    Apr 24, 2024 12:54:44.846555948 CEST4970180192.168.2.16192.229.211.108
    Apr 24, 2024 12:54:45.012303114 CEST4972880192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:45.012353897 CEST4972980192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:45.277724981 CEST4973080192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:46.024610996 CEST4972880192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:46.025777102 CEST4972980192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:46.279674053 CEST4973080192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:48.038654089 CEST4972880192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:48.038655996 CEST4972980192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:48.293601990 CEST4973080192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:52.046627998 CEST4972880192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:52.046864986 CEST4972980192.168.2.16208.48.229.99
    Apr 24, 2024 12:54:52.301578999 CEST4973080192.168.2.16208.48.229.99
    Apr 24, 2024 12:55:00.051536083 CEST4972980192.168.2.16208.48.229.99
    Apr 24, 2024 12:55:00.051599979 CEST4972880192.168.2.16208.48.229.99
    Apr 24, 2024 12:55:00.307600021 CEST4973080192.168.2.16208.48.229.99
    TimestampSource PortDest PortSource IPDest IP
    Apr 24, 2024 12:53:05.941925049 CEST53530431.1.1.1192.168.2.16
    Apr 24, 2024 12:53:05.951922894 CEST53647201.1.1.1192.168.2.16
    Apr 24, 2024 12:53:06.906464100 CEST53613291.1.1.1192.168.2.16
    Apr 24, 2024 12:53:10.466017962 CEST6022453192.168.2.161.1.1.1
    Apr 24, 2024 12:53:10.466494083 CEST5737753192.168.2.161.1.1.1
    Apr 24, 2024 12:53:10.619441986 CEST53602241.1.1.1192.168.2.16
    Apr 24, 2024 12:53:10.619911909 CEST53573771.1.1.1192.168.2.16
    Apr 24, 2024 12:53:23.972223043 CEST53540291.1.1.1192.168.2.16
    Apr 24, 2024 12:53:42.839649916 CEST53615031.1.1.1192.168.2.16
    Apr 24, 2024 12:54:05.792819977 CEST53525461.1.1.1192.168.2.16
    Apr 24, 2024 12:54:05.900068045 CEST53596281.1.1.1192.168.2.16
    Apr 24, 2024 12:54:13.232465029 CEST138138192.168.2.16192.168.2.255
    Apr 24, 2024 12:54:34.443691969 CEST53588721.1.1.1192.168.2.16
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Apr 24, 2024 12:53:10.466017962 CEST192.168.2.161.1.1.10x4145Standard query (0)www.google.comA (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.466494083 CEST192.168.2.161.1.1.10xebfcStandard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619441986 CEST1.1.1.1192.168.2.160x4145No error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
    Apr 24, 2024 12:53:10.619911909 CEST1.1.1.1192.168.2.160xebfcNo error (0)www.google.com65IN (0x0001)false
    • fs.microsoft.com
    • slscr.update.microsoft.com
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.164971523.206.6.29443
    TimestampBytes transferredDirectionData
    2024-04-24 10:53:15 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-04-24 10:53:15 UTC467INHTTP/1.1 200 OK
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    Content-Type: application/octet-stream
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    Server: ECAcc (sac/2518)
    X-CID: 11
    X-Ms-ApiVersion: Distribute 1.2
    X-Ms-Region: prod-eus-z1
    Cache-Control: public, max-age=245433
    Date: Wed, 24 Apr 2024 10:53:15 GMT
    Connection: close
    X-CID: 2


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    1192.168.2.164971723.206.6.29443
    TimestampBytes transferredDirectionData
    2024-04-24 10:53:16 UTC239OUTGET /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
    Range: bytes=0-2147483646
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-04-24 10:53:16 UTC531INHTTP/1.1 200 OK
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Content-Type: application/octet-stream
    ApiVersion: Distribute 1.1
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    X-Azure-Ref: 0Fz4RYwAAAACZW8dCTzveR7lI76J6Z2l5U0pDRURHRTA1MTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
    Cache-Control: public, max-age=245425
    Date: Wed, 24 Apr 2024 10:53:16 GMT
    Content-Length: 55
    Connection: close
    X-CID: 2
    2024-04-24 10:53:16 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    2192.168.2.164971640.68.123.157443
    TimestampBytes transferredDirectionData
    2024-04-24 10:53:17 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XoH1sckWpD61SFd&MD=BDLYU7MP HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
    Host: slscr.update.microsoft.com
    2024-04-24 10:53:17 UTC560INHTTP/1.1 200 OK
    Cache-Control: no-cache
    Pragma: no-cache
    Content-Type: application/octet-stream
    Expires: -1
    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
    ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
    MS-CorrelationId: de61c8cf-8e2b-46ff-9d1b-1d8b2d906f18
    MS-RequestId: 09b32db5-1d57-4bd5-ba01-319350073b9e
    MS-CV: vCSJuVM17kOeV9Nt.0
    X-Microsoft-SLSClientCache: 2880
    Content-Disposition: attachment; filename=environment.cab
    X-Content-Type-Options: nosniff
    Date: Wed, 24 Apr 2024 10:53:17 GMT
    Connection: close
    Content-Length: 24490
    2024-04-24 10:53:17 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
    Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
    2024-04-24 10:53:17 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
    Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    3192.168.2.164972440.68.123.157443
    TimestampBytes transferredDirectionData
    2024-04-24 10:53:55 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XoH1sckWpD61SFd&MD=BDLYU7MP HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
    Host: slscr.update.microsoft.com
    2024-04-24 10:53:56 UTC560INHTTP/1.1 200 OK
    Cache-Control: no-cache
    Pragma: no-cache
    Content-Type: application/octet-stream
    Expires: -1
    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
    ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
    MS-CorrelationId: f1f08b5d-74f8-4d78-8944-63130b6847b5
    MS-RequestId: 2f144767-482a-44f6-a55a-a35a43d99f9f
    MS-CV: 3eK+MEnTR0ueo/iJ.0
    X-Microsoft-SLSClientCache: 2160
    Content-Disposition: attachment; filename=environment.cab
    X-Content-Type-Options: nosniff
    Date: Wed, 24 Apr 2024 10:53:55 GMT
    Connection: close
    Content-Length: 25457
    2024-04-24 10:53:56 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
    Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
    2024-04-24 10:53:56 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
    Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:12:53:04
    Start date:24/04/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://208.48.229.99/
    Imagebase:0x7ff7f9810000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:1
    Start time:12:53:04
    Start date:24/04/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1924,i,16111623134245472612,15511103530334576046,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff7f9810000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    No disassembly