Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d

Overview

General Information

Sample URL:https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d
Analysis ID:1431122
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6736 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2212,i,17304811127047344951,1977242911418865081,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 6356 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://cw-eu-documents.s3.eu-west-1.amazonaws.com/infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0...HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.7:49715 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 40.119.6.228
Source: global trafficHTTP traffic detected: GET /v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d HTTP/1.1Host: eu.myconnectwise.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413c HTTP/1.1Host: cw-eu-documents.s3.eu-west-1.amazonaws.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cw-eu-documents.s3.eu-west-1.amazonaws.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://cw-eu-documents.s3.eu-west-1.amazonaws.com/infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413cAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: eu.myconnectwise.net
Source: global trafficDNS traffic detected: DNS query: cw-eu-documents.s3.eu-west-1.amazonaws.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbiddenx-amz-request-id: GNFSBTRVD043NRBQx-amz-id-2: wYnovtjKW3N9VwKhdkojjZILJB3qtAzTMxTzddrEXlsrjPr38PEj+DgnNShz4vva79V/eZ+1v1w=Content-Type: application/xmlTransfer-Encoding: chunkedDate: Wed, 24 Apr 2024 14:02:22 GMTServer: AmazonS3Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.7:49715 version: TLS 1.2
Source: classification engineClassification label: clean0.win@18/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2212,i,17304811127047344951,1977242911418865081,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2212,i,17304811127047344951,1977242911418865081,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    s3-r-w.eu-west-1.amazonaws.com
    52.218.116.234
    truefalse
      high
      eu.myconnectwise.net
      18.164.174.26
      truefalse
        high
        www.google.com
        142.250.141.99
        truefalse
          high
          cw-eu-documents.s3.eu-west-1.amazonaws.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46dfalse
              high
              https://cw-eu-documents.s3.eu-west-1.amazonaws.com/favicon.icofalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                18.164.174.26
                eu.myconnectwise.netUnited States
                3MIT-GATEWAYSUSfalse
                52.218.116.234
                s3-r-w.eu-west-1.amazonaws.comUnited States
                16509AMAZON-02USfalse
                142.250.141.99
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.7
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1431122
                Start date and time:2024-04-24 16:01:20 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 24s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:16
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@18/4@6/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.102, 142.251.2.101, 142.251.2.100, 142.251.2.113, 142.251.2.138, 142.251.2.139, 142.251.2.84, 34.104.35.123, 40.68.123.157, 23.45.12.163, 23.45.12.153, 13.85.23.206, 23.45.12.170, 142.251.2.94, 23.45.12.161
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, time.windows.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 480 x 43, 8-bit/color RGBA, non-interlaced
                Category:downloaded
                Size (bytes):2224
                Entropy (8bit):7.74256788769744
                Encrypted:false
                SSDEEP:48:esZ6ViAfEE0H9IR5PDiHmgaT1rD83NoIaaGko1FVCyVZW5rrmvYsF4Eb+N:5Z09EE8IfMmgY1rD83yHFVCyLarmvP4F
                MD5:60DD8DF5242525EBEE08E9BDDF3B6C68
                SHA1:149085CAA1261C955B65591350BEF327FC5CA0D8
                SHA-256:90DF602A99F22AD2A3E20EDFF4281BC11022E1F25607E6714A6041B7F4978AFB
                SHA-512:812F71918998420AA2EAB219D76AC969AF4E5C82090638B3B803A42CF0A97D66E8ABD53BE4BCC5E366B6911104080264C7B022E842E7AAA44AC1E3FA6A65EB5A
                Malicious:false
                Reputation:low
                URL:https://cw-eu-documents.s3.eu-west-1.amazonaws.com/infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413c
                Preview:.PNG........IHDR.......+.......[V....sRGB.........gAMA......a.....pHYs..........o.d...EIDATx^....e..p...(.....B..$....5A..o...x@...j..c.c.@......Z."]..-.-t..fII.P...PBkj.K.F.>o.Rvv......$..>..3.y.|.yf..==C...0{6..d.C..........u"....f........`.... ....<..............`.... ....<..............`.... ....<..............`.H.zJe.0..e.hR.x...5...L(B..*M.....8JsCq..._..r...M..>(.hK?........25j..b4hc$...9[..i.....(........Y.....G...7......A.....tYNz.|."=..3.h.N7./j...}.{..P...P...}.,....U.0....|e.^.W.f..k...H.h.Q..b....._..^o....F.EZ.2K..&.e.v&....ES....H...~Y.R..~\....r#.A...4>...f.^K...T7........sT.%.F+%Z>.l:2D..FV?..6v?y.~BtR.#...uL.xFV6..s......ew.X...R..[..5...{.!?.?...9Z.v......b...e..DhL..v....{U.b...Tm.1..&u.q.M..M6._.qe.F..2.\:....h.....W...+....|.....tCN-.......S.3..j3.y1.h!o.cE.,k.5..U..Z.B{u.V..&.......d..O.%..4...z..T@]..u?F3.Y.../\../....2.2c#.....:7'K.q....9...eQ'...Q.&.q...`.I......xm........Z.u.......=."...~...tR.../.W...+.U.e....p....z
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, ASCII text
                Category:downloaded
                Size (bytes):243
                Entropy (8bit):5.558587984818707
                Encrypted:false
                SSDEEP:6:TMVBd/ZbZjZvKtWRVzjiASr5NnUWUPVE08QeqYZ2ian:TMHd9BZKtWRf2UWUPvOqYZta
                MD5:9524491D53AB928F14466C1EC707B6B0
                SHA1:4E94B1528177221C5DE2C9E80DB6372B6A8258DF
                SHA-256:43922E725FE17A251EECE2FDF11BE25559E44215BDC24BC4B43AC1B0BB4CCF7F
                SHA-512:46A51A86D815928C2D727CF853A013CC53C11848809A439D9B98CEC899CC3BC3D169BA74188F14836DDC55A2BFE41C29A3CD07C51F4657C191F70AF5EE3E35F9
                Malicious:false
                Reputation:low
                URL:https://cw-eu-documents.s3.eu-west-1.amazonaws.com/favicon.ico
                Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>GNFSBTRVD043NRBQ</RequestId><HostId>wYnovtjKW3N9VwKhdkojjZILJB3qtAzTMxTzddrEXlsrjPr38PEj+DgnNShz4vva79V/eZ+1v1w=</HostId></Error>
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 24, 2024 16:02:08.245867014 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:08.558027029 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:08.807987928 CEST49674443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:08.823631048 CEST49675443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:08.901753902 CEST49672443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:09.167404890 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:10.370487928 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:12.776798010 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:16.794281960 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:17.199285984 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:17.605381966 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:17.989360094 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:18.142419100 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.142456055 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.142532110 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.142929077 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.142970085 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.143275023 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.143326044 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.143337011 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.143558025 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.143572092 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.472688913 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.473098040 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.473124981 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.474351883 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.474422932 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.475682020 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.475756884 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.475874901 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.476336002 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.476547003 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.476576090 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.477838039 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.477921009 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.478800058 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.478869915 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.495367050 CEST49675443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:18.495460987 CEST49674443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:18.511373043 CEST49672443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:18.516160011 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.684119940 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.684156895 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:18.684231043 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:18.684298992 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:19.117789984 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.117820024 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.117889881 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:19.117918015 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.117959976 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:19.121068001 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.121154070 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.121197939 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:19.177979946 CEST49706443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:19.178004980 CEST4434970618.164.174.26192.168.2.7
                Apr 24, 2024 16:02:19.395354033 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:19.395440102 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:19.395512104 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:19.396601915 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:19.396640062 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:19.495387077 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:19.928853989 CEST44349699104.98.116.138192.168.2.7
                Apr 24, 2024 16:02:19.928956032 CEST49699443192.168.2.7104.98.116.138
                Apr 24, 2024 16:02:20.319782019 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.320096016 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.320130110 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.321258068 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.321331024 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.321351051 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.321403980 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.560390949 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.560641050 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.560969114 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.561019897 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:20.700211048 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:20.735121965 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:20.735207081 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:20.735383034 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:20.736072063 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:20.736121893 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.097783089 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.101728916 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:21.101793051 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.102906942 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.103014946 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:21.119146109 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:21.119378090 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.170013905 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:21.170037031 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:21.210933924 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:21.211009026 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:21.211086988 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:21.211086035 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.211137056 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.214148998 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:21.305490971 CEST49710443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.305560112 CEST4434971052.218.116.234192.168.2.7
                Apr 24, 2024 16:02:21.431823015 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.431875944 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:21.431956053 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.438613892 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:21.438632965 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.040694952 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.040728092 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.040868044 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.042793036 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.042809010 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.341706991 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.342478037 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:22.342502117 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.342865944 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.355896950 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:22.356028080 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.360327959 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:22.360375881 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.389036894 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.389126062 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.401925087 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.401952982 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.402901888 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.448307991 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.479530096 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:22.669594049 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.669728994 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.669830084 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:22.702894926 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.748114109 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.763084888 CEST49712443192.168.2.752.218.116.234
                Apr 24, 2024 16:02:22.763112068 CEST4434971252.218.116.234192.168.2.7
                Apr 24, 2024 16:02:22.872778893 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.872975111 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.873258114 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.885314941 CEST49713443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.885353088 CEST4434971323.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.994117022 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.994208097 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:22.994450092 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.995105982 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:22.995138884 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.337219000 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.337315083 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.339405060 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.339416027 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.339746952 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.343863964 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.384129047 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.673748970 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.674552917 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.674607038 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.675071955 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.675087929 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:23.675100088 CEST49715443192.168.2.723.202.57.177
                Apr 24, 2024 16:02:23.675105095 CEST4434971523.202.57.177192.168.2.7
                Apr 24, 2024 16:02:27.215070009 CEST49671443192.168.2.7204.79.197.203
                Apr 24, 2024 16:02:28.433312893 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:31.125099897 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:31.125272036 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:31.125426054 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:32.544831038 CEST49711443192.168.2.7142.250.141.99
                Apr 24, 2024 16:02:32.544902086 CEST44349711142.250.141.99192.168.2.7
                Apr 24, 2024 16:02:40.339756012 CEST49677443192.168.2.720.50.201.200
                Apr 24, 2024 16:02:48.465794086 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:48.465959072 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:02:48.466017962 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:48.544270039 CEST49707443192.168.2.718.164.174.26
                Apr 24, 2024 16:02:48.544298887 CEST4434970718.164.174.26192.168.2.7
                Apr 24, 2024 16:03:20.625296116 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:20.625327110 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:20.625447989 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:20.625701904 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:20.625719070 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:20.988753080 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:20.989111900 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:20.989128113 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:20.989417076 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:20.989958048 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:20.990010977 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:21.030261040 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:30.993710995 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:30.993776083 CEST44349722142.250.141.99192.168.2.7
                Apr 24, 2024 16:03:30.993855953 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:31.131232977 CEST49722443192.168.2.7142.250.141.99
                Apr 24, 2024 16:03:31.131259918 CEST44349722142.250.141.99192.168.2.7
                TimestampSource PortDest PortSource IPDest IP
                Apr 24, 2024 16:02:16.352252007 CEST53491811.1.1.1192.168.2.7
                Apr 24, 2024 16:02:16.439111948 CEST53623971.1.1.1192.168.2.7
                Apr 24, 2024 16:02:17.762129068 CEST53608011.1.1.1192.168.2.7
                Apr 24, 2024 16:02:17.967082024 CEST5206553192.168.2.71.1.1.1
                Apr 24, 2024 16:02:17.967545033 CEST6332153192.168.2.71.1.1.1
                Apr 24, 2024 16:02:18.137465954 CEST53633211.1.1.1192.168.2.7
                Apr 24, 2024 16:02:18.138962030 CEST53520651.1.1.1192.168.2.7
                Apr 24, 2024 16:02:19.185726881 CEST6512653192.168.2.71.1.1.1
                Apr 24, 2024 16:02:19.186408043 CEST5574953192.168.2.71.1.1.1
                Apr 24, 2024 16:02:19.354207993 CEST53651261.1.1.1192.168.2.7
                Apr 24, 2024 16:02:19.393563986 CEST53557491.1.1.1192.168.2.7
                Apr 24, 2024 16:02:20.561752081 CEST5023453192.168.2.71.1.1.1
                Apr 24, 2024 16:02:20.561923981 CEST5423853192.168.2.71.1.1.1
                Apr 24, 2024 16:02:20.715110064 CEST53502341.1.1.1192.168.2.7
                Apr 24, 2024 16:02:20.715306997 CEST53542381.1.1.1192.168.2.7
                Apr 24, 2024 16:02:23.512018919 CEST123123192.168.2.740.119.6.228
                Apr 24, 2024 16:02:23.725660086 CEST12312340.119.6.228192.168.2.7
                Apr 24, 2024 16:02:35.858931065 CEST53509731.1.1.1192.168.2.7
                Apr 24, 2024 16:02:54.629446030 CEST53529851.1.1.1192.168.2.7
                Apr 24, 2024 16:03:16.074258089 CEST53493081.1.1.1192.168.2.7
                Apr 24, 2024 16:03:17.288712025 CEST138138192.168.2.7192.168.2.255
                Apr 24, 2024 16:03:17.873461962 CEST53591821.1.1.1192.168.2.7
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 24, 2024 16:02:17.967082024 CEST192.168.2.71.1.1.10x5ef2Standard query (0)eu.myconnectwise.netA (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:17.967545033 CEST192.168.2.71.1.1.10x9503Standard query (0)eu.myconnectwise.net65IN (0x0001)false
                Apr 24, 2024 16:02:19.185726881 CEST192.168.2.71.1.1.10x8450Standard query (0)cw-eu-documents.s3.eu-west-1.amazonaws.comA (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.186408043 CEST192.168.2.71.1.1.10xb69Standard query (0)cw-eu-documents.s3.eu-west-1.amazonaws.com65IN (0x0001)false
                Apr 24, 2024 16:02:20.561752081 CEST192.168.2.71.1.1.10xd2f1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.561923981 CEST192.168.2.71.1.1.10xafcaStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 24, 2024 16:02:18.138962030 CEST1.1.1.1192.168.2.70x5ef2No error (0)eu.myconnectwise.net18.164.174.26A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:18.138962030 CEST1.1.1.1192.168.2.70x5ef2No error (0)eu.myconnectwise.net18.164.174.58A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:18.138962030 CEST1.1.1.1192.168.2.70x5ef2No error (0)eu.myconnectwise.net18.164.174.31A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:18.138962030 CEST1.1.1.1192.168.2.70x5ef2No error (0)eu.myconnectwise.net18.164.174.63A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)cw-eu-documents.s3.eu-west-1.amazonaws.coms3-r-w.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.218.116.234A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.92.17.162A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com3.5.65.1A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.218.108.48A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.218.97.131A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.218.44.58A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com3.5.69.112A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.354207993 CEST1.1.1.1192.168.2.70x8450No error (0)s3-r-w.eu-west-1.amazonaws.com52.218.44.74A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:19.393563986 CEST1.1.1.1192.168.2.70xb69No error (0)cw-eu-documents.s3.eu-west-1.amazonaws.coms3-r-w.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715110064 CEST1.1.1.1192.168.2.70xd2f1No error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:20.715306997 CEST1.1.1.1192.168.2.70xafcaNo error (0)www.google.com65IN (0x0001)false
                Apr 24, 2024 16:02:44.199153900 CEST1.1.1.1192.168.2.70x7cb7No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 24, 2024 16:02:44.199153900 CEST1.1.1.1192.168.2.70x7cb7No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                • eu.myconnectwise.net
                • cw-eu-documents.s3.eu-west-1.amazonaws.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.74970618.164.174.264436736C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 14:02:18 UTC741OUTGET /v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d HTTP/1.1
                Host: eu.myconnectwise.net
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 14:02:19 UTC4551INHTTP/1.1 302 Moved Temporarily
                Content-Length: 0
                Connection: close
                Date: Wed, 24 Apr 2024 14:02:18 GMT
                Cache-Control: no-cache
                Pragma: no-cache
                Expires: -1
                Location: https://cw-eu-documents.s3.eu-west-1.amazonaws.com/infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413c
                Server: Microsoft-IIS/10.0
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                api-current-version: 3.1.0
                Content-Security-Policy: frame-ancestors 'self' blob: *.myconnectwise.net *.connectwisedev.com *.itboost.com; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.walkme.com *.connectwise *.connectwise.com az416426.vo.msecnd.net dc.services.visualstudio.com/v2/track *.connectwisedev.com *.myconnectwise.net cwview.com *.cwview.com *.cwnet.io *.wise-pay.com *.wise-sync.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com files.connectwise.com *.itsupport247.net *.myconnectwise.net; font-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.walkme.com *.connectwise.com *.googleapis.com; img-src * data: snapshot:; frame-src * data: mailto:; connect-src 'self' *.walkme.com *.connectwise.com *.connectwisedev.com *.myconnectwise.net *.itsupport247.net cwview.com *.cwview.com *.cwnet.io dc.services.visualstudio.com/v2/track cheetah quotewerks://* wss://*.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.connectwise.com *.connectwisedev.com *.myconnectwise.net cwview.com *.cwview.com *.walkme.com *.cwnet.io *.itsupport247.net
                Referrer-Policy: strict-origin-when-cross-origin
                X-Content-Type-Options: nosniff
                X-Xss-Protection: 1; mode=block
                Content-Security-Policy: frame-ancestors 'self' blob: *.myconnectwise.net *.connectwisedev.com *.itboost.com; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.walkme.com *.connectwise *.connectwise.com az416426.vo.msecnd.net dc.services.visualstudio.com/v2/track *.connectwisedev.com *.myconnectwise.net cwview.com *.cwview.com *.cwnet.io *.wise-pay.com *.wise-sync.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com files.connectwise.com *.itsupport247.net *.myconnectwise.net; font-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.walkme.com *.connectwise.com *.googleapis.com; img-src * data: snapshot:; frame-src * data: mailto:; connect-src 'self' *.walkme.com *.connectwise.com *.connectwisedev.com *.myconnectwise.net *.itsupport247.net cwview.com *.cwview.com *.cwnet.io dc.services.visualstudio.com/v2/track cheetah quotewerks://* wss://*.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.connectwise.com *.connectwisedev.com *.myconnectwise.net cwview.com *.cwview.com *.walkme.com *.cwnet.io *.itsupport247.net
                Referrer-Policy: strict-origin-when-cross-origin
                X-Cache: Miss from cloudfront
                Via: 1.1 c6a4871893ac935ba2b308d02ff4cd7a.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: LAX53-P4
                X-Amz-Cf-Id: vo6wrJKfnzTC0w4D52G8rza5F8qv98Or4NcpDlGFjGb5OkW2aoD2Hg==


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.74971052.218.116.2344436736C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 14:02:20 UTC2419OUTGET /infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413c HTTP/1.1
                Host: cw-eu-documents.s3.eu-west-1.amazonaws.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 14:02:21 UTC466INHTTP/1.1 200 OK
                x-amz-id-2: 8bBctFaVHW/NMIGLfW2Tcut5l46YPis0Yd5bdPuetpZjOPbqHvPVpvseQf+h8Donvgo1GthQru8=
                x-amz-request-id: B2ZC5CFY7ERTQ0BA
                Date: Wed, 24 Apr 2024 14:02:22 GMT
                Last-Modified: Wed, 24 Apr 2024 10:20:25 GMT
                ETag: "60dd8df5242525ebee08e9bddf3b6c68"
                x-amz-server-side-encryption: AES256
                x-amz-version-id: PenX5I8azyVtPIRiK4jyZX60nNYcd9eP
                Accept-Ranges: bytes
                Content-Type: image/png
                Server: AmazonS3
                Content-Length: 2224
                Connection: close
                2024-04-24 14:02:21 UTC2224INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 e0 00 00 00 2b 08 06 00 00 00 a0 8c 5b 56 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 08 45 49 44 41 54 78 5e ed dc cd 8f 13 65 1c 07 70 12 e1 0f 28 1e b8 14 d4 cb 42 d0 03 24 ac 06 8c 12 35 41 d0 03 6f e1 04 d1 78 40 f4 c2 0a 6a b2 1a 63 04 63 d4 40 82 d1 db ae 1a 88 0c 5a dd 22 5d b6 da ae 2d d9 9a 2d 74 93 16 66 49 49 ba 50 92 2e 94 50 42 6b 6a a8 4b 13 46 7f 3e 6f f3 52 76 76 b3 05 dc 19 e1 fb 24 9f c0 3e fb cc 33 9d 79 c8 7c e7 79 66 ca 9c 05 3d 3d 43 00 00 00 30 7b 36 ed df bf 64 ce 43 07 0f 12 00 00 00 cc 9e b5 fb f6 75 22 80 01 00 00 66 19 02 18 00 00 c0 03 08 60 00 00 00 0f 20 80
                Data Ascii: PNGIHDR+[VsRGBgAMAapHYsodEIDATx^ep(B$5Aox@jcc@Z"]--tfIIP.PBkjKF>oRvv$>3y|yf==C0{6dCu"f`


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.74971252.218.116.2344436736C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 14:02:22 UTC2374OUTGET /favicon.ico HTTP/1.1
                Host: cw-eu-documents.s3.eu-west-1.amazonaws.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://cw-eu-documents.s3.eu-west-1.amazonaws.com/infinitygrp/7df2b4da-ddd3-49bc-9d40-ba86e6ff6d6c.png?X-Amz-Expires=300&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEEUaCWV1LXdlc3QtMSJGMEQCIGhCZ04ZR7dqRuUrg2gcJEnulmoGQDZTwlL%2FyPHVfzqyAiBB3Wl8Z5Rlc4gOZIAmW4L4N3N5gatma5hsPemdQsILsyq6BQiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwOTA0MzgzMTM3OCIMarrG2VhTy3VjABzxKo4FfTUisDdctRb3p%2Bd8HMbM6IhdntM25HsBTZwWmDvJZJKM3tuY7CkSVR3b3Bz2FtVJeJ7fycf3ecFIU146BrrIjh%2BGsDbeTcxiB9rTepupv7sslvTeYFwwqvl4OA0AHri5PJou3lEAA4N%2BwwHuyTJEzs%2BzAPXEEn1WwzlwW2g2FAtfghaEKC3mw01tGhXSO0cFvu7ApgMOJGBDJAV3KffZc%2B4bK1ZMhgI0LvcIGVDkIivnWHKIUDCp4XMvzUyHR4jo%2BpWI79mconN1xSn5kMw71aDlmD1XEK8JTb0HnGTA9QQCvoF7bUR%2FwRJPzMBmjcV4WqJiJBY9DUp8YLC18hNWqqANHuRVmSD%2BX0MXbj2dW2NDH80yvhPwWFApqWvplDutkONR4oAv939zO%2FuH0uuE1mD9EA6NGbTyggCGKAqBcCTvbrRkXqDf9Ht8Gx87gLw%2BRmvIm97EH5CMwq4vMGBc5%2FiCqZn6k6hjrfFuNSdBHJXs9ZvVeMQwwLUxSkRE8FeB7EnSA9iCUVtjtqh5iujwVXZrKrg%2BmEdtIRMhBNPAR63eLGyL14GQe2WZs9Lt6%2F8BKKJBT0yfYn3IJJjlt12EJqRxEn%2FN20zKB%2BwSs%2FTJekbw5FV0HjD7t4a%2F0bxXVG9x9ggMsKPkkTKBqW1%2F%2Fq0AE6ulPhZETnISCNBifCH3eTtuNyV8h4NqL2QairfHeKTvHLeZbAkm4Dsvn9tETsJfdR4Ze11ps2a9WZIwyZ8YFnMs1Na4V4raPVLIXfIEtcTGQoNJFCkD9YJAutEg%2FkyQq14KZg4iYF44BpncxulaJRfa9FwR%2F0YzEMJ9oW8HbXX%2FGaIZzlD6ecVUPMxjER3KGHu4WVekMoHaxLBJzVEzMLSCpLEGOrIBYgHU34OyNThsb0zrFpSI948XMVqGzl7FP1Xrm0QO9LF6e6ovad9DGyoi8PWC4vUjxei9mV6YMzvyxrc0qgyjeYdVn6ggphdHv6r9Mkbxq2dMyk%2BCjQL15lGsdy5AANVg6Kt7QrDi2JRLpn5DVe7oa6So9rFzBT7pDcZ7NlBDuoo45RM4d5AdoZtV89tn9YtWN%2BBi1qjyl%2FzA14FV%2BSUWpAmNYVa5E874LsuAt5oivKSwWQ%3D%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQEGYN5JJNLUOHHLU%2F20240424%2Feu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20240424T140218Z&X-Amz-SignedHeaders=host&X-Amz-Signature=f433cf11fba2c2737f30faae122ab28581622d995f31674453f0cfa77e57413c
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 14:02:22 UTC285INHTTP/1.1 403 Forbidden
                x-amz-request-id: GNFSBTRVD043NRBQ
                x-amz-id-2: wYnovtjKW3N9VwKhdkojjZILJB3qtAzTMxTzddrEXlsrjPr38PEj+DgnNShz4vva79V/eZ+1v1w=
                Content-Type: application/xml
                Transfer-Encoding: chunked
                Date: Wed, 24 Apr 2024 14:02:22 GMT
                Server: AmazonS3
                Connection: close
                2024-04-24 14:02:22 UTC254INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 47 4e 46 53 42 54 52 56 44 30 34 33 4e 52 42 51 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 77 59 6e 6f 76 74 6a 4b 57 33 4e 39 56 77 4b 68 64 6b 6f 6a 6a 5a 49 4c 4a 42 33 71 74 41 7a 54 4d 78 54 7a 64 64 72 45 58 6c 73 72 6a 50 72 33 38 50 45 6a 2b 44 67 6e 4e 53 68 7a 34 76 76 61 37 39 56 2f 65 5a 2b 31 76 31 77 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a 30 0d 0a 0d 0a
                Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>GNFSBTRVD043NRBQ</RequestId><HostId>wYnovtjKW3N9VwKhdkojjZILJB3qtAzTMxTzddrEXlsrjPr38PEj+DgnNShz4vva79V/eZ+1v1w=</HostId></Error>0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.74971323.202.57.177443
                TimestampBytes transferredDirectionData
                2024-04-24 14:02:22 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-24 14:02:22 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (sac/2518)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=234057
                Date: Wed, 24 Apr 2024 14:02:22 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.74971523.202.57.177443
                TimestampBytes transferredDirectionData
                2024-04-24 14:02:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-24 14:02:23 UTC521INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-MSEdge-Ref: Ref A: CC1186E36C704BA5AF8177F229D6CC87 Ref B: PAOEDGE0621 Ref C: 2023-04-04T13:32:33Z
                Cache-Control: public, max-age=234008
                Date: Wed, 24 Apr 2024 14:02:23 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-24 14:02:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:16:02:09
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:16:02:15
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2212,i,17304811127047344951,1977242911418865081,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:11
                Start time:16:02:17
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eu.myconnectwise.net/v4_6_release/api/inlineimages/infinitygrp/8a07a37f-0e34-48e8-8792-5f81fcbde46d"
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly