Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938

Overview

General Information

Sample URL:https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938
Analysis ID:1431388
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 5580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3664 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=2016,i,8647603559806436608,12181136153905039309,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6448 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938SlashNext: detection malicious, Label: Scareware type: Phishing & Social Engineering
Source: https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 23.216.69.213
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.26
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.26
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.216.69.213:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=2016,i,8647603559806436608,12181136153905039309,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=2016,i,8647603559806436608,12181136153905039309,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-09380%Avira URL Cloudsafe
https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938100%SlashNextScareware type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
64.233.176.105
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      64.233.176.105
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      192.168.2.5
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1431388
      Start date and time:2024-04-25 00:52:43 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 10s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal48.win@16/4@2/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.251.15.94, 74.125.138.84, 64.233.185.138, 64.233.185.102, 64.233.185.113, 64.233.185.139, 64.233.185.100, 64.233.185.101, 34.104.35.123, 20.209.163.232, 40.127.169.103, 72.21.81.240, 192.229.211.108, 20.3.187.198, 52.165.164.15, 64.233.176.94
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      • VT rate limit hit for: https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
      Category:downloaded
      Size (bytes):321
      Entropy (8bit):5.1005859583652295
      Encrypted:false
      SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOhDt3E9DR2p02bjQQE:hax0rKRHkhzRH/Un2i2GprK5YWOhDtEB
      MD5:8B07636521B8ABF0F7A24DF408DD8424
      SHA1:FDBA8D39EC70E6E7DD2B76A9E690D24798BAAED1
      SHA-256:5877E08CB77096000CCB8D4F3258F2A8B594E5DFE5F7CAD9F5F666D854400F5C
      SHA-512:6356D1D1AA444026A36276A9CFD942B3CBDD07F33F201C0E3D13E919B9771B4CD17D5B0C7FC7F793C99635CAC59DB862CA089B13E29B7CEE54020911E47F600E
      Malicious:false
      Reputation:low
      URL:https://apppbc007.z13.web.core.windows.net/favicon.ico
      Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : 14e9a790-401e-0029-299a-9659ff000000</li><li>TimeStamp : 2024-04-24T22:53:37.2515871Z</li></ul></p></body></html>
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with very long lines (321), with no line terminators
      Category:downloaded
      Size (bytes):321
      Entropy (8bit):5.106090693281731
      Encrypted:false
      SSDEEP:6:haxU0H2rKRHX96TdzRHxhgR0zY2i21sasPrK5YWOpVvVMR2p02bUeRS5E:hax0rKRHkhzRH/Un2i2GprK5YWOHVMYx
      MD5:5AB5B7B5F85D823A1327AC05256889E3
      SHA1:1739931F734970AB7BF0E69ADD87917B5D7AF15C
      SHA-256:0775091379EA6F6ABF70FA117F00CD099280AA868C645FDDDAD2B144D1711620
      SHA-512:769D97628C6ED030B8708DBB43567A00CDFCE84C9038AE7D37506A441835E335CED337741C7E66ACC76BB12280470C95DB232BFD1908EAB632F43A76C355CE14
      Malicious:false
      Reputation:low
      URL:https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938
      Preview:<!DOCTYPE html><html><head><title>WebContentNotFound</title></head><body><h1>The requested content does not exist.</h1><p><ul><li>HttpStatusCode: 404</li><li>ErrorCode: WebContentNotFound</li><li>RequestId : 8877a5e7-901e-0015-529a-967038000000</li><li>TimeStamp : 2024-04-24T22:53:37.0561189Z</li></ul></p></body></html>
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 25, 2024 00:53:26.051888943 CEST49678443192.168.2.4104.46.162.224
      Apr 25, 2024 00:53:27.208220005 CEST49675443192.168.2.4173.222.162.32
      Apr 25, 2024 00:53:36.821712017 CEST49675443192.168.2.4173.222.162.32
      Apr 25, 2024 00:53:37.367002964 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.367080927 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.367173910 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.367414951 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.367444038 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.607774973 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.608093023 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.608136892 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.609673977 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.609750986 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.611192942 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.611282110 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.660521030 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:37.660537004 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:37.701282978 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:39.530864954 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.530952930 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:39.531075001 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.532900095 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.532937050 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:39.769988060 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:39.770071983 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.774486065 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.774496078 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:39.774885893 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:39.816485882 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.892597914 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:39.936152935 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.093944073 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.094084978 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.094160080 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.094325066 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.094366074 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.094407082 CEST49740443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.094423056 CEST4434974023.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.180970907 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.181021929 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.181098938 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.181510925 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.181531906 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.411604881 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.411690950 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.412938118 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.412960052 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.413516998 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.416268110 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.460140944 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.627564907 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.627707005 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.627775908 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.653278112 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.653278112 CEST49741443192.168.2.423.216.69.213
      Apr 25, 2024 00:53:40.653323889 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:40.653352976 CEST4434974123.216.69.213192.168.2.4
      Apr 25, 2024 00:53:47.592729092 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:47.592895031 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:47.593055010 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:49.155226946 CEST49739443192.168.2.464.233.176.105
      Apr 25, 2024 00:53:49.155258894 CEST4434973964.233.176.105192.168.2.4
      Apr 25, 2024 00:53:49.554469109 CEST49672443192.168.2.4173.222.162.32
      Apr 25, 2024 00:53:49.554503918 CEST44349672173.222.162.32192.168.2.4
      Apr 25, 2024 00:54:37.309146881 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:37.309174061 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.309257030 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:37.309833050 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:37.309844971 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.540185928 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.554516077 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:37.554533005 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.554897070 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.555692911 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:37.555751085 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:37.598114967 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:45.004796982 CEST4972380192.168.2.423.40.205.26
      Apr 25, 2024 00:54:45.115030050 CEST804972323.40.205.26192.168.2.4
      Apr 25, 2024 00:54:45.115098000 CEST4972380192.168.2.423.40.205.26
      Apr 25, 2024 00:54:47.555913925 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:47.555984974 CEST4434975064.233.176.105192.168.2.4
      Apr 25, 2024 00:54:47.556047916 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:49.099976063 CEST49750443192.168.2.464.233.176.105
      Apr 25, 2024 00:54:49.099997044 CEST4434975064.233.176.105192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 25, 2024 00:53:34.689929008 CEST53536131.1.1.1192.168.2.4
      Apr 25, 2024 00:53:34.691313028 CEST53613241.1.1.1192.168.2.4
      Apr 25, 2024 00:53:35.378699064 CEST53576241.1.1.1192.168.2.4
      Apr 25, 2024 00:53:37.255660057 CEST5445253192.168.2.41.1.1.1
      Apr 25, 2024 00:53:37.255840063 CEST5417853192.168.2.41.1.1.1
      Apr 25, 2024 00:53:37.365905046 CEST53541781.1.1.1192.168.2.4
      Apr 25, 2024 00:53:37.366000891 CEST53544521.1.1.1192.168.2.4
      Apr 25, 2024 00:53:52.446513891 CEST53536191.1.1.1192.168.2.4
      Apr 25, 2024 00:53:56.576047897 CEST138138192.168.2.4192.168.2.255
      Apr 25, 2024 00:54:11.502126932 CEST53502251.1.1.1192.168.2.4
      Apr 25, 2024 00:54:34.160754919 CEST53649151.1.1.1192.168.2.4
      Apr 25, 2024 00:54:34.506577015 CEST53532491.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 25, 2024 00:53:37.255660057 CEST192.168.2.41.1.1.10x5b5dStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.255840063 CEST192.168.2.41.1.1.10x3ec2Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 25, 2024 00:53:37.365905046 CEST1.1.1.1192.168.2.40x3ec2No error (0)www.google.com65IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.105A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.104A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.103A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.99A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.147A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:37.366000891 CEST1.1.1.1192.168.2.40x5b5dNo error (0)www.google.com64.233.176.106A (IP address)IN (0x0001)false
      Apr 25, 2024 00:53:51.129919052 CEST1.1.1.1192.168.2.40x44dfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 00:53:51.129919052 CEST1.1.1.1192.168.2.40x44dfNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 00:54:04.428595066 CEST1.1.1.1192.168.2.40xbff5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 00:54:04.428595066 CEST1.1.1.1192.168.2.40xbff5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 00:54:26.600524902 CEST1.1.1.1192.168.2.40x7bebNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 00:54:26.600524902 CEST1.1.1.1192.168.2.40x7bebNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 00:54:47.021754980 CEST1.1.1.1192.168.2.40xcfbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 00:54:47.021754980 CEST1.1.1.1192.168.2.40xcfbNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44974023.216.69.213443
      TimestampBytes transferredDirectionData
      2024-04-24 22:53:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-24 22:53:40 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0712)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=202263
      Date: Wed, 24 Apr 2024 22:53:40 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974123.216.69.213443
      TimestampBytes transferredDirectionData
      2024-04-24 22:53:40 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-24 22:53:40 UTC531INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0oq75YgAAAAAYL/6cwgY8QpNw2UWojohPQ0hHRURHRTE2MTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=202194
      Date: Wed, 24 Apr 2024 22:53:40 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-24 22:53:40 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:00:53:29
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:00:53:31
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=2016,i,8647603559806436608,12181136153905039309,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:00:53:35
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://apppbc007.z13.web.core.windows.net/Win0security-helpline07/index.html?ph0n=1-888-576-0938"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly