Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://earthfare96617.lt.emlnk9.com/Prod/link

Overview

General Information

Sample URL:https://earthfare96617.lt.emlnk9.com/Prod/link
Analysis ID:1431591
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2200 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1704 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,12592488550153597030,5254020665770698214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6512 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://earthfare96617.lt.emlnk9.com/Prod/link" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://earthfare96617.lt.emlnk9.com/Prod/linkHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /Prod/link HTTP/1.1Host: earthfare96617.lt.emlnk9.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: earthfare96617.lt.emlnk9.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://earthfare96617.lt.emlnk9.com/Prod/linkAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: earthfare96617.lt.emlnk9.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Thu, 25 Apr 2024 11:55:15 GMTContent-Type: application/jsonContent-Length: 42Connection: closex-amzn-RequestId: 285b0714-561b-43d4-9994-4c5ae5ea5523x-amzn-ErrorType: MissingAuthenticationTokenExceptionx-amz-apigw-id: Wx-poG1iIAMEBVw=
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Thu, 25 Apr 2024 11:55:16 GMTContent-Type: application/jsonContent-Length: 23Connection: closex-amzn-RequestId: 7b464fa1-9cc6-4346-8ce5-77482eb38d2dx-amzn-ErrorType: ForbiddenExceptionx-amz-apigw-id: Wx-pvGNZoAMEVhw=
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,12592488550153597030,5254020665770698214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://earthfare96617.lt.emlnk9.com/Prod/link"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,12592488550153597030,5254020665770698214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://earthfare96617.lt.emlnk9.com/Prod/link0%Avira URL Cloudsafe
https://earthfare96617.lt.emlnk9.com/Prod/link1%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://earthfare96617.lt.emlnk9.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
earthfare96617.lt.emlnk9.com
52.21.0.115
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      172.217.215.99
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://earthfare96617.lt.emlnk9.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://earthfare96617.lt.emlnk9.com/Prod/linkfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            172.217.215.99
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            52.21.0.115
            earthfare96617.lt.emlnk9.comUnited States
            14618AMAZON-AESUSfalse
            IP
            192.168.2.22
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1431591
            Start date and time:2024-04-25 13:54:20 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 10s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://earthfare96617.lt.emlnk9.com/Prod/link
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/4@4/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.105.94, 108.177.122.100, 108.177.122.138, 108.177.122.139, 108.177.122.113, 108.177.122.102, 108.177.122.101, 64.233.176.84, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.211.108, 20.166.126.56, 52.165.164.15, 64.233.176.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JSON data
            Category:downloaded
            Size (bytes):42
            Entropy (8bit):4.136248672727249
            Encrypted:false
            SSDEEP:3:YIzIX/GZR49aLVAL4n:YIyGvvVln
            MD5:905B1FBB26E082557FF0B3B3553CDA6C
            SHA1:8FE0790D6026998BDB2C9FFA3B915952E613E1B4
            SHA-256:F249B63CB2FCB66B47E86F906C98F8FD912E82DD035B4E53D7E72FC1960CFD16
            SHA-512:284567E83A5C15761498249B27B4B700AA081A65B858F29458E5D0F3DEBDEA93DD5CFAD94EEFAEB43837E70CC288B2A34EA168D2771CB57C993E269C287097CE
            Malicious:false
            Reputation:low
            URL:https://earthfare96617.lt.emlnk9.com/Prod/link
            Preview:{"message":"Missing Authentication Token"}
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JSON data
            Category:downloaded
            Size (bytes):23
            Entropy (8bit):3.7950885863977324
            Encrypted:false
            SSDEEP:3:YIzDb+4:YI3C4
            MD5:BC45704AAD57D445B6DFA58B101071E3
            SHA1:6EA226EA9C42E1CC7E668B33BD7C6C0A5C205B0F
            SHA-256:12A22880BC2E59F8278B4A5E547567F0AA14D020EA456598267FA00208CFEBC5
            SHA-512:F4D5D32034543693A5E28F6BB6B4BC20CBE1739A2683C1B2AFD9312C4B4DDADECEF9BD95644D8F348DD9A689313CC56BE7B2608D564BE2EE921735605646AE70
            Malicious:false
            Reputation:low
            URL:https://earthfare96617.lt.emlnk9.com/favicon.ico
            Preview:{"message":"Forbidden"}
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2024 13:55:03.239185095 CEST49678443192.168.2.4104.46.162.224
            Apr 25, 2024 13:55:03.520517111 CEST49675443192.168.2.4173.222.162.32
            Apr 25, 2024 13:55:13.129776955 CEST49675443192.168.2.4173.222.162.32
            Apr 25, 2024 13:55:15.303738117 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.303787947 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.303898096 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.307847977 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.307934999 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.308024883 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.308549881 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.308569908 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.309197903 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.309252024 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.569896936 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.570576906 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.570607901 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.571124077 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.571197987 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.572124958 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.572202921 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.573518038 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.573609114 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.574094057 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.574101925 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.574747086 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.574976921 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.575011015 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.575536013 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.575611115 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.576555967 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.576597929 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.578453064 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.578536987 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.613866091 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.629941940 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.629973888 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.678258896 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.814450026 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.814574003 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:15.814651966 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.815593004 CEST49737443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:15.815634012 CEST4434973752.21.0.115192.168.2.4
            Apr 25, 2024 13:55:16.389380932 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:16.436119080 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:16.513761044 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:16.513870001 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:16.514024019 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:16.518273115 CEST49736443192.168.2.452.21.0.115
            Apr 25, 2024 13:55:16.518292904 CEST4434973652.21.0.115192.168.2.4
            Apr 25, 2024 13:55:16.801181078 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:16.801244974 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:16.801314116 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:16.801723957 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:16.801743984 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.034145117 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.034451962 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:17.034497023 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.036163092 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.036266088 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:17.037723064 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:17.037825108 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.082278967 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:17.082308054 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:17.129168034 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:18.079898119 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.079935074 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.080076933 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.094150066 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.094172001 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.325483084 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.325582981 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.329380035 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.329407930 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.329816103 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.378638029 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.707349062 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.748121023 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.818089008 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.818190098 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.818265915 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.825951099 CEST49740443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.825984001 CEST4434974023.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.910095930 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.910201073 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:18.910295963 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.911021948 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:18.911072969 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.139000893 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.139091015 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.140669107 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.140685081 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.141047001 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.142357111 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.184145927 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.357110977 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.357209921 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.357299089 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.358119011 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.358169079 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:19.358197927 CEST49742443192.168.2.423.44.104.130
            Apr 25, 2024 13:55:19.358213902 CEST4434974223.44.104.130192.168.2.4
            Apr 25, 2024 13:55:27.040874958 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:27.040978909 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:55:27.041034937 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:28.921703100 CEST49739443192.168.2.4172.217.215.99
            Apr 25, 2024 13:55:28.921753883 CEST44349739172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.738625050 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:16.738725901 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.738822937 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:16.739612103 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:16.739662886 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.963037968 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.963350058 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:16.963391066 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.963761091 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:16.964096069 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:16.964185953 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:17.004420042 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:22.176522970 CEST4972380192.168.2.4199.232.214.172
            Apr 25, 2024 13:56:22.176654100 CEST4972480192.168.2.472.21.81.240
            Apr 25, 2024 13:56:22.286684990 CEST804972472.21.81.240192.168.2.4
            Apr 25, 2024 13:56:22.286797047 CEST4972480192.168.2.472.21.81.240
            Apr 25, 2024 13:56:22.286808968 CEST8049723199.232.214.172192.168.2.4
            Apr 25, 2024 13:56:22.286843061 CEST8049723199.232.214.172192.168.2.4
            Apr 25, 2024 13:56:22.286914110 CEST4972380192.168.2.4199.232.214.172
            Apr 25, 2024 13:56:26.986186028 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:26.986259937 CEST44349751172.217.215.99192.168.2.4
            Apr 25, 2024 13:56:26.986361027 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:28.789984941 CEST49751443192.168.2.4172.217.215.99
            Apr 25, 2024 13:56:28.790075064 CEST44349751172.217.215.99192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2024 13:55:12.376036882 CEST53635451.1.1.1192.168.2.4
            Apr 25, 2024 13:55:12.580918074 CEST53566621.1.1.1192.168.2.4
            Apr 25, 2024 13:55:13.230766058 CEST53559961.1.1.1192.168.2.4
            Apr 25, 2024 13:55:15.186367989 CEST5579853192.168.2.41.1.1.1
            Apr 25, 2024 13:55:15.186904907 CEST4970753192.168.2.41.1.1.1
            Apr 25, 2024 13:55:15.297213078 CEST53557981.1.1.1192.168.2.4
            Apr 25, 2024 13:55:15.302968025 CEST53497071.1.1.1192.168.2.4
            Apr 25, 2024 13:55:16.687673092 CEST5432153192.168.2.41.1.1.1
            Apr 25, 2024 13:55:16.688040018 CEST5650153192.168.2.41.1.1.1
            Apr 25, 2024 13:55:16.799071074 CEST53565011.1.1.1192.168.2.4
            Apr 25, 2024 13:55:16.799199104 CEST53543211.1.1.1192.168.2.4
            Apr 25, 2024 13:55:30.170501947 CEST53591511.1.1.1192.168.2.4
            Apr 25, 2024 13:55:33.773574114 CEST138138192.168.2.4192.168.2.255
            Apr 25, 2024 13:55:49.115751028 CEST53643961.1.1.1192.168.2.4
            Apr 25, 2024 13:56:11.889514923 CEST53543381.1.1.1192.168.2.4
            Apr 25, 2024 13:56:12.435821056 CEST53555691.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 25, 2024 13:55:15.186367989 CEST192.168.2.41.1.1.10xbd88Standard query (0)earthfare96617.lt.emlnk9.comA (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:15.186904907 CEST192.168.2.41.1.1.10x7096Standard query (0)earthfare96617.lt.emlnk9.com65IN (0x0001)false
            Apr 25, 2024 13:55:16.687673092 CEST192.168.2.41.1.1.10xcdc0Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.688040018 CEST192.168.2.41.1.1.10x69c9Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 25, 2024 13:55:15.297213078 CEST1.1.1.1192.168.2.40xbd88No error (0)earthfare96617.lt.emlnk9.com52.21.0.115A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:15.297213078 CEST1.1.1.1192.168.2.40xbd88No error (0)earthfare96617.lt.emlnk9.com52.203.212.110A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:15.297213078 CEST1.1.1.1192.168.2.40xbd88No error (0)earthfare96617.lt.emlnk9.com50.19.192.67A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799071074 CEST1.1.1.1192.168.2.40x69c9No error (0)www.google.com65IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.99A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.103A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.147A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.105A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.106A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:16.799199104 CEST1.1.1.1192.168.2.40xcdc0No error (0)www.google.com172.217.215.104A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:26.176209927 CEST1.1.1.1192.168.2.40xfa28No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:26.176209927 CEST1.1.1.1192.168.2.40xfa28No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:26.639000893 CEST1.1.1.1192.168.2.40x8e4cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2024 13:55:26.639000893 CEST1.1.1.1192.168.2.40x8e4cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 25, 2024 13:55:39.463352919 CEST1.1.1.1192.168.2.40xe1c0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2024 13:55:39.463352919 CEST1.1.1.1192.168.2.40xe1c0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 25, 2024 13:56:04.224067926 CEST1.1.1.1192.168.2.40x9fefNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2024 13:56:04.224067926 CEST1.1.1.1192.168.2.40x9fefNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 25, 2024 13:56:25.224994898 CEST1.1.1.1192.168.2.40x412aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2024 13:56:25.224994898 CEST1.1.1.1192.168.2.40x412aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • earthfare96617.lt.emlnk9.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44973752.21.0.1154431704C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-25 11:55:15 UTC680OUTGET /Prod/link HTTP/1.1
            Host: earthfare96617.lt.emlnk9.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-25 11:55:15 UTC279INHTTP/1.1 403 Forbidden
            Date: Thu, 25 Apr 2024 11:55:15 GMT
            Content-Type: application/json
            Content-Length: 42
            Connection: close
            x-amzn-RequestId: 285b0714-561b-43d4-9994-4c5ae5ea5523
            x-amzn-ErrorType: MissingAuthenticationTokenException
            x-amz-apigw-id: Wx-poG1iIAMEBVw=
            2024-04-25 11:55:15 UTC42INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 4d 69 73 73 69 6e 67 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 54 6f 6b 65 6e 22 7d
            Data Ascii: {"message":"Missing Authentication Token"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973652.21.0.1154431704C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-25 11:55:16 UTC621OUTGET /favicon.ico HTTP/1.1
            Host: earthfare96617.lt.emlnk9.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://earthfare96617.lt.emlnk9.com/Prod/link
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-25 11:55:16 UTC262INHTTP/1.1 403 Forbidden
            Date: Thu, 25 Apr 2024 11:55:16 GMT
            Content-Type: application/json
            Content-Length: 23
            Connection: close
            x-amzn-RequestId: 7b464fa1-9cc6-4346-8ce5-77482eb38d2d
            x-amzn-ErrorType: ForbiddenException
            x-amz-apigw-id: Wx-pvGNZoAMEVhw=
            2024-04-25 11:55:16 UTC23INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 46 6f 72 62 69 64 64 65 6e 22 7d
            Data Ascii: {"message":"Forbidden"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974023.44.104.130443
            TimestampBytes transferredDirectionData
            2024-04-25 11:55:18 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-25 11:55:18 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0712)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=155264
            Date: Thu, 25 Apr 2024 11:55:18 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974223.44.104.130443
            TimestampBytes transferredDirectionData
            2024-04-25 11:55:19 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-25 11:55:19 UTC531INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=155353
            Date: Thu, 25 Apr 2024 11:55:19 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-25 11:55:19 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:13:55:06
            Start date:25/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:13:55:10
            Start date:25/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,12592488550153597030,5254020665770698214,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:13:55:13
            Start date:25/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://earthfare96617.lt.emlnk9.com/Prod/link"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly