Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN

Overview

General Information

Sample URL:http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUB
Analysis ID:1431856
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3248 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 7128 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 3392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: classification engineClassification label: clean0.win@20/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1431856 URL: http://ZRsivJd9eJZYI6hYZjp4... Startdate: 25/04/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.6, 443, 49698, 49706 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 64.233.177.106, 443, 49706, 49718 GOOGLEUS United States 10->17 19 google.com 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalseunknown
google.com
64.233.185.139
truefalse
    high
    www.google.com
    64.233.177.106
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalseunknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      64.233.177.106
      www.google.comUnited States
      15169GOOGLEUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      IP
      192.168.2.6
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1431856
      Start date and time:2024-04-25 21:48:29 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 1s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:6
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@20/0@4/3
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 74.125.138.94, 142.250.105.84, 108.177.122.102, 108.177.122.113, 108.177.122.101, 108.177.122.100, 108.177.122.139, 108.177.122.138, 34.104.35.123, 40.68.123.157, 199.232.214.172, 192.229.211.108, 13.95.31.18, 20.166.126.56
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 25, 2024 21:49:13.491241932 CEST49673443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:13.491281986 CEST49674443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:13.802536964 CEST49672443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:23.099853992 CEST49673443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:23.099869013 CEST49674443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:23.412362099 CEST49672443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:24.683851004 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.683938026 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.684027910 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.684303045 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.684340000 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.814637899 CEST44349698173.222.162.64192.168.2.6
      Apr 25, 2024 21:49:24.814755917 CEST49698443192.168.2.6173.222.162.64
      Apr 25, 2024 21:49:24.919502974 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.920284033 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.920344114 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.921228886 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.921304941 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.923937082 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.924046993 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:24.975090981 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:24.975148916 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:25.021981001 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:25.234431982 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.234487057 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.234575987 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.238272905 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.238295078 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.471569061 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.471661091 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.475778103 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.475790024 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.476140022 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.522047043 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.561835051 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.604130030 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.682697058 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.682780981 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.682856083 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.682980061 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.683000088 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.683016062 CEST49707443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.683021069 CEST44349707184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.777578115 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.777622938 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:25.777741909 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.778126001 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:25.778139114 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.002697945 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.002846003 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:26.004554033 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:26.004571915 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.004825115 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.006557941 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:26.052123070 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.220995903 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.221075058 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:26.221144915 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:26.223350048 CEST49708443192.168.2.6184.31.62.93
      Apr 25, 2024 21:49:26.223371983 CEST44349708184.31.62.93192.168.2.6
      Apr 25, 2024 21:49:34.914057970 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:34.914145947 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:49:34.914206982 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:36.698940039 CEST49706443192.168.2.664.233.177.106
      Apr 25, 2024 21:49:36.698990107 CEST4434970664.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.592027903 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:24.592065096 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.592119932 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:24.592442036 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:24.592457056 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.818125963 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.818584919 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:24.818599939 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.819060087 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.819591999 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:24.819674969 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:24.864926100 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:34.862838984 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:34.862906933 CEST4434971864.233.177.106192.168.2.6
      Apr 25, 2024 21:50:34.863481998 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:36.741369009 CEST49718443192.168.2.664.233.177.106
      Apr 25, 2024 21:50:36.741426945 CEST4434971864.233.177.106192.168.2.6
      TimestampSource PortDest PortSource IPDest IP
      Apr 25, 2024 21:49:20.298199892 CEST53521181.1.1.1192.168.2.6
      Apr 25, 2024 21:49:20.333039045 CEST53601021.1.1.1192.168.2.6
      Apr 25, 2024 21:49:20.981426954 CEST53530411.1.1.1192.168.2.6
      Apr 25, 2024 21:49:21.723212957 CEST5310053192.168.2.68.8.8.8
      Apr 25, 2024 21:49:21.723504066 CEST6082853192.168.2.61.1.1.1
      Apr 25, 2024 21:49:21.836144924 CEST53608281.1.1.1192.168.2.6
      Apr 25, 2024 21:49:21.836297989 CEST53531008.8.8.8192.168.2.6
      Apr 25, 2024 21:49:24.541344881 CEST5552453192.168.2.61.1.1.1
      Apr 25, 2024 21:49:24.542443991 CEST6059953192.168.2.61.1.1.1
      Apr 25, 2024 21:49:24.652287006 CEST53555241.1.1.1192.168.2.6
      Apr 25, 2024 21:49:24.652812958 CEST53605991.1.1.1192.168.2.6
      Apr 25, 2024 21:49:37.946672916 CEST53563641.1.1.1192.168.2.6
      Apr 25, 2024 21:49:57.171998024 CEST53583371.1.1.1192.168.2.6
      Apr 25, 2024 21:50:19.533509016 CEST53585571.1.1.1192.168.2.6
      Apr 25, 2024 21:50:20.095170975 CEST53631521.1.1.1192.168.2.6
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 25, 2024 21:49:21.723212957 CEST192.168.2.68.8.8.80xb5aeStandard query (0)google.comA (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.723504066 CEST192.168.2.61.1.1.10xbb4bStandard query (0)google.comA (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.541344881 CEST192.168.2.61.1.1.10xf186Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.542443991 CEST192.168.2.61.1.1.10x4da5Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.139A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.138A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.100A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.102A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.101A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836144924 CEST1.1.1.1192.168.2.60xbb4bNo error (0)google.com64.233.185.113A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.101A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.139A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.138A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.100A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.113A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:21.836297989 CEST8.8.8.8192.168.2.60xb5aeNo error (0)google.com173.194.77.102A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652287006 CEST1.1.1.1192.168.2.60xf186No error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:24.652812958 CEST1.1.1.1192.168.2.60x4da5No error (0)www.google.com65IN (0x0001)false
      Apr 25, 2024 21:49:34.295605898 CEST1.1.1.1192.168.2.60x67e9No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:34.295605898 CEST1.1.1.1192.168.2.60x67e9No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:34.654391050 CEST1.1.1.1192.168.2.60xdb4cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 21:49:34.654391050 CEST1.1.1.1192.168.2.60xdb4cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 21:49:49.472493887 CEST1.1.1.1192.168.2.60xe970No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 21:49:49.472493887 CEST1.1.1.1192.168.2.60xe970No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 21:50:12.244158983 CEST1.1.1.1192.168.2.60x6ae8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 21:50:12.244158983 CEST1.1.1.1192.168.2.60x6ae8No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 25, 2024 21:50:32.867038012 CEST1.1.1.1192.168.2.60x5f41No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 25, 2024 21:50:32.867038012 CEST1.1.1.1192.168.2.60x5f41No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.649707184.31.62.93443
      TimestampBytes transferredDirectionData
      2024-04-25 19:49:25 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-25 19:49:25 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0790)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=126850
      Date: Thu, 25 Apr 2024 19:49:25 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.649708184.31.62.93443
      TimestampBytes transferredDirectionData
      2024-04-25 19:49:26 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-25 19:49:26 UTC515INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0758)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=126849
      Date: Thu, 25 Apr 2024 19:49:26 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-25 19:49:26 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:21:49:14
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff684c40000
      File size:3'242'272 bytes
      MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:21:49:18
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff684c40000
      File size:3'242'272 bytes
      MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:21:49:21
      Start date:25/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#"
      Imagebase:0x7ff684c40000
      File size:3'242'272 bytes
      MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly