Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html

Overview

General Information

Sample URL:https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html
Analysis ID:1431926
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1396 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2424 --field-trial-handle=2356,i,13033558146578825708,11093226625479854620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6356 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.htmlSlashNext: detection malicious, Label: Scareware type: Phishing & Social Engineering
Source: https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.205.135.29:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.205.135.29:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.135.29
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /Win0belzer0sys07/index.html HTTP/1.1Host: sabbynarula-73p7yyw32q-ue.a.run.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: sabbynarula-73p7yyw32q-ue.a.run.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: sabbynarula-73p7yyw32q-ue.a.run.app
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Length: 272Content-Type: text/html; charset=UTF-8Date: Thu, 25 Apr 2024 23:32:12 GMTAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Length: 272Content-Type: text/html; charset=UTF-8Date: Thu, 25 Apr 2024 23:32:12 GMTAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.205.135.29:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.205.135.29:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2424 --field-trial-handle=2356,i,13033558146578825708,11093226625479854620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2424 --field-trial-handle=2356,i,13033558146578825708,11093226625479854620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html0%Avira URL Cloudsafe
https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html100%SlashNextScareware type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://sabbynarula-73p7yyw32q-ue.a.run.app/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
    162.222.107.39
    truefalse
      unknown
      sabbynarula-73p7yyw32q-ue.a.run.app
      216.239.38.53
      truefalse
        unknown
        www.google.com
        142.250.217.196
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            windowsupdatebg.s.llnwi.net
            208.111.136.128
            truefalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.htmltrue
                unknown
                https://sabbynarula-73p7yyw32q-ue.a.run.app/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.217.196
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                216.239.38.53
                sabbynarula-73p7yyw32q-ue.a.run.appUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1431926
                Start date and time:2024-04-26 01:31:20 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 14s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:9
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@16/4@4/4
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.217.165.195, 142.250.189.142, 173.194.213.84, 34.104.35.123, 40.127.169.103, 23.45.182.100, 23.45.182.79, 23.45.182.84, 23.45.182.76, 23.45.182.78, 23.45.182.69, 23.45.182.112, 23.45.182.102, 23.45.182.74, 192.229.211.108, 208.111.136.128, 13.95.31.18, 72.21.81.240, 13.85.23.206, 142.250.217.227
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):272
                Entropy (8bit):4.933509349028602
                Encrypted:false
                SSDEEP:6:q9xCrQWR0iYBtqRkOACevXmEdxEDLfDDCLCevT4wzRx3G0CezoREQD:cxCrY1t3eevXm4x0ztevT4wzRxGezI
                MD5:9902FB9F7CF3E9A8DD26F45A5CB94113
                SHA1:91995C443AA89CDCF3AB52E2EA1AE3D4893624BC
                SHA-256:6B43B396BA4708E5FFE9DA06909BC2059E55B300F2434BC4181CA3A842D83BD6
                SHA-512:76158AD6A30C9905DD3A1044125114E90D6CBC74EABE38A0C49E07E5F52813615074BD22088578B91A763B5186E924C322E9FCE5281B672E2748CD563C9CFAD8
                Malicious:false
                Reputation:low
                URL:https://sabbynarula-73p7yyw32q-ue.a.run.app/favicon.ico
                Preview:.<html><head>.<meta http-equiv="content-type" content="text/html;charset=utf-8">.<title>404 Page not found</title>.</head>.<body text=#000000 bgcolor=#ffffff>.<h1>Error: Page not found</h1>.<h2>The requested URL was not found on this server.</h2>.<h2></h2>.</body></html>.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):272
                Entropy (8bit):4.933509349028602
                Encrypted:false
                SSDEEP:6:q9xCrQWR0iYBtqRkOACevXmEdxEDLfDDCLCevT4wzRx3G0CezoREQD:cxCrY1t3eevXm4x0ztevT4wzRxGezI
                MD5:9902FB9F7CF3E9A8DD26F45A5CB94113
                SHA1:91995C443AA89CDCF3AB52E2EA1AE3D4893624BC
                SHA-256:6B43B396BA4708E5FFE9DA06909BC2059E55B300F2434BC4181CA3A842D83BD6
                SHA-512:76158AD6A30C9905DD3A1044125114E90D6CBC74EABE38A0C49E07E5F52813615074BD22088578B91A763B5186E924C322E9FCE5281B672E2748CD563C9CFAD8
                Malicious:false
                Reputation:low
                URL:https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html
                Preview:.<html><head>.<meta http-equiv="content-type" content="text/html;charset=utf-8">.<title>404 Page not found</title>.</head>.<body text=#000000 bgcolor=#ffffff>.<h1>Error: Page not found</h1>.<h2>The requested URL was not found on this server.</h2>.<h2></h2>.</body></html>.
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 26, 2024 01:32:02.883532047 CEST49678443192.168.2.4104.46.162.224
                Apr 26, 2024 01:32:04.305391073 CEST49675443192.168.2.4173.222.162.32
                Apr 26, 2024 01:32:11.996189117 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.996253967 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:11.996395111 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.996651888 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.996685028 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:11.996870041 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.997220993 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.997236013 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:11.997476101 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:11.997483969 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.322268963 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.324378967 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.324424028 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.324923992 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.325059891 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.325911045 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.325972080 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.326951981 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.327039957 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.327176094 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.368138075 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.369390011 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.369410992 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.389990091 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.390260935 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.390291929 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.390696049 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.390768051 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.391381025 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.391437054 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.391593933 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.391655922 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.415020943 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.600126982 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.600238085 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.661910057 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.662009001 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.664139032 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.664382935 CEST49736443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.664413929 CEST44349736216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.711479902 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.752126932 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.937273026 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.937527895 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:12.937592030 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.938893080 CEST49735443192.168.2.4216.239.38.53
                Apr 26, 2024 01:32:12.938930988 CEST44349735216.239.38.53192.168.2.4
                Apr 26, 2024 01:32:15.283745050 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.283782959 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.283922911 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.284709930 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.284728050 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.610738993 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.611079931 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.611125946 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.611980915 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.612061977 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.613544941 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.613606930 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.666014910 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.666038990 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:15.667424917 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:15.667458057 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:15.667525053 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:15.670192957 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:15.670209885 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:15.712892056 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:15.928282022 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:15.928371906 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:15.931329012 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:15.931335926 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:15.931546926 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:15.978544950 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.016357899 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.064143896 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.175292969 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.175368071 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.175523996 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.175523996 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.175550938 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.175566912 CEST49740443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.175574064 CEST4434974023.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.218111038 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.218131065 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.218228102 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.218516111 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.218529940 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.473118067 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.473186970 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.475840092 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.475846052 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.476069927 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.501457930 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.548114061 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.727727890 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.727880001 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.727931023 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.731826067 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.731838942 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:16.731848955 CEST49741443192.168.2.423.205.135.29
                Apr 26, 2024 01:32:16.731854916 CEST4434974123.205.135.29192.168.2.4
                Apr 26, 2024 01:32:25.598306894 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:25.598362923 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:32:25.598432064 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:27.206943035 CEST49739443192.168.2.4142.250.217.196
                Apr 26, 2024 01:32:27.206990004 CEST44349739142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.202562094 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:15.202595949 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.202673912 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:15.202955008 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:15.202975988 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.533833027 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.534280062 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:15.534301043 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.535382032 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.535866022 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:15.536040068 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:15.586169004 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:25.516195059 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:25.516356945 CEST44349750142.250.217.196192.168.2.4
                Apr 26, 2024 01:33:25.516427040 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:27.072633982 CEST49750443192.168.2.4142.250.217.196
                Apr 26, 2024 01:33:27.072698116 CEST44349750142.250.217.196192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 26, 2024 01:32:10.958000898 CEST53569991.1.1.1192.168.2.4
                Apr 26, 2024 01:32:10.988672972 CEST53648141.1.1.1192.168.2.4
                Apr 26, 2024 01:32:11.849549055 CEST5879953192.168.2.41.1.1.1
                Apr 26, 2024 01:32:11.849719048 CEST5840553192.168.2.41.1.1.1
                Apr 26, 2024 01:32:11.941768885 CEST53519951.1.1.1192.168.2.4
                Apr 26, 2024 01:32:11.992290974 CEST53587991.1.1.1192.168.2.4
                Apr 26, 2024 01:32:11.995593071 CEST53584051.1.1.1192.168.2.4
                Apr 26, 2024 01:32:15.152910948 CEST5064553192.168.2.41.1.1.1
                Apr 26, 2024 01:32:15.153069019 CEST6303453192.168.2.41.1.1.1
                Apr 26, 2024 01:32:15.281312943 CEST53630341.1.1.1192.168.2.4
                Apr 26, 2024 01:32:15.281363964 CEST53506451.1.1.1192.168.2.4
                Apr 26, 2024 01:32:28.868127108 CEST53587771.1.1.1192.168.2.4
                Apr 26, 2024 01:32:33.435990095 CEST138138192.168.2.4192.168.2.255
                Apr 26, 2024 01:32:48.125157118 CEST53495771.1.1.1192.168.2.4
                Apr 26, 2024 01:33:10.588131905 CEST53537531.1.1.1192.168.2.4
                Apr 26, 2024 01:33:10.605298996 CEST53532791.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 26, 2024 01:32:11.849549055 CEST192.168.2.41.1.1.10xe3ebStandard query (0)sabbynarula-73p7yyw32q-ue.a.run.appA (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:11.849719048 CEST192.168.2.41.1.1.10xc08bStandard query (0)sabbynarula-73p7yyw32q-ue.a.run.app65IN (0x0001)false
                Apr 26, 2024 01:32:15.152910948 CEST192.168.2.41.1.1.10xed53Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:15.153069019 CEST192.168.2.41.1.1.10x7861Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 26, 2024 01:32:11.992290974 CEST1.1.1.1192.168.2.40xe3ebNo error (0)sabbynarula-73p7yyw32q-ue.a.run.app216.239.38.53A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:11.992290974 CEST1.1.1.1192.168.2.40xe3ebNo error (0)sabbynarula-73p7yyw32q-ue.a.run.app216.239.36.53A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:11.992290974 CEST1.1.1.1192.168.2.40xe3ebNo error (0)sabbynarula-73p7yyw32q-ue.a.run.app216.239.32.53A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:11.992290974 CEST1.1.1.1192.168.2.40xe3ebNo error (0)sabbynarula-73p7yyw32q-ue.a.run.app216.239.34.53A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:15.281312943 CEST1.1.1.1192.168.2.40x7861No error (0)www.google.com65IN (0x0001)false
                Apr 26, 2024 01:32:15.281363964 CEST1.1.1.1192.168.2.40xed53No error (0)www.google.com142.250.217.196A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:27.751797915 CEST1.1.1.1192.168.2.40x3cb0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 26, 2024 01:32:27.751797915 CEST1.1.1.1192.168.2.40x3cb0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:28.209321022 CEST1.1.1.1192.168.2.40xc455No error (0)windowsupdatebg.s.llnwi.net208.111.136.128A (IP address)IN (0x0001)false
                Apr 26, 2024 01:32:28.209321022 CEST1.1.1.1192.168.2.40xc455No error (0)windowsupdatebg.s.llnwi.net208.111.136.0A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:03.227710962 CEST1.1.1.1192.168.2.40xe4ffNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:03.227710962 CEST1.1.1.1192.168.2.40xe4ffNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.39A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.24A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.20A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.19A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.38A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.34A (IP address)IN (0x0001)false
                Apr 26, 2024 01:33:23.618810892 CEST1.1.1.1192.168.2.40x7e17No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.21A (IP address)IN (0x0001)false
                • sabbynarula-73p7yyw32q-ue.a.run.app
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449736216.239.38.534431396C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-25 23:32:12 UTC705OUTGET /Win0belzer0sys07/index.html HTTP/1.1
                Host: sabbynarula-73p7yyw32q-ue.a.run.app
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-25 23:32:12 UTC200INHTTP/1.1 404 Not Found
                Content-Length: 272
                Content-Type: text/html; charset=UTF-8
                Date: Thu, 25 Apr 2024 23:32:12 GMT
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-25 23:32:12 UTC272INData Raw: 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 50 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 74 65 78 74 3d 23 30 30 30 30 30 30 20 62 67 63 6f 6c 6f 72 3d 23 66 66 66 66 66 66 3e 0a 3c 68 31 3e 45 72 72 6f 72 3a 20 50 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 68 32 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 68 32 3e 0a 3c 68 32 3e 3c 2f 68 32
                Data Ascii: <html><head><meta http-equiv="content-type" content="text/html;charset=utf-8"><title>404 Page not found</title></head><body text=#000000 bgcolor=#ffffff><h1>Error: Page not found</h1><h2>The requested URL was not found on this server.</h2><h2></h2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449735216.239.38.534431396C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-25 23:32:12 UTC653OUTGET /favicon.ico HTTP/1.1
                Host: sabbynarula-73p7yyw32q-ue.a.run.app
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-25 23:32:12 UTC200INHTTP/1.1 404 Not Found
                Content-Length: 272
                Content-Type: text/html; charset=UTF-8
                Date: Thu, 25 Apr 2024 23:32:12 GMT
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-25 23:32:12 UTC272INData Raw: 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 50 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 74 65 78 74 3d 23 30 30 30 30 30 30 20 62 67 63 6f 6c 6f 72 3d 23 66 66 66 66 66 66 3e 0a 3c 68 31 3e 45 72 72 6f 72 3a 20 50 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 68 32 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 68 32 3e 0a 3c 68 32 3e 3c 2f 68 32
                Data Ascii: <html><head><meta http-equiv="content-type" content="text/html;charset=utf-8"><title>404 Page not found</title></head><body text=#000000 bgcolor=#ffffff><h1>Error: Page not found</h1><h2>The requested URL was not found on this server.</h2><h2></h2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974023.205.135.29443
                TimestampBytes transferredDirectionData
                2024-04-25 23:32:16 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-25 23:32:16 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/079C)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=113442
                Date: Thu, 25 Apr 2024 23:32:16 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974123.205.135.29443
                TimestampBytes transferredDirectionData
                2024-04-25 23:32:16 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-25 23:32:16 UTC805INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/0778)
                X-CID: 11
                X-CCC: US
                X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
                X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
                Content-Type: application/octet-stream
                X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                Cache-Control: public, max-age=113566
                Date: Thu, 25 Apr 2024 23:32:16 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-25 23:32:16 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:01:32:06
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:01:32:09
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2424 --field-trial-handle=2356,i,13033558146578825708,11093226625479854620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:01:32:11
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sabbynarula-73p7yyw32q-ue.a.run.app/Win0belzer0sys07/index.html"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly