Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com

Overview

General Information

Sample URL:http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
Analysis ID:1431939
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4820 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4192 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2024,i,2804570014799152367,11466075511828613232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6376 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2024,i,2804570014799152367,11466075511828613232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2024,i,2804570014799152367,11466075511828613232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com
    3.248.33.252
    truefalse
      high
      www.google.com
      172.217.15.196
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/false
              unknown
              http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/favicon.icofalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              3.248.33.252
              PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comUnited States
              16509AMAZON-02USfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.217.15.196
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1431939
              Start date and time:2024-04-26 02:44:26 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 9s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/5@6/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.64.131, 142.250.189.142, 173.194.217.84, 34.104.35.123, 20.114.59.183, 199.232.210.172, 192.229.211.108, 13.95.31.18, 20.242.39.171, 142.250.189.131
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):58
              Entropy (8bit):4.618768874766759
              Encrypted:false
              SSDEEP:3:qVZqZBKEuAdHfPQLTSCKa:qzIBKEFHfoCJa
              MD5:B9D376F56D086D4279B183BE9D184001
              SHA1:F99F7DE84755A398EA776A8FA6D853A1B14C795C
              SHA-256:F98A5BB089DC48B1F9267D0BA4FCC72C8AFE80E2EB77560B931873BB17AF4729
              SHA-512:20A1B8C5DE6A44A625D0BA2C66CC35EACA0CAF37BB953EC78972399E363BF64A1F19C713BAC03B9AF1EAFBCFAAD50CF77B67DEE41555A959A03E2D539F5B6033
              Malicious:false
              Reputation:low
              URL:http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/
              Preview:<html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with no line terminators
              Category:dropped
              Size (bytes):58
              Entropy (8bit):4.618768874766759
              Encrypted:false
              SSDEEP:3:qVZqZBKEuAdHfPQLTSCKa:qzIBKEFHfoCJa
              MD5:B9D376F56D086D4279B183BE9D184001
              SHA1:F99F7DE84755A398EA776A8FA6D853A1B14C795C
              SHA-256:F98A5BB089DC48B1F9267D0BA4FCC72C8AFE80E2EB77560B931873BB17AF4729
              SHA-512:20A1B8C5DE6A44A625D0BA2C66CC35EACA0CAF37BB953EC78972399E363BF64A1F19C713BAC03B9AF1EAFBCFAAD50CF77B67DEE41555A959A03E2D539F5B6033
              Malicious:false
              Reputation:low
              Preview:<html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):90
              Entropy (8bit):4.6415272628521125
              Encrypted:false
              SSDEEP:3:qVZqZBKEuAdHfPQLTSUhuAdHfPQLTSCKa:qzIBKEFHfoCwFHfoCJa
              MD5:15D455C72A362C8B6C957A522E7D7AB1
              SHA1:9B1BECE5C8D96D43AD378FFE62F48B8FB2E2A980
              SHA-256:0C2E0B0EA63570659D56662D8D7DCFB24C9E7A3E937A7D7060E8502B245B068F
              SHA-512:C6A5AAEC18C1F41AA9D6BE511AB70D698420CAA0D411074E0029B6716AD89B605C37B22A5A9EED3DB1606100ED36B86833C3BA9C080F62C223C3CA3CAFAB6144
              Malicious:false
              Reputation:low
              URL:http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/favicon.ico
              Preview:<html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 26, 2024 02:45:09.115293980 CEST49678443192.168.2.4104.46.162.224
              Apr 26, 2024 02:45:10.256108046 CEST49675443192.168.2.4173.222.162.32
              Apr 26, 2024 02:45:18.258769035 CEST4973580192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.270210981 CEST4973680192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.496305943 CEST80497353.248.33.252192.168.2.4
              Apr 26, 2024 02:45:18.496484995 CEST4973580192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.496643066 CEST4973580192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.513348103 CEST80497363.248.33.252192.168.2.4
              Apr 26, 2024 02:45:18.513442039 CEST4973680192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.733110905 CEST80497353.248.33.252192.168.2.4
              Apr 26, 2024 02:45:18.733262062 CEST80497353.248.33.252192.168.2.4
              Apr 26, 2024 02:45:18.733315945 CEST80497353.248.33.252192.168.2.4
              Apr 26, 2024 02:45:18.733884096 CEST4973580192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.734173059 CEST4973580192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.782993078 CEST4973680192.168.2.43.248.33.252
              Apr 26, 2024 02:45:18.970593929 CEST80497353.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.025254011 CEST80497363.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.025414944 CEST80497363.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.025464058 CEST80497363.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.025540113 CEST4973680192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.032789946 CEST4973680192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.274983883 CEST80497363.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.364506006 CEST4973880192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.582989931 CEST4974080192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.607675076 CEST80497383.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.607806921 CEST4973880192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.607997894 CEST4973880192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.826323986 CEST80497403.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.826436996 CEST4974080192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.849915028 CEST80497383.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.850104094 CEST80497383.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.850152016 CEST80497383.248.33.252192.168.2.4
              Apr 26, 2024 02:45:19.850225925 CEST4973880192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.851888895 CEST4973880192.168.2.43.248.33.252
              Apr 26, 2024 02:45:19.866179943 CEST49675443192.168.2.4173.222.162.32
              Apr 26, 2024 02:45:20.093828917 CEST80497383.248.33.252192.168.2.4
              Apr 26, 2024 02:45:21.449872017 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.449945927 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.450114012 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.450665951 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.450711966 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.781348944 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.782000065 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.782042980 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.783052921 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.783123016 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.785239935 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.785320997 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.832916975 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.832937956 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:21.879774094 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:21.903831959 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:21.903862953 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:21.903934956 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:21.907243013 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:21.907263994 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.200361013 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.200428963 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.204500914 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.204513073 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.204933882 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.254769087 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.313520908 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.360116005 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.464961052 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.465095997 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.465153933 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.465346098 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.465364933 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.465373993 CEST49742443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.465379000 CEST4434974223.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.509179115 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.509223938 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.509351969 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.509649038 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.509665012 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.797344923 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.797446012 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.800081015 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.800090075 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.800957918 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:22.804120064 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:22.848145962 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:23.068425894 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:23.068574905 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:23.068633080 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:23.087569952 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:23.087587118 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:23.087615967 CEST49743443192.168.2.423.63.206.91
              Apr 26, 2024 02:45:23.087624073 CEST4434974323.63.206.91192.168.2.4
              Apr 26, 2024 02:45:30.076472044 CEST80497403.248.33.252192.168.2.4
              Apr 26, 2024 02:45:30.076549053 CEST4974080192.168.2.43.248.33.252
              Apr 26, 2024 02:45:31.606482983 CEST4974080192.168.2.43.248.33.252
              Apr 26, 2024 02:45:31.772336960 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:31.772403002 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:45:31.772465944 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:31.849205971 CEST80497403.248.33.252192.168.2.4
              Apr 26, 2024 02:45:33.199331999 CEST49741443192.168.2.4172.217.15.196
              Apr 26, 2024 02:45:33.199404955 CEST44349741172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.393368006 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:21.393424988 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.393553019 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:21.393901110 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:21.393909931 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.720863104 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.721143961 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:21.721160889 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.721442938 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.721896887 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:21.721950054 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:21.771341085 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:28.067357063 CEST4972380192.168.2.472.21.81.240
              Apr 26, 2024 02:46:28.067476034 CEST4972480192.168.2.472.21.81.240
              Apr 26, 2024 02:46:28.192265034 CEST804972372.21.81.240192.168.2.4
              Apr 26, 2024 02:46:28.192285061 CEST804972472.21.81.240192.168.2.4
              Apr 26, 2024 02:46:28.192337036 CEST4972380192.168.2.472.21.81.240
              Apr 26, 2024 02:46:28.192348003 CEST4972480192.168.2.472.21.81.240
              Apr 26, 2024 02:46:31.713542938 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:31.713604927 CEST44349752172.217.15.196192.168.2.4
              Apr 26, 2024 02:46:31.713659048 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:33.197170973 CEST49752443192.168.2.4172.217.15.196
              Apr 26, 2024 02:46:33.197241068 CEST44349752172.217.15.196192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 26, 2024 02:45:16.872278929 CEST53560571.1.1.1192.168.2.4
              Apr 26, 2024 02:45:16.915237904 CEST53520041.1.1.1192.168.2.4
              Apr 26, 2024 02:45:17.818588972 CEST53559321.1.1.1192.168.2.4
              Apr 26, 2024 02:45:17.994153023 CEST6181653192.168.2.41.1.1.1
              Apr 26, 2024 02:45:17.996365070 CEST6389153192.168.2.41.1.1.1
              Apr 26, 2024 02:45:18.240936041 CEST53638911.1.1.1192.168.2.4
              Apr 26, 2024 02:45:18.254983902 CEST53618161.1.1.1192.168.2.4
              Apr 26, 2024 02:45:19.060084105 CEST5534653192.168.2.41.1.1.1
              Apr 26, 2024 02:45:19.060228109 CEST4955153192.168.2.41.1.1.1
              Apr 26, 2024 02:45:19.306034088 CEST53553461.1.1.1192.168.2.4
              Apr 26, 2024 02:45:19.457134008 CEST53495511.1.1.1192.168.2.4
              Apr 26, 2024 02:45:21.321321011 CEST6457553192.168.2.41.1.1.1
              Apr 26, 2024 02:45:21.321614027 CEST6269153192.168.2.41.1.1.1
              Apr 26, 2024 02:45:21.446311951 CEST53645751.1.1.1192.168.2.4
              Apr 26, 2024 02:45:21.447407007 CEST53626911.1.1.1192.168.2.4
              Apr 26, 2024 02:45:35.101290941 CEST53648911.1.1.1192.168.2.4
              Apr 26, 2024 02:45:39.650199890 CEST138138192.168.2.4192.168.2.255
              Apr 26, 2024 02:45:54.372147083 CEST53579891.1.1.1192.168.2.4
              Apr 26, 2024 02:46:16.759115934 CEST53496381.1.1.1192.168.2.4
              Apr 26, 2024 02:46:16.912633896 CEST53642201.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Apr 26, 2024 02:45:19.457344055 CEST192.168.2.41.1.1.1c2a5(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 26, 2024 02:45:17.994153023 CEST192.168.2.41.1.1.10x5d99Standard query (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comA (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:17.996365070 CEST192.168.2.41.1.1.10x936dStandard query (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com65IN (0x0001)false
              Apr 26, 2024 02:45:19.060084105 CEST192.168.2.41.1.1.10xafc5Standard query (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comA (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:19.060228109 CEST192.168.2.41.1.1.10xaac7Standard query (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com65IN (0x0001)false
              Apr 26, 2024 02:45:21.321321011 CEST192.168.2.41.1.1.10x3ca0Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:21.321614027 CEST192.168.2.41.1.1.10x178eStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 26, 2024 02:45:18.240936041 CEST1.1.1.1192.168.2.40x936dNo error (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comPublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:18.254983902 CEST1.1.1.1192.168.2.40x5d99No error (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comPublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:18.254983902 CEST1.1.1.1192.168.2.40x5d99No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com3.248.33.252A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:18.254983902 CEST1.1.1.1192.168.2.40x5d99No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com54.77.139.23A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:19.306034088 CEST1.1.1.1192.168.2.40xafc5No error (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comPublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:19.306034088 CEST1.1.1.1192.168.2.40xafc5No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com3.248.33.252A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:19.306034088 CEST1.1.1.1192.168.2.40xafc5No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com54.77.139.23A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:19.457134008 CEST1.1.1.1192.168.2.40xaac7No error (0)2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.comPublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:21.446311951 CEST1.1.1.1192.168.2.40x3ca0No error (0)www.google.com172.217.15.196A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:21.447407007 CEST1.1.1.1192.168.2.40x178eNo error (0)www.google.com65IN (0x0001)false
              Apr 26, 2024 02:45:33.697509050 CEST1.1.1.1192.168.2.40x6f08No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:33.697509050 CEST1.1.1.1192.168.2.40x6f08No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:34.169761896 CEST1.1.1.1192.168.2.40x7edcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:34.169761896 CEST1.1.1.1192.168.2.40x7edcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 02:45:47.101643085 CEST1.1.1.1192.168.2.40xb5caNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:45:47.101643085 CEST1.1.1.1192.168.2.40xb5caNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 02:46:09.445105076 CEST1.1.1.1192.168.2.40xbe53No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:46:09.445105076 CEST1.1.1.1192.168.2.40xbe53No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 02:46:29.771727085 CEST1.1.1.1192.168.2.40x623aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 02:46:29.771727085 CEST1.1.1.1192.168.2.40x623aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • fs.microsoft.com
              • 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.4497353.248.33.252804192C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 02:45:18.496643066 CEST462OUTGET / HTTP/1.1
              Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 26, 2024 02:45:18.733262062 CEST206INHTTP/1.1 200 OK
              Server: Burp Collaborator https://burpcollaborator.net/
              X-Collaborator-Version: 4
              Content-Type: text/html
              Content-Length: 58
              Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 39 64 6f 39 77 35 6b 70 33 6f 36 76 65 77 72 35 6f 69 73 70 31 62 7a 6a 35 36 62 63 61 77 76 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
              Data Ascii: <html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.4497363.248.33.252804192C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 02:45:18.782993078 CEST438OUTGET /favicon.ico HTTP/1.1
              Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 26, 2024 02:45:19.025414944 CEST238INHTTP/1.1 200 OK
              Server: Burp Collaborator https://burpcollaborator.net/
              X-Collaborator-Version: 4
              Content-Type: text/html
              Content-Length: 90
              Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 39 64 6f 39 77 35 6b 70 33 6f 36 76 65 77 72 35 6f 69 73 70 31 62 7a 6a 35 36 62 63 61 77 76 7a 39 64 6f 39 77 35 6b 70 33 6f 36 76 65 77 72 35 6f 69 73 70 31 62 7a 6a 35 36 62 63 61 77 76 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
              Data Ascii: <html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.4497383.248.33.252804192C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 02:45:19.607997894 CEST311OUTGET /favicon.ico HTTP/1.1
              Host: 2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 26, 2024 02:45:19.850104094 CEST206INHTTP/1.1 200 OK
              Server: Burp Collaborator https://burpcollaborator.net/
              X-Collaborator-Version: 4
              Content-Type: text/html
              Content-Length: 58
              Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 39 64 6f 39 77 35 6b 70 33 6f 36 76 65 77 72 35 6f 69 73 70 31 62 7a 6a 35 36 62 63 61 77 76 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
              Data Ascii: <html><body>9do9w5kp3o6vewr5oisp1bzj56bcawvz</body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44974223.63.206.91443
              TimestampBytes transferredDirectionData
              2024-04-26 00:45:22 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-26 00:45:22 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0712)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=109102
              Date: Fri, 26 Apr 2024 00:45:22 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44974323.63.206.91443
              TimestampBytes transferredDirectionData
              2024-04-26 00:45:22 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-26 00:45:23 UTC531INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=109106
              Date: Fri, 26 Apr 2024 00:45:22 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-26 00:45:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:02:45:12
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:02:45:15
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2024,i,2804570014799152367,11466075511828613232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:02:45:17
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://2z2jkf1jebbm70amelrhhheqxh3uhd1v5yu.oastify.com"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly