Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://apresolve.spotify.com

Overview

General Information

Sample URL:http://apresolve.spotify.com
Analysis ID:1431949
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5568 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,13565889976884238719,893327145635933713,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://apresolve.spotify.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://apresolve.spotify.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.46.188.128:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.46.188.128:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownTCP traffic detected without corresponding DNS query: 23.46.188.128
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKcontent-type: application/json; charset=utf-8access-control-allow-origin: *cache-control: no-cachecontent-encoding: gzipContent-Length: 90date: Fri, 26 Apr 2024 01:59:11 GMTserver: envoyVia: 1.1 googleData Raw: 1f 8b 08 00 00 00 00 00 00 00 aa 56 4a 2c 88 cf c9 2c 2e 51 b2 8a 06 32 75 d3 4b 53 0d f5 8a 0b f2 4b 32 d3 2a f5 92 f3 73 ad 4c 0c cc 0d 94 74 b0 4b 99 18 e3 90 b1 80 6b 49 36 c6 65 5a 62 aa 11 0e d3 52 cb 4d d0 4d 8b ad 05 00 00 00 ff ff 03 00 ae 60 5d 2a a9 00 00 00 Data Ascii: VJ,,.Q2uKSK2*sLtKkI6eZbRMM`]*
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: apresolve.spotify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: apresolve.spotify.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://apresolve.spotify.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: apresolve.spotify.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Fri, 26 Apr 2024 01:59:12 GMTserver: envoyContent-Length: 0Via: 1.1 google
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownHTTPS traffic detected: 23.46.188.128:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.46.188.128:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,13565889976884238719,893327145635933713,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://apresolve.spotify.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,13565889976884238719,893327145635933713,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture4
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://apresolve.spotify.com0%Avira URL Cloudsafe
http://apresolve.spotify.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    apresolve.spotify.com
    35.186.224.25
    truefalse
      high
      www.google.com
      142.250.217.196
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://apresolve.spotify.com/favicon.icofalse
            high
            http://apresolve.spotify.com/false
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              35.186.224.25
              apresolve.spotify.comUnited States
              15169GOOGLEUSfalse
              142.250.217.196
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1431949
              Start date and time:2024-04-26 03:58:17 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 18s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://apresolve.spotify.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/2@4/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.165.195, 74.125.141.84, 142.250.189.142, 34.104.35.123, 40.68.123.157, 199.232.210.172, 192.229.211.108, 20.166.126.56, 20.3.187.198, 142.250.217.195
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 169
              Category:downloaded
              Size (bytes):90
              Entropy (8bit):5.54948927507263
              Encrypted:false
              SSDEEP:3:FttLd5J2MXYoiWPppykyjA/HMr23niudtRSxd/:XthaMXYoiWRpykyIMiSupC
              MD5:5A417A97AA195C9946500DB476430D94
              SHA1:39E308F871CA56269FBB727E85062ABF1BE8552B
              SHA-256:A939C08A9CA372B4324AC11B90BB6ACAB21AC44468FDEEA5D5442209623BAF71
              SHA-512:95D80E10C19A24F71E174B1ED6674C490D35BF671B27FAE6B633ECB670D27264C09A668FA0ABF7ACDB2DFEA2295363DC75B4F6FB4D983AD11A9CCAD4CB815E40
              Malicious:false
              Reputation:low
              URL:http://apresolve.spotify.com/
              Preview:...........VJ,...,.Q...2u.KS.....K2.*...s.L....t.K....kI6.eZb....R.M.M...........`]*....
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 26, 2024 03:59:02.105643034 CEST49675443192.168.2.4173.222.162.32
              Apr 26, 2024 03:59:11.823049068 CEST49675443192.168.2.4173.222.162.32
              Apr 26, 2024 03:59:12.168473959 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.169353008 CEST4973680192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.309070110 CEST4973780192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.326442003 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.326549053 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.326586962 CEST804973635.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.326647997 CEST4973680192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.326812029 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.466857910 CEST804973735.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.467010021 CEST4973780192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.484345913 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.503989935 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.549377918 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:12.710721016 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.725260019 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 03:59:12.778179884 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:15.314675093 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.314716101 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.315020084 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.315020084 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.315054893 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.702066898 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:15.702152014 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:15.702653885 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:15.705028057 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:15.705075979 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:15.716538906 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.734833002 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.734863997 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.738713980 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.738840103 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.742836952 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.743025064 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.794836998 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:15.794848919 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:15.854126930 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:16.129833937 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.129931927 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.133948088 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.133999109 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.134558916 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.182353020 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.194586039 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.236165047 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.553992033 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.554064989 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.554130077 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.554299116 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.554343939 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.554378033 CEST49742443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.554394007 CEST4434974223.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.601970911 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.602050066 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:16.602174044 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.602632999 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:16.602670908 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.021745920 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.021847010 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.039185047 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.039253950 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.039617062 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.044617891 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.088161945 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.434302092 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.434401035 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.434695005 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.442914009 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.442974091 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:17.443021059 CEST49743443192.168.2.423.46.188.128
              Apr 26, 2024 03:59:17.443038940 CEST4434974323.46.188.128192.168.2.4
              Apr 26, 2024 03:59:25.688040972 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:25.688221931 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:25.688379049 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:27.223335981 CEST49741443192.168.2.4142.250.217.196
              Apr 26, 2024 03:59:27.223407030 CEST44349741142.250.217.196192.168.2.4
              Apr 26, 2024 03:59:57.338764906 CEST4973680192.168.2.435.186.224.25
              Apr 26, 2024 03:59:57.479370117 CEST4973780192.168.2.435.186.224.25
              Apr 26, 2024 03:59:57.497071028 CEST804973635.186.224.25192.168.2.4
              Apr 26, 2024 03:59:57.640475988 CEST804973735.186.224.25192.168.2.4
              Apr 26, 2024 03:59:57.729399920 CEST4973580192.168.2.435.186.224.25
              Apr 26, 2024 03:59:57.887048960 CEST804973535.186.224.25192.168.2.4
              Apr 26, 2024 04:00:13.221904993 CEST4973680192.168.2.435.186.224.25
              Apr 26, 2024 04:00:13.222260952 CEST4973780192.168.2.435.186.224.25
              Apr 26, 2024 04:00:13.379342079 CEST804973635.186.224.25192.168.2.4
              Apr 26, 2024 04:00:13.379415035 CEST4973680192.168.2.435.186.224.25
              Apr 26, 2024 04:00:13.379566908 CEST804973735.186.224.25192.168.2.4
              Apr 26, 2024 04:00:13.379662991 CEST4973780192.168.2.435.186.224.25
              Apr 26, 2024 04:00:15.245522022 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:15.245563030 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.245635986 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:15.246012926 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:15.246026993 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.577749014 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.578054905 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:15.578083038 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.579174995 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.579554081 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:15.579725981 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:15.619025946 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:25.571737051 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:25.571871996 CEST44349752142.250.217.196192.168.2.4
              Apr 26, 2024 04:00:25.571944952 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:27.186254978 CEST49752443192.168.2.4142.250.217.196
              Apr 26, 2024 04:00:27.186332941 CEST44349752142.250.217.196192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 26, 2024 03:59:10.903444052 CEST53532651.1.1.1192.168.2.4
              Apr 26, 2024 03:59:10.972505093 CEST53495481.1.1.1192.168.2.4
              Apr 26, 2024 03:59:11.821893930 CEST53571351.1.1.1192.168.2.4
              Apr 26, 2024 03:59:12.032413960 CEST5164753192.168.2.41.1.1.1
              Apr 26, 2024 03:59:12.032556057 CEST5124353192.168.2.41.1.1.1
              Apr 26, 2024 03:59:12.157939911 CEST53512431.1.1.1192.168.2.4
              Apr 26, 2024 03:59:12.159265041 CEST53516471.1.1.1192.168.2.4
              Apr 26, 2024 03:59:15.186151028 CEST6372353192.168.2.41.1.1.1
              Apr 26, 2024 03:59:15.186151028 CEST5787853192.168.2.41.1.1.1
              Apr 26, 2024 03:59:15.311224937 CEST53637231.1.1.1192.168.2.4
              Apr 26, 2024 03:59:15.313258886 CEST53578781.1.1.1192.168.2.4
              Apr 26, 2024 03:59:29.062768936 CEST53494851.1.1.1192.168.2.4
              Apr 26, 2024 03:59:30.603656054 CEST138138192.168.2.4192.168.2.255
              Apr 26, 2024 03:59:47.875550032 CEST53569851.1.1.1192.168.2.4
              Apr 26, 2024 04:00:10.513576031 CEST53654341.1.1.1192.168.2.4
              Apr 26, 2024 04:00:10.640578985 CEST53495281.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 26, 2024 03:59:12.032413960 CEST192.168.2.41.1.1.10xc098Standard query (0)apresolve.spotify.comA (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:12.032556057 CEST192.168.2.41.1.1.10x8b92Standard query (0)apresolve.spotify.com65IN (0x0001)false
              Apr 26, 2024 03:59:15.186151028 CEST192.168.2.41.1.1.10x7563Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:15.186151028 CEST192.168.2.41.1.1.10x7b85Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 26, 2024 03:59:12.159265041 CEST1.1.1.1192.168.2.40xc098No error (0)apresolve.spotify.com35.186.224.25A (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:15.311224937 CEST1.1.1.1192.168.2.40x7563No error (0)www.google.com142.250.217.196A (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:15.313258886 CEST1.1.1.1192.168.2.40x7b85No error (0)www.google.com65IN (0x0001)false
              Apr 26, 2024 03:59:26.129674911 CEST1.1.1.1192.168.2.40x98beNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:26.129674911 CEST1.1.1.1192.168.2.40x98beNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:26.562515974 CEST1.1.1.1192.168.2.40x2588No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 03:59:26.562515974 CEST1.1.1.1192.168.2.40x2588No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 03:59:39.606791019 CEST1.1.1.1192.168.2.40xdb82No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 03:59:39.606791019 CEST1.1.1.1192.168.2.40xdb82No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 04:00:02.966110945 CEST1.1.1.1192.168.2.40xd5c2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 04:00:02.966110945 CEST1.1.1.1192.168.2.40xd5c2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 26, 2024 04:00:24.043921947 CEST1.1.1.1192.168.2.40xcd91No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 26, 2024 04:00:24.043921947 CEST1.1.1.1192.168.2.40xcd91No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • fs.microsoft.com
              • apresolve.spotify.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973535.186.224.25805740C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 03:59:12.326812029 CEST436OUTGET / HTTP/1.1
              Host: apresolve.spotify.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 26, 2024 03:59:12.503989935 CEST326INHTTP/1.1 200 OK
              content-type: application/json; charset=utf-8
              access-control-allow-origin: *
              cache-control: no-cache
              content-encoding: gzip
              Content-Length: 90
              date: Fri, 26 Apr 2024 01:59:11 GMT
              server: envoy
              Via: 1.1 google
              Data Raw: 1f 8b 08 00 00 00 00 00 00 00 aa 56 4a 2c 88 cf c9 2c 2e 51 b2 8a 06 32 75 d3 4b 53 0d f5 8a 0b f2 4b 32 d3 2a f5 92 f3 73 ad 4c 0c cc 0d 94 74 b0 4b 99 18 e3 90 b1 80 6b 49 36 c6 65 5a 62 aa 11 0e d3 52 cb 4d d0 4d 8b ad 05 00 00 00 ff ff 03 00 ae 60 5d 2a a9 00 00 00
              Data Ascii: VJ,,.Q2uKSK2*sLtKkI6eZbRMM`]*
              Apr 26, 2024 03:59:12.549377918 CEST386OUTGET /favicon.ico HTTP/1.1
              Host: apresolve.spotify.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://apresolve.spotify.com/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 26, 2024 03:59:12.725260019 CEST114INHTTP/1.1 404 Not Found
              date: Fri, 26 Apr 2024 01:59:12 GMT
              server: envoy
              Content-Length: 0
              Via: 1.1 google
              Apr 26, 2024 03:59:57.729399920 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973635.186.224.25805740C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 03:59:57.338764906 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44973735.186.224.25805740C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 26, 2024 03:59:57.479370117 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44974223.46.188.128443
              TimestampBytes transferredDirectionData
              2024-04-26 01:59:16 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-26 01:59:16 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0712)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=104652
              Date: Fri, 26 Apr 2024 01:59:16 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44974323.46.188.128443
              TimestampBytes transferredDirectionData
              2024-04-26 01:59:17 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-26 01:59:17 UTC531INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=104615
              Date: Fri, 26 Apr 2024 01:59:17 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-26 01:59:17 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:03:59:04
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:03:59:08
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,13565889976884238719,893327145635933713,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:03:59:10
              Start date:26/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://apresolve.spotify.com"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly