Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://au1-s2s.sensic.net

Overview

General Information

Sample URL:http://au1-s2s.sensic.net
Analysis ID:1432012
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1856 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1860 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2136,i,2085057673793376809,13504174864024297580,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://au1-s2s.sensic.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: au1-s2s.sensic.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: au1-s2s.sensic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://au1-s2s.sensic.net/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: au1-s2s.sensic.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: CloudFrontContent-Type: text/html;charset=iso-8859-1Content-Length: 243Connection: keep-aliveDate: Fri, 26 Apr 2024 07:26:45 GMTCache-Control: must-revalidate,no-cache,no-storeX-Cache: Error from cloudfrontVia: 1.1 239ebd908a5cd20ee7b9bd546b4bf248.cloudfront.net (CloudFront)X-Amz-Cf-Pop: MIA3-P7Alt-Svc: h3=":443"; ma=86400X-Amz-Cf-Id: 81uZlj-v7g1sQc1JFoJSNFugHZZ5RbjlONPH1lw4YrbvPvcp9bCXlg==X-Content-Type-Options: nosniffVary: OriginData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 2f 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 3c 68 32 3e 48 54 54 50 20 45 52 52 4f 52 20 34 30 34 3c 2f 68 32 3e 0a 3c 70 3e 50 72 6f 62 6c 65 6d 20 61 63 63 65 73 73 69 6e 67 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 2e 20 52 65 61 73 6f 6e 3a 0a 3c 70 72 65 3e 20 20 20 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 70 72 65 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8"/><title>Error 404 Not Found</title></head><body><h2>HTTP ERROR 404</h2><p>Problem accessing /favicon.ico. Reason:<pre> Not Found</pre></p></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2136,i,2085057673793376809,13504174864024297580,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://au1-s2s.sensic.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2136,i,2085057673793376809,13504174864024297580,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://au1-s2s.sensic.net0%VirustotalBrowse
http://au1-s2s.sensic.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
au1-s2s.sensic.net0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://au1-s2s.sensic.net/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
www.google.com
192.178.50.36
truefalse
    high
    au1-s2s.sensic.net
    18.173.166.54
    truefalseunknown
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    http://au1-s2s.sensic.net/favicon.icofalse
    • Avira URL Cloud: safe
    unknown
    http://au1-s2s.sensic.net/false
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      192.178.50.36
      www.google.comUnited States
      15169GOOGLEUSfalse
      18.173.166.54
      au1-s2s.sensic.netUnited States
      3MIT-GATEWAYSUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      IP
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1432012
      Start date and time:2024-04-26 09:25:55 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 4s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://au1-s2s.sensic.net
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@16/2@4/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.64.227, 142.251.107.84, 192.178.50.78, 34.104.35.123, 20.114.59.183, 199.232.210.172, 192.229.211.108, 20.166.126.56, 20.3.187.198, 142.250.217.195
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:ASCII text
      Category:downloaded
      Size (bytes):12
      Entropy (8bit):3.0220552088742005
      Encrypted:false
      SSDEEP:3:agPv:agPv
      MD5:F0EF7081E1539AC00EF5B761B4FB01B3
      SHA1:33AB5639BFD8E7B95EB1D8D0B87781D4FFEA4D5D
      SHA-256:1894A19C85BA153ACBF743AC4E43FC004C891604B26F8C69E1E83EA2AFC7C48F
      SHA-512:81381F1DACD4824A6C503FD07057763099C12B8309D0ABCEC4000C9060CBBFA67988B2ADA669AB4837FCD3D4EA6E2B8DB2B9DA9197D5112FB369FD006DA545DE
      Malicious:false
      Reputation:low
      URL:http://au1-s2s.sensic.net/
      Preview:Hello world.
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 26, 2024 09:26:36.832654953 CEST49675443192.168.2.4173.222.162.32
      Apr 26, 2024 09:26:37.770215034 CEST49678443192.168.2.4104.46.162.224
      Apr 26, 2024 09:26:44.325356960 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.325679064 CEST4973680192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.449286938 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:26:44.449373007 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.449590921 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.451230049 CEST804973618.173.166.54192.168.2.4
      Apr 26, 2024 09:26:44.451297998 CEST4973680192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.573704958 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:26:44.807917118 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:26:44.855184078 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:44.878375053 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:45.015917063 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:26:45.244920015 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:26:45.284560919 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:26:46.440814018 CEST49675443192.168.2.4173.222.162.32
      Apr 26, 2024 09:26:46.930658102 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:46.930697918 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:46.931070089 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:46.938540936 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:46.938559055 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.330588102 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.331043959 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:47.331063986 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.332724094 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.333064079 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:47.336036921 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:47.336136103 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.337069035 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.337150097 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.337429047 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.339735985 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.339785099 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.378576994 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:47.378586054 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:47.428018093 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:47.598026037 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.598213911 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.601789951 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.601799011 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.602054119 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.644417048 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.659188032 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.700124979 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.855211973 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.855267048 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.855314016 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.855428934 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.855448008 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.855460882 CEST49740443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.855468035 CEST4434974023.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.883003950 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.883042097 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:47.883102894 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.883343935 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:47.883353949 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.140077114 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.140141010 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.143134117 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.143151045 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.143419981 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.146857977 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.188116074 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.414772987 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.414926052 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.414977074 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.419627905 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.419645071 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:48.419653893 CEST49741443192.168.2.423.193.120.112
      Apr 26, 2024 09:26:48.419658899 CEST4434974123.193.120.112192.168.2.4
      Apr 26, 2024 09:26:57.353585958 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:57.353703022 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:26:57.353807926 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:58.933141947 CEST49739443192.168.2.4192.178.50.36
      Apr 26, 2024 09:26:58.933203936 CEST44349739192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:14.575730085 CEST804973618.173.166.54192.168.2.4
      Apr 26, 2024 09:27:14.575814962 CEST4973680192.168.2.418.173.166.54
      Apr 26, 2024 09:27:14.787537098 CEST4973680192.168.2.418.173.166.54
      Apr 26, 2024 09:27:14.912013054 CEST804973618.173.166.54192.168.2.4
      Apr 26, 2024 09:27:30.253891945 CEST4973580192.168.2.418.173.166.54
      Apr 26, 2024 09:27:30.378051043 CEST804973518.173.166.54192.168.2.4
      Apr 26, 2024 09:27:46.848675013 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:46.848715067 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:46.848771095 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:46.849247932 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:46.849260092 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:47.177234888 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:47.217116117 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:47.217133045 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:47.217648029 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:47.218884945 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:47.218952894 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:47.269309044 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:57.196307898 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:57.196475029 CEST44349750192.178.50.36192.168.2.4
      Apr 26, 2024 09:27:57.196564913 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:58.787760019 CEST49750443192.168.2.4192.178.50.36
      Apr 26, 2024 09:27:58.787797928 CEST44349750192.178.50.36192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 26, 2024 09:26:42.379724979 CEST53634901.1.1.1192.168.2.4
      Apr 26, 2024 09:26:42.383147955 CEST53542451.1.1.1192.168.2.4
      Apr 26, 2024 09:26:43.257781029 CEST53516321.1.1.1192.168.2.4
      Apr 26, 2024 09:26:44.195472956 CEST5481653192.168.2.41.1.1.1
      Apr 26, 2024 09:26:44.195600033 CEST6061553192.168.2.41.1.1.1
      Apr 26, 2024 09:26:44.324662924 CEST53606151.1.1.1192.168.2.4
      Apr 26, 2024 09:26:44.324837923 CEST53548161.1.1.1192.168.2.4
      Apr 26, 2024 09:26:46.788171053 CEST4919353192.168.2.41.1.1.1
      Apr 26, 2024 09:26:46.789202929 CEST6188953192.168.2.41.1.1.1
      Apr 26, 2024 09:26:46.912940025 CEST53491931.1.1.1192.168.2.4
      Apr 26, 2024 09:26:46.914283991 CEST53618891.1.1.1192.168.2.4
      Apr 26, 2024 09:27:01.067183018 CEST53504561.1.1.1192.168.2.4
      Apr 26, 2024 09:27:08.292395115 CEST138138192.168.2.4192.168.2.255
      Apr 26, 2024 09:27:20.448756933 CEST53569781.1.1.1192.168.2.4
      Apr 26, 2024 09:27:42.241794109 CEST53642851.1.1.1192.168.2.4
      Apr 26, 2024 09:27:43.398976088 CEST53567991.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 26, 2024 09:26:44.195472956 CEST192.168.2.41.1.1.10x886Standard query (0)au1-s2s.sensic.netA (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:44.195600033 CEST192.168.2.41.1.1.10x6943Standard query (0)au1-s2s.sensic.net65IN (0x0001)false
      Apr 26, 2024 09:26:46.788171053 CEST192.168.2.41.1.1.10x3dcaStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:46.789202929 CEST192.168.2.41.1.1.10xe685Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 26, 2024 09:26:44.324837923 CEST1.1.1.1192.168.2.40x886No error (0)au1-s2s.sensic.net18.173.166.54A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:44.324837923 CEST1.1.1.1192.168.2.40x886No error (0)au1-s2s.sensic.net18.173.166.44A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:44.324837923 CEST1.1.1.1192.168.2.40x886No error (0)au1-s2s.sensic.net18.173.166.11A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:44.324837923 CEST1.1.1.1192.168.2.40x886No error (0)au1-s2s.sensic.net18.173.166.118A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:46.912940025 CEST1.1.1.1192.168.2.40x3dcaNo error (0)www.google.com192.178.50.36A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:46.914283991 CEST1.1.1.1192.168.2.40xe685No error (0)www.google.com65IN (0x0001)false
      Apr 26, 2024 09:26:59.821583986 CEST1.1.1.1192.168.2.40xe956No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Apr 26, 2024 09:26:59.821583986 CEST1.1.1.1192.168.2.40xe956No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Apr 26, 2024 09:27:00.232696056 CEST1.1.1.1192.168.2.40x6188No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 09:27:00.232696056 CEST1.1.1.1192.168.2.40x6188No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 09:27:13.082262993 CEST1.1.1.1192.168.2.40x542No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 09:27:13.082262993 CEST1.1.1.1192.168.2.40x542No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 09:27:35.541801929 CEST1.1.1.1192.168.2.40x368dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 09:27:35.541801929 CEST1.1.1.1192.168.2.40x368dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 09:27:55.129488945 CEST1.1.1.1192.168.2.40xf7faNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 09:27:55.129488945 CEST1.1.1.1192.168.2.40xf7faNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • au1-s2s.sensic.net
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44973518.173.166.54801860C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Apr 26, 2024 09:26:44.449590921 CEST433OUTGET / HTTP/1.1
      Host: au1-s2s.sensic.net
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Apr 26, 2024 09:26:44.807917118 CEST467INHTTP/1.1 200 OK
      Server: CloudFront
      Content-Type: text/html;charset=iso-8859-1
      Content-Length: 12
      Connection: keep-alive
      Date: Fri, 26 Apr 2024 07:26:44 GMT
      Access-Control-Allow-Origin: *
      X-Cache: Miss from cloudfront
      Via: 1.1 239ebd908a5cd20ee7b9bd546b4bf248.cloudfront.net (CloudFront)
      X-Amz-Cf-Pop: MIA3-P7
      Alt-Svc: h3=":443"; ma=86400
      X-Amz-Cf-Id: dMOR8xI-WLbcwBwpKYL7q483Co-XjdvE6NzMxwzGeG-Bk9B43O89Xw==
      X-Content-Type-Options: nosniff
      Data Raw: 48 65 6c 6c 6f 20 77 6f 72 6c 64 0a
      Data Ascii: Hello world
      Apr 26, 2024 09:26:44.878375053 CEST380OUTGET /favicon.ico HTTP/1.1
      Host: au1-s2s.sensic.net
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Referer: http://au1-s2s.sensic.net/
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Apr 26, 2024 09:26:45.244920015 CEST739INHTTP/1.1 404 Not Found
      Server: CloudFront
      Content-Type: text/html;charset=iso-8859-1
      Content-Length: 243
      Connection: keep-alive
      Date: Fri, 26 Apr 2024 07:26:45 GMT
      Cache-Control: must-revalidate,no-cache,no-store
      X-Cache: Error from cloudfront
      Via: 1.1 239ebd908a5cd20ee7b9bd546b4bf248.cloudfront.net (CloudFront)
      X-Amz-Cf-Pop: MIA3-P7
      Alt-Svc: h3=":443"; ma=86400
      X-Amz-Cf-Id: 81uZlj-v7g1sQc1JFoJSNFugHZZ5RbjlONPH1lw4YrbvPvcp9bCXlg==
      X-Content-Type-Options: nosniff
      Vary: Origin
      Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 2f 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 3c 68 32 3e 48 54 54 50 20 45 52 52 4f 52 20 34 30 34 3c 2f 68 32 3e 0a 3c 70 3e 50 72 6f 62 6c 65 6d 20 61 63 63 65 73 73 69 6e 67 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 2e 20 52 65 61 73 6f 6e 3a 0a 3c 70 72 65 3e 20 20 20 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 70 72 65 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a
      Data Ascii: <html><head><meta http-equiv="Content-Type" content="text/html;charset=utf-8"/><title>Error 404 Not Found</title></head><body><h2>HTTP ERROR 404</h2><p>Problem accessing /favicon.ico. Reason:<pre> Not Found</pre></p></body></html>
      Apr 26, 2024 09:27:30.253891945 CEST6OUTData Raw: 00
      Data Ascii:


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44974023.193.120.112443
      TimestampBytes transferredDirectionData
      2024-04-26 07:26:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-26 07:26:47 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0712)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=85065
      Date: Fri, 26 Apr 2024 07:26:47 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974123.193.120.112443
      TimestampBytes transferredDirectionData
      2024-04-26 07:26:48 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-26 07:26:48 UTC530INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=85077
      Date: Fri, 26 Apr 2024 07:26:48 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-26 07:26:48 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:09:26:39
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:09:26:41
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2136,i,2085057673793376809,13504174864024297580,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:09:26:43
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://au1-s2s.sensic.net"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly