Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://f-log-extension.grammarly.io

Overview

General Information

Sample URL:http://f-log-extension.grammarly.io
Analysis ID:1432127
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3192 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,13024243500430534651,5569693173010471511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6316 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://f-log-extension.grammarly.io" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://f-log-extension.grammarly.io/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: f-log-extension.grammarly.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: f-log-extension.grammarly.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: f-log-extension.grammarly.io
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 26 Apr 2024 12:58:17 GMTContent-Type: text/plain; charset=utf-8Content-Length: 19Connection: closeAccess-Control-Allow-Headers: Keep-Alive,User-Agent,X-Requested-With,Cache-Control,Content-TypeAccess-Control-Allow-Methods: GET, POST, OPTIONSAccess-Control-Allow-Origin: *Content-Security-Policy: default-src 'none'Referrer-Policy: no-referrerStrict-Transport-Security: max-age=31536000; includeSubDomainsX-Content-Type-Options: nosniffX-Frame-Options: DENYX-Xss-Protection: 1;mode=block
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/2@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,13024243500430534651,5569693173010471511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://f-log-extension.grammarly.io"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,13024243500430534651,5569693173010471511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://f-log-extension.grammarly.io0%Avira URL Cloudsafe
http://f-log-extension.grammarly.io0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://f-log-extension.grammarly.io/0%Avira URL Cloudsafe
http://f-log-extension.grammarly.io/0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
f-log-extension.grammarly.io
3.214.105.83
truefalse
    unknown
    www.google.com
    142.250.217.164
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://f-log-extension.grammarly.io/false
        • 0%, Virustotal, Browse
        • Avira URL Cloud: safe
        unknown
        https://f-log-extension.grammarly.io/false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          44.206.202.177
          unknownUnited States
          14618AMAZON-AESUSfalse
          142.250.217.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          3.214.105.83
          f-log-extension.grammarly.ioUnited States
          14618AMAZON-AESUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1432127
          Start date and time:2024-04-26 14:57:15 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 15s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://f-log-extension.grammarly.io
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:9
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@17/2@6/5
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.35.238, 108.177.11.84, 142.250.217.163, 34.104.35.123, 13.85.23.86, 23.45.182.77, 23.45.182.85, 23.45.182.97, 23.45.182.93, 23.45.182.104, 20.3.187.198, 192.229.211.108, 20.242.39.171, 52.165.165.26, 192.178.50.67, 40.68.123.157
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text
          Category:downloaded
          Size (bytes):19
          Entropy (8bit):3.6818808028034042
          Encrypted:false
          SSDEEP:3:uZuUeZn:u5eZn
          MD5:595E88012A6521AAE3E12CBEBE76EB9E
          SHA1:DA3968197E7BF67AA45A77515B52BA2710C5FC34
          SHA-256:B16E15764B8BC06C5C3F9F19BC8B99FA48E7894AA5A6CCDAD65DA49BBF564793
          SHA-512:FD13C580D15CC5E8B87D97EAD633209930E00E85C113C776088E246B47F140EFE99BDF6AB02070677445DB65410F7E62EC23C71182F9F78E9D0E1B9F7FDA0DC3
          Malicious:false
          Reputation:low
          URL:https://f-log-extension.grammarly.io/
          Preview:404 page not found.
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 26, 2024 14:58:04.561532021 CEST49675443192.168.2.4173.222.162.32
          Apr 26, 2024 14:58:14.301667929 CEST49675443192.168.2.4173.222.162.32
          Apr 26, 2024 14:58:16.699331045 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:58:16.699754000 CEST4973780192.168.2.43.214.105.83
          Apr 26, 2024 14:58:16.851238966 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:58:16.851358891 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:58:16.851577997 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:58:16.851965904 CEST80497373.214.105.83192.168.2.4
          Apr 26, 2024 14:58:16.852041960 CEST4973780192.168.2.43.214.105.83
          Apr 26, 2024 14:58:17.003555059 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:58:17.003585100 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:58:17.137835979 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:58:17.142529964 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.142587900 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.142679930 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.142995119 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.143028021 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.620668888 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.621121883 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.621181011 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.622334957 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.622433901 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.622454882 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.622510910 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.651312113 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.651493073 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.651638985 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.696127892 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.803601027 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:17.803687096 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.805744886 CEST49739443192.168.2.444.206.202.177
          Apr 26, 2024 14:58:17.805773973 CEST4434973944.206.202.177192.168.2.4
          Apr 26, 2024 14:58:18.027071953 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.027132034 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.027206898 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.028374910 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.028410912 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.359602928 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.359869957 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.359918118 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.361022949 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.361079931 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.526160955 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.526361942 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.639359951 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:18.639398098 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:18.842483044 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:21.463673115 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.463709116 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:21.463851929 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.465728998 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.465744019 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:21.735729933 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:21.735791922 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.739797115 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.739805937 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:21.740207911 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:21.785687923 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:21.832133055 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:22.000978947 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:22.001128912 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:22.001240015 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:22.214584112 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:22.214639902 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:22.214662075 CEST49741443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:22.214683056 CEST4434974123.193.120.112192.168.2.4
          Apr 26, 2024 14:58:23.848747015 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:23.848783016 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:23.848861933 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:23.849793911 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:23.849811077 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.110006094 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.110102892 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:24.112823009 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:24.112852097 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.113234043 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.115776062 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:24.160115957 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.389971972 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.390131950 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:24.390208960 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:24.391484022 CEST49742443192.168.2.423.193.120.112
          Apr 26, 2024 14:58:24.391521931 CEST4434974223.193.120.112192.168.2.4
          Apr 26, 2024 14:58:28.359118938 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:28.359178066 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:28.359314919 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:28.422101974 CEST49740443192.168.2.4142.250.217.164
          Apr 26, 2024 14:58:28.422121048 CEST44349740142.250.217.164192.168.2.4
          Apr 26, 2024 14:58:28.695352077 CEST4972380192.168.2.472.21.81.240
          Apr 26, 2024 14:58:28.819972992 CEST804972372.21.81.240192.168.2.4
          Apr 26, 2024 14:58:28.820038080 CEST4972380192.168.2.472.21.81.240
          Apr 26, 2024 14:59:01.858057976 CEST4973780192.168.2.43.214.105.83
          Apr 26, 2024 14:59:02.010098934 CEST80497373.214.105.83192.168.2.4
          Apr 26, 2024 14:59:02.015696049 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:59:02.167454004 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:59:17.012372971 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:59:17.012485981 CEST80497373.214.105.83192.168.2.4
          Apr 26, 2024 14:59:17.012486935 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:59:17.012540102 CEST4973780192.168.2.43.214.105.83
          Apr 26, 2024 14:59:17.524914026 CEST4973780192.168.2.43.214.105.83
          Apr 26, 2024 14:59:17.524955988 CEST4973680192.168.2.43.214.105.83
          Apr 26, 2024 14:59:17.676728010 CEST80497363.214.105.83192.168.2.4
          Apr 26, 2024 14:59:17.676872969 CEST80497373.214.105.83192.168.2.4
          Apr 26, 2024 14:59:17.789637089 CEST4972480192.168.2.472.21.81.240
          Apr 26, 2024 14:59:17.884644985 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:17.884679079 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:17.884917974 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:17.885349035 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:17.885360956 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:17.914089918 CEST804972472.21.81.240192.168.2.4
          Apr 26, 2024 14:59:17.914150953 CEST4972480192.168.2.472.21.81.240
          Apr 26, 2024 14:59:18.211333036 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:18.214107037 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:18.214126110 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:18.214487076 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:18.219577074 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:18.219655991 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:18.266881943 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:28.198429108 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:28.198503971 CEST44349751142.250.217.164192.168.2.4
          Apr 26, 2024 14:59:28.198992014 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:28.865592003 CEST49751443192.168.2.4142.250.217.164
          Apr 26, 2024 14:59:28.865627050 CEST44349751142.250.217.164192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Apr 26, 2024 14:58:14.134177923 CEST53502671.1.1.1192.168.2.4
          Apr 26, 2024 14:58:14.160119057 CEST53555721.1.1.1192.168.2.4
          Apr 26, 2024 14:58:16.568145037 CEST5279753192.168.2.41.1.1.1
          Apr 26, 2024 14:58:16.568272114 CEST5334553192.168.2.41.1.1.1
          Apr 26, 2024 14:58:16.698602915 CEST53527971.1.1.1192.168.2.4
          Apr 26, 2024 14:58:16.698627949 CEST53533451.1.1.1192.168.2.4
          Apr 26, 2024 14:58:16.712133884 CEST53632891.1.1.1192.168.2.4
          Apr 26, 2024 14:58:17.016346931 CEST5727153192.168.2.41.1.1.1
          Apr 26, 2024 14:58:17.016551018 CEST5417253192.168.2.41.1.1.1
          Apr 26, 2024 14:58:17.141433001 CEST53572711.1.1.1192.168.2.4
          Apr 26, 2024 14:58:17.141944885 CEST53541721.1.1.1192.168.2.4
          Apr 26, 2024 14:58:17.826276064 CEST5102853192.168.2.41.1.1.1
          Apr 26, 2024 14:58:17.828598976 CEST5545753192.168.2.41.1.1.1
          Apr 26, 2024 14:58:17.951572895 CEST53510281.1.1.1192.168.2.4
          Apr 26, 2024 14:58:17.953824997 CEST53554571.1.1.1192.168.2.4
          Apr 26, 2024 14:58:28.802488089 CEST138138192.168.2.4192.168.2.255
          Apr 26, 2024 14:58:35.937815905 CEST53554561.1.1.1192.168.2.4
          Apr 26, 2024 14:58:54.839934111 CEST53618371.1.1.1192.168.2.4
          Apr 26, 2024 14:59:13.917689085 CEST53624021.1.1.1192.168.2.4
          Apr 26, 2024 14:59:17.650460958 CEST53495171.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 26, 2024 14:58:16.568145037 CEST192.168.2.41.1.1.10xe99Standard query (0)f-log-extension.grammarly.ioA (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.568272114 CEST192.168.2.41.1.1.10xa2adStandard query (0)f-log-extension.grammarly.io65IN (0x0001)false
          Apr 26, 2024 14:58:17.016346931 CEST192.168.2.41.1.1.10x5ed7Standard query (0)f-log-extension.grammarly.ioA (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.016551018 CEST192.168.2.41.1.1.10x3242Standard query (0)f-log-extension.grammarly.io65IN (0x0001)false
          Apr 26, 2024 14:58:17.826276064 CEST192.168.2.41.1.1.10xb12Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.828598976 CEST192.168.2.41.1.1.10xd323Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io3.214.105.83A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io3.219.126.96A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io44.207.16.100A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io204.236.228.195A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io34.206.223.5A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io52.203.124.48A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io54.243.226.44A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:16.698602915 CEST1.1.1.1192.168.2.40xe99No error (0)f-log-extension.grammarly.io34.205.204.162A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io44.206.202.177A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io34.200.169.99A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io54.86.94.41A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io3.93.104.103A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io44.217.252.82A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io18.213.180.153A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io3.209.189.142A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.141433001 CEST1.1.1.1192.168.2.40x5ed7No error (0)f-log-extension.grammarly.io44.193.62.30A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.951572895 CEST1.1.1.1192.168.2.40xb12No error (0)www.google.com142.250.217.164A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:17.953824997 CEST1.1.1.1192.168.2.40xd323No error (0)www.google.com65IN (0x0001)false
          Apr 26, 2024 14:58:29.264868975 CEST1.1.1.1192.168.2.40x2be4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 26, 2024 14:58:29.264868975 CEST1.1.1.1192.168.2.40x2be4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 26, 2024 14:58:51.021861076 CEST1.1.1.1192.168.2.40x1c70No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 26, 2024 14:58:51.021861076 CEST1.1.1.1192.168.2.40x1c70No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • f-log-extension.grammarly.io
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.4497363.214.105.83803192C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 26, 2024 14:58:16.851577997 CEST443OUTGET / HTTP/1.1
          Host: f-log-extension.grammarly.io
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Apr 26, 2024 14:58:17.003585100 CEST348INHTTP/1.1 301 Moved Permanently
          Server: awselb/2.0
          Date: Fri, 26 Apr 2024 12:58:16 GMT
          Content-Type: text/html
          Content-Length: 134
          Connection: keep-alive
          Location: https://f-log-extension.grammarly.io:443/
          Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
          Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center></body></html>
          Apr 26, 2024 14:59:02.015696049 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.4497373.214.105.83803192C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 26, 2024 14:59:01.858057976 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44973944.206.202.1774433192C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-04-26 12:58:17 UTC671OUTGET / HTTP/1.1
          Host: f-log-extension.grammarly.io
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-04-26 12:58:17 UTC549INHTTP/1.1 404 Not Found
          Date: Fri, 26 Apr 2024 12:58:17 GMT
          Content-Type: text/plain; charset=utf-8
          Content-Length: 19
          Connection: close
          Access-Control-Allow-Headers: Keep-Alive,User-Agent,X-Requested-With,Cache-Control,Content-Type
          Access-Control-Allow-Methods: GET, POST, OPTIONS
          Access-Control-Allow-Origin: *
          Content-Security-Policy: default-src 'none'
          Referrer-Policy: no-referrer
          Strict-Transport-Security: max-age=31536000; includeSubDomains
          X-Content-Type-Options: nosniff
          X-Frame-Options: DENY
          X-Xss-Protection: 1;mode=block
          2024-04-26 12:58:17 UTC19INData Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a
          Data Ascii: 404 page not found


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44974123.193.120.112443
          TimestampBytes transferredDirectionData
          2024-04-26 12:58:21 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-26 12:58:21 UTC466INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0712)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=65171
          Date: Fri, 26 Apr 2024 12:58:21 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.44974223.193.120.112443
          TimestampBytes transferredDirectionData
          2024-04-26 12:58:24 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-26 12:58:24 UTC530INHTTP/1.1 200 OK
          Content-Type: application/octet-stream
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=65236
          Date: Fri, 26 Apr 2024 12:58:24 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-26 12:58:24 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:14:58:07
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:14:58:12
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,13024243500430534651,5569693173010471511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:14:58:14
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://f-log-extension.grammarly.io"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly