Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://44.214.84.226

Overview

General Information

Sample URL:http://44.214.84.226
Analysis ID:1432198
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 4744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5160 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2252,i,17042343845688903675,6875140049084255595,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3008 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://44.214.84.226" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownTCP traffic detected without corresponding DNS query: 44.214.84.226
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 44.214.84.226Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/6@2/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2252,i,17042343845688903675,6875140049084255595,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://44.214.84.226"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2252,i,17042343845688903675,6875140049084255595,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://44.214.84.2260%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://44.214.84.226/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.64.196
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://44.214.84.226/false
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        44.214.84.226
        unknownUnited States
        14618AMAZON-AESUSfalse
        142.250.64.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.5
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1432198
        Start date and time:2024-04-26 17:05:26 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 11s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://44.214.84.226
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@17/6@2/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.217.163, 192.178.50.46, 173.194.216.84, 34.104.35.123, 52.165.165.26, 199.232.210.172, 192.229.211.108, 20.3.187.198, 20.12.23.50, 172.217.3.67
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 14:06:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2677
        Entropy (8bit):3.9794516089895935
        Encrypted:false
        SSDEEP:48:80dqT8LqhH8idAKZdA19ehwiZUklqehOy+3:8BgeEBy
        MD5:39CC2A8DFE0C5DF26B134E7FC1D18278
        SHA1:5B0C3086AD3FC53DC4C48F9991681FC07B323E55
        SHA-256:38046109D96FAB92E0E8109F9EBE25D4724AD283E0150E9C9618B76CBC1A7883
        SHA-512:24585541C4199E63DABD709CA730A0F9070D573EBE0C61B3C8D56395B71C773D2DB20A6BE6B4F9A4FA159970A14A2A345DCF1A4C591056873EB213FB3CA8340A
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,....A.J...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.x...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 14:06:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2679
        Entropy (8bit):3.997515498414281
        Encrypted:false
        SSDEEP:48:8dWdqT8LqhH8idAKZdA1weh/iZUkAQkqehxy+2:8dPge29Qgy
        MD5:F2A7551B1D39143F2B653A3364640123
        SHA1:201011ADF1B57DF8486DFE550AD6B26B42DFF36E
        SHA-256:3EC072D65F6122AA57C78170CB8C8E603537F834B5EA937AE1A5B0D28DB3E9B6
        SHA-512:27400239F7917813DE152E900F66645F1956F9DBE9DE353FAB0196A8318DBF00C555C68687691EA676A3EBB681D4A1BAC2D75E313C90367159797D902FE24FE5
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.......J...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.x...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2693
        Entropy (8bit):4.00587415399101
        Encrypted:false
        SSDEEP:48:8x7dqT8LqsH8idAKZdA14tseh7sFiZUkmgqeh7sby+BX:8xUgeJn1y
        MD5:248D750016DEE1D01079CCF324EDE4BD
        SHA1:B8185D42F719FCDC8939536086FDCAE7E7F1E42A
        SHA-256:69DFB3587490636E59A519F35A5A0BB7D08B735D7193B7A90BB59A9081F9AEBD
        SHA-512:C183CD1D17722EBC9DACBDC1B5CA7B4154F5B99DD5D4F3375D4A03AA5D94858955C6D997488984493C2CD6B89A1780DE869EC73ACE956414BF21CFE5814E775F
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 14:06:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2681
        Entropy (8bit):3.9947225377082765
        Encrypted:false
        SSDEEP:48:8KdqT8LqhH8idAKZdA1vehDiZUkwqehty+R:8bgedTy
        MD5:8CD496F562C284B3DE49073C68D46687
        SHA1:CE97F48DC4237C0E005175F594E7A16652FC5F2B
        SHA-256:3259BAE36837C1E826A0890EDDCFD861D7CFD74CC819F1A409AC3E06D340E0FF
        SHA-512:03145E64A69BBB6633E0C63C50B3B6538DE6181F01CAA6C4B756D40EB340D57446D22EA9582DFBAE6CED0173682CA46A21508C9428295C639FE27DD8F582F9AB
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....a.J...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.x...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 14:06:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2681
        Entropy (8bit):3.9862226186562517
        Encrypted:false
        SSDEEP:48:8fWdqT8LqhH8idAKZdA1hehBiZUk1W1qehvy+C:8Hge99Py
        MD5:ADD66BC378C0B481B3A58096C4F73757
        SHA1:23EEDB234F3F01DDC672E29FFADE728BFEEBCD6A
        SHA-256:D14384A53329020FD4907D6667EB5A6BC9C12301297F57B9CD34DBA838981DDE
        SHA-512:AA76373E6B568D2F495686FA990907A9BA8E874FB6EE87CA54339E7B222E95BE086261FF3A4CE7F718E46F57F9748ED8969F0ED34F34795D826FE4BCF108D7AE
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,......J...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.x...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 14:06:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2683
        Entropy (8bit):3.9950496455466302
        Encrypted:false
        SSDEEP:48:8GdqT8LqhH8idAKZdA1duT+ehOuTbbiZUk5OjqehOuTb1y+yT+:8fgeBT/TbxWOvTb1y7T
        MD5:4C272692F86D0ECCBCB9C74E90E75D2B
        SHA1:9878AE7EF42E0CCCC7E32E97C3A23BBDB14D03B4
        SHA-256:7340F329ECCEF367B5C3B178BED356DF0289DDD968C830C86427CB44079F1A1A
        SHA-512:1EA2032736922EC27CE6F98C4FB26209BE85847F3566A8965DB490600B007F127C326457A8007A5BC854168ABFDB4ACCAE9E66D78A360B39036871E816E87B12
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,......rJ...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.x....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.x....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.x....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.x..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.x...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 26, 2024 17:06:09.437139988 CEST49674443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:09.437218904 CEST49675443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:09.546575069 CEST49673443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:19.042253017 CEST49675443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:19.089030027 CEST49674443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:19.229723930 CEST49673443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:19.882272959 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:06:19.882471085 CEST4971080192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.033595085 CEST804971044.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.033682108 CEST4971080192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.034157991 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.034216881 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.035592079 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.187448978 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.188226938 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.224189043 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.224235058 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.224313974 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.224509954 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.224524975 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.275053978 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.672436953 CEST4434970323.1.237.91192.168.2.5
        Apr 26, 2024 17:06:20.672547102 CEST49703443192.168.2.523.1.237.91
        Apr 26, 2024 17:06:20.688859940 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.689251900 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.689282894 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.690355062 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.690423965 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.692526102 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.692714930 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:20.692781925 CEST49712443192.168.2.544.214.84.226
        Apr 26, 2024 17:06:20.692797899 CEST4434971244.214.84.226192.168.2.5
        Apr 26, 2024 17:06:21.953075886 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:21.953119040 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:21.953196049 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:21.953855038 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:21.953870058 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:22.352013111 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:22.539767027 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:23.823884964 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:23.823918104 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:23.825018883 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:23.825032949 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:23.825093031 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:23.896130085 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:23.896226883 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:24.039743900 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:24.039762020 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:24.176249981 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:24.815305948 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:24.815356016 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:24.815663099 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:24.817318916 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:24.817358971 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.086312056 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.086395979 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.094588995 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.094619989 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.095032930 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.169202089 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.216119051 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.323019028 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.323462963 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.323606968 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.517390013 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.517436981 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:25.517457008 CEST49717443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:25.517462969 CEST4434971723.204.76.112192.168.2.5
        Apr 26, 2024 17:06:27.855943918 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:27.855993032 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:27.856061935 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:27.856581926 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:27.856600046 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.119344950 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.119447947 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.122435093 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.122442961 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.122771025 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.148092031 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.192121029 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.366182089 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.366343021 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.366405010 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.369862080 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.369887114 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:28.369903088 CEST49718443192.168.2.523.204.76.112
        Apr 26, 2024 17:06:28.369910002 CEST4434971823.204.76.112192.168.2.5
        Apr 26, 2024 17:06:32.329884052 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:32.329957008 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:06:32.330086946 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:33.700156927 CEST49716443192.168.2.5142.250.64.196
        Apr 26, 2024 17:06:33.700225115 CEST44349716142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:05.040055037 CEST4971080192.168.2.544.214.84.226
        Apr 26, 2024 17:07:05.191595078 CEST804971044.214.84.226192.168.2.5
        Apr 26, 2024 17:07:05.196283102 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:07:05.348445892 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:07:20.183090925 CEST804971044.214.84.226192.168.2.5
        Apr 26, 2024 17:07:20.183171034 CEST4971080192.168.2.544.214.84.226
        Apr 26, 2024 17:07:20.189074039 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:07:20.189127922 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:07:21.699244976 CEST4971080192.168.2.544.214.84.226
        Apr 26, 2024 17:07:21.699302912 CEST4970980192.168.2.544.214.84.226
        Apr 26, 2024 17:07:21.839121103 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:21.839175940 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:21.839297056 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:21.839550018 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:21.839566946 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:21.850405931 CEST804971044.214.84.226192.168.2.5
        Apr 26, 2024 17:07:21.851228952 CEST804970944.214.84.226192.168.2.5
        Apr 26, 2024 17:07:22.226651907 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:22.226996899 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:22.227030993 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:22.227355003 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:22.227736950 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:22.227804899 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:22.270658970 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:32.226007938 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:32.226083994 CEST44349728142.250.64.196192.168.2.5
        Apr 26, 2024 17:07:32.227144957 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:34.032958031 CEST49728443192.168.2.5142.250.64.196
        Apr 26, 2024 17:07:34.032984018 CEST44349728142.250.64.196192.168.2.5
        TimestampSource PortDest PortSource IPDest IP
        Apr 26, 2024 17:06:17.519423962 CEST53531961.1.1.1192.168.2.5
        Apr 26, 2024 17:06:17.538209915 CEST53560401.1.1.1192.168.2.5
        Apr 26, 2024 17:06:18.395139933 CEST53543711.1.1.1192.168.2.5
        Apr 26, 2024 17:06:20.982861996 CEST53626561.1.1.1192.168.2.5
        Apr 26, 2024 17:06:21.790883064 CEST4943553192.168.2.51.1.1.1
        Apr 26, 2024 17:06:21.791348934 CEST5389553192.168.2.51.1.1.1
        Apr 26, 2024 17:06:21.916167021 CEST53494351.1.1.1192.168.2.5
        Apr 26, 2024 17:06:21.917054892 CEST53538951.1.1.1192.168.2.5
        Apr 26, 2024 17:06:37.267363071 CEST53551851.1.1.1192.168.2.5
        Apr 26, 2024 17:06:56.214556932 CEST53624501.1.1.1192.168.2.5
        Apr 26, 2024 17:07:17.328274965 CEST53510411.1.1.1192.168.2.5
        Apr 26, 2024 17:07:19.284346104 CEST53569241.1.1.1192.168.2.5
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 26, 2024 17:06:21.790883064 CEST192.168.2.51.1.1.10x833dStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 26, 2024 17:06:21.791348934 CEST192.168.2.51.1.1.10xaf78Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 26, 2024 17:06:21.916167021 CEST1.1.1.1192.168.2.50x833dNo error (0)www.google.com142.250.64.196A (IP address)IN (0x0001)false
        Apr 26, 2024 17:06:21.917054892 CEST1.1.1.1192.168.2.50xaf78No error (0)www.google.com65IN (0x0001)false
        Apr 26, 2024 17:06:30.275693893 CEST1.1.1.1192.168.2.50x6031No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Apr 26, 2024 17:06:30.275693893 CEST1.1.1.1192.168.2.50x6031No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Apr 26, 2024 17:06:30.716499090 CEST1.1.1.1192.168.2.50x64b9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 26, 2024 17:06:30.716499090 CEST1.1.1.1192.168.2.50x64b9No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 26, 2024 17:06:43.842871904 CEST1.1.1.1192.168.2.50x3cfeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 26, 2024 17:06:43.842871904 CEST1.1.1.1192.168.2.50x3cfeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • fs.microsoft.com
        • 44.214.84.226
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.54970944.214.84.226805160C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 26, 2024 17:06:20.035592079 CEST428OUTGET / HTTP/1.1
        Host: 44.214.84.226
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Apr 26, 2024 17:06:20.188226938 CEST188INHTTP/1.1 301 Moved Permanently
        Date: Fri, 26 Apr 2024 15:06:20 GMT
        Content-Type: text/html; charset=utf-8
        Content-Length: 0
        Connection: keep-alive
        location: https://44.214.84.226/
        Apr 26, 2024 17:07:05.196283102 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.54971044.214.84.226805160C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Apr 26, 2024 17:07:05.040055037 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.54971723.204.76.112443
        TimestampBytes transferredDirectionData
        2024-04-26 15:06:25 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-26 15:06:25 UTC466INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/0758)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus-z1
        Cache-Control: public, max-age=57440
        Date: Fri, 26 Apr 2024 15:06:25 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.54971823.204.76.112443
        TimestampBytes transferredDirectionData
        2024-04-26 15:06:28 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-26 15:06:28 UTC530INHTTP/1.1 200 OK
        Content-Type: application/octet-stream
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
        Cache-Control: public, max-age=57431
        Date: Fri, 26 Apr 2024 15:06:28 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-26 15:06:28 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:17:06:09
        Start date:26/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:17:06:15
        Start date:26/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2252,i,17042343845688903675,6875140049084255595,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:17:06:17
        Start date:26/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://44.214.84.226"
        Imagebase:0x7ff715980000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly