Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa

Overview

General Information

Sample URL:http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa
Analysis ID:1432234
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=2108,i,9715931353910741068,16769521476899145294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: classification engineClassification label: clean0.win@20/0@5/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=2108,i,9715931353910741068,16769521476899145294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=2108,i,9715931353910741068,16769521476899145294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1432234 URL: http://https:/mwebharmoniou... Startdate: 26/04/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 137, 138, 443 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.217.228, 443, 49737, 49749 GOOGLEUS United States 10->17 19 google.com 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
google.com
142.250.64.142
truefalse
    high
    www.google.com
    142.250.217.228
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalseunknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.217.228
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1432234
      Start date and time:2024-04-26 18:09:50 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 11s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@20/0@5/3
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 192.178.50.67, 142.250.64.174, 173.194.216.84, 34.104.35.123, 40.68.123.157, 199.232.210.172, 192.229.211.108, 20.242.39.171, 13.95.31.18, 172.217.165.195
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 26, 2024 18:10:32.813077927 CEST49678443192.168.2.4104.46.162.224
      Apr 26, 2024 18:10:33.063044071 CEST49675443192.168.2.4173.222.162.32
      Apr 26, 2024 18:10:42.670973063 CEST49675443192.168.2.4173.222.162.32
      Apr 26, 2024 18:10:45.974911928 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:45.974992037 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:45.975084066 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:45.975387096 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:45.975423098 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:46.079077005 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:46.079118013 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:46.079611063 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:46.083281994 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:46.083297014 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:46.342525959 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:46.342622995 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:46.373279095 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:46.441250086 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.412623882 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.412702084 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:47.416639090 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:47.416676998 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:47.416728973 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.528280020 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.532396078 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.532777071 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:47.733916998 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.733968019 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:47.808514118 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:47.808547974 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:47.808856964 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:47.834057093 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:47.936845064 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.140146971 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.184122086 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.265996933 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.266048908 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.266100883 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.422496080 CEST49738443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.422532082 CEST4434973823.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.475188017 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.475224972 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.475280046 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.475541115 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.475549936 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.730376005 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.730436087 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.731652021 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.731659889 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.731857061 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.732835054 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.780118942 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.982070923 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.982146978 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.982407093 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.986360073 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.986360073 CEST49739443192.168.2.423.204.76.112
      Apr 26, 2024 18:10:48.986377954 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:48.986386061 CEST4434973923.204.76.112192.168.2.4
      Apr 26, 2024 18:10:56.362080097 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:56.362225056 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:10:56.362314939 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:57.006164074 CEST49737443192.168.2.4142.250.217.228
      Apr 26, 2024 18:10:57.006195068 CEST44349737142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:45.897018909 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:45.897046089 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:45.897118092 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:45.897412062 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:45.897420883 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:46.227621078 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:46.227946043 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:46.227956057 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:46.228420019 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:46.228826046 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:46.228900909 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:46.281114101 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:51.750066996 CEST4972380192.168.2.4199.232.214.172
      Apr 26, 2024 18:11:51.750222921 CEST4972480192.168.2.4199.232.214.172
      Apr 26, 2024 18:11:51.881612062 CEST8049724199.232.214.172192.168.2.4
      Apr 26, 2024 18:11:51.881669998 CEST8049724199.232.214.172192.168.2.4
      Apr 26, 2024 18:11:51.881841898 CEST4972480192.168.2.4199.232.214.172
      Apr 26, 2024 18:11:51.885932922 CEST8049723199.232.214.172192.168.2.4
      Apr 26, 2024 18:11:51.885970116 CEST8049723199.232.214.172192.168.2.4
      Apr 26, 2024 18:11:51.886013985 CEST4972380192.168.2.4199.232.214.172
      Apr 26, 2024 18:11:56.221561909 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:56.221726894 CEST44349749142.250.217.228192.168.2.4
      Apr 26, 2024 18:11:56.221806049 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:57.276038885 CEST49749443192.168.2.4142.250.217.228
      Apr 26, 2024 18:11:57.276119947 CEST44349749142.250.217.228192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 26, 2024 18:10:41.210725069 CEST53632681.1.1.1192.168.2.4
      Apr 26, 2024 18:10:41.228494883 CEST53633601.1.1.1192.168.2.4
      Apr 26, 2024 18:10:43.903491974 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:43.932883978 CEST53652581.1.1.1192.168.2.4
      Apr 26, 2024 18:10:44.656657934 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:45.410227060 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:45.847146988 CEST6234653192.168.2.41.1.1.1
      Apr 26, 2024 18:10:45.847362041 CEST6485253192.168.2.41.1.1.1
      Apr 26, 2024 18:10:45.973089933 CEST53648521.1.1.1192.168.2.4
      Apr 26, 2024 18:10:45.973207951 CEST53623461.1.1.1192.168.2.4
      Apr 26, 2024 18:10:46.312800884 CEST6508453192.168.2.48.8.8.8
      Apr 26, 2024 18:10:46.313025951 CEST5263853192.168.2.41.1.1.1
      Apr 26, 2024 18:10:46.438922882 CEST53526381.1.1.1192.168.2.4
      Apr 26, 2024 18:10:46.489064932 CEST53650848.8.8.8192.168.2.4
      Apr 26, 2024 18:10:47.413223982 CEST5518353192.168.2.48.8.4.4
      Apr 26, 2024 18:10:47.538203001 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:47.571578026 CEST53551838.8.4.4192.168.2.4
      Apr 26, 2024 18:10:48.293714046 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:49.045258999 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:57.002064943 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:57.766443014 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:10:58.521657944 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:11:03.513036013 CEST138138192.168.2.4192.168.2.255
      Apr 26, 2024 18:11:05.952136040 CEST53645971.1.1.1192.168.2.4
      Apr 26, 2024 18:11:25.049160004 CEST53541881.1.1.1192.168.2.4
      Apr 26, 2024 18:11:29.341645956 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:11:30.091286898 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:11:30.846193075 CEST137137192.168.2.4192.168.2.255
      Apr 26, 2024 18:11:40.930243015 CEST53495991.1.1.1192.168.2.4
      Apr 26, 2024 18:11:47.477899075 CEST53608471.1.1.1192.168.2.4
      TimestampSource IPDest IPChecksumCodeType
      Apr 26, 2024 18:10:47.571654081 CEST192.168.2.48.8.4.4cc4a(Port unreachable)Destination Unreachable
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 26, 2024 18:10:45.847146988 CEST192.168.2.41.1.1.10xddccStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:45.847362041 CEST192.168.2.41.1.1.10x7249Standard query (0)www.google.com65IN (0x0001)false
      Apr 26, 2024 18:10:46.312800884 CEST192.168.2.48.8.8.80x9eStandard query (0)google.comA (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.313025951 CEST192.168.2.41.1.1.10xa09fStandard query (0)google.comA (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.413223982 CEST192.168.2.48.8.4.40x8ad2Standard query (0)google.comA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 26, 2024 18:10:45.973089933 CEST1.1.1.1192.168.2.40x7249No error (0)www.google.com65IN (0x0001)false
      Apr 26, 2024 18:10:45.973207951 CEST1.1.1.1192.168.2.40xddccNo error (0)www.google.com142.250.217.228A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.438922882 CEST1.1.1.1192.168.2.40xa09fNo error (0)google.com142.250.64.142A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.102A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.113A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.138A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.100A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.139A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:46.489064932 CEST8.8.8.8192.168.2.40x9eNo error (0)google.com142.250.113.101A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.101A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.102A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.100A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.113A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.139A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:47.571578026 CEST8.8.4.4192.168.2.40x8ad2No error (0)google.com142.250.113.138A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:57.271657944 CEST1.1.1.1192.168.2.40xa081No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:57.271657944 CEST1.1.1.1192.168.2.40xa081No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Apr 26, 2024 18:10:57.681952000 CEST1.1.1.1192.168.2.40x1e54No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 18:10:57.681952000 CEST1.1.1.1192.168.2.40x1e54No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 18:11:13.627837896 CEST1.1.1.1192.168.2.40x5372No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 18:11:13.627837896 CEST1.1.1.1192.168.2.40x5372No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 18:11:40.236628056 CEST1.1.1.1192.168.2.40xdca7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 18:11:40.236628056 CEST1.1.1.1192.168.2.40xdca7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 26, 2024 18:11:53.931512117 CEST1.1.1.1192.168.2.40xa1bfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 26, 2024 18:11:53.931512117 CEST1.1.1.1192.168.2.40xa1bfNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44973823.204.76.112443
      TimestampBytes transferredDirectionData
      2024-04-26 16:10:48 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-26 16:10:48 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/0758)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=53577
      Date: Fri, 26 Apr 2024 16:10:48 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44973923.204.76.112443
      TimestampBytes transferredDirectionData
      2024-04-26 16:10:48 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-26 16:10:48 UTC530INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=53571
      Date: Fri, 26 Apr 2024 16:10:48 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-26 16:10:48 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:18:10:36
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:18:10:40
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=2108,i,9715931353910741068,16769521476899145294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:18:10:42
      Start date:26/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/mwebharmonious.com/8807/70/3/?subid=rhdsghfdsfGaa"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly