Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.verifyrequest.com/

Overview

General Information

Sample URL:http://www.verifyrequest.com/
Analysis ID:1433173
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4340 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2076 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2024,i,16824128801002358642,17108538071278763702,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.verifyrequest.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 104.122.44.67:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.122.44.67:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownTCP traffic detected without corresponding DNS query: 104.122.44.67
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.verifyrequest.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownHTTPS traffic detected: 104.122.44.67:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.122.44.67:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@18/0@4/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2024,i,16824128801002358642,17108538071278763702,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.verifyrequest.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2024,i,16824128801002358642,17108538071278763702,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.verifyrequest.com/0%Avira URL Cloudsafe
http://www.verifyrequest.com/0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.verifyrequest.com
3.231.1.210
truefalse
    unknown
    www.google.com
    142.250.191.196
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        windowsupdatebg.s.llnwi.net
        208.111.186.128
        truefalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          3.231.1.210
          www.verifyrequest.comUnited States
          14618AMAZON-AESUSfalse
          35.153.152.137
          unknownUnited States
          14618AMAZON-AESUSfalse
          142.250.191.196
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.16
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1433173
          Start date and time:2024-04-29 10:37:41 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 39s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://www.verifyrequest.com/
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown0.win@18/0@4/6
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.190.67, 142.250.191.238, 142.251.165.84, 34.104.35.123, 40.68.123.157, 208.111.186.128, 13.95.31.18, 192.229.211.108
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 29, 2024 10:38:23.661473036 CEST49678443192.168.2.4104.46.162.224
          Apr 29, 2024 10:38:23.692679882 CEST49675443192.168.2.4173.222.162.32
          Apr 29, 2024 10:38:33.015443087 CEST4973580192.168.2.43.231.1.210
          Apr 29, 2024 10:38:33.016212940 CEST4973680192.168.2.43.231.1.210
          Apr 29, 2024 10:38:33.148005962 CEST4973780192.168.2.43.231.1.210
          Apr 29, 2024 10:38:33.398411989 CEST49675443192.168.2.4173.222.162.32
          Apr 29, 2024 10:38:34.029891968 CEST4973580192.168.2.43.231.1.210
          Apr 29, 2024 10:38:34.157862902 CEST4973680192.168.2.43.231.1.210
          Apr 29, 2024 10:38:34.157875061 CEST4973780192.168.2.43.231.1.210
          Apr 29, 2024 10:38:36.038629055 CEST4973580192.168.2.43.231.1.210
          Apr 29, 2024 10:38:36.161530018 CEST4973780192.168.2.43.231.1.210
          Apr 29, 2024 10:38:36.205085039 CEST4973680192.168.2.43.231.1.210
          Apr 29, 2024 10:38:36.640661001 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.640701056 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:36.640783072 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.641587973 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.641601086 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:36.882642031 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:36.908067942 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.908080101 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:36.909646034 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:36.909744024 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.912951946 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:36.913033009 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:37.050410032 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:37.050419092 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:37.149291992 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.149327993 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.149446964 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.151688099 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.151700974 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.236383915 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:37.392982960 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.393075943 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.401693106 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.401710033 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.402182102 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.441983938 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.493679047 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.536127090 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.642092943 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.642276049 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.642292023 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.642301083 CEST49741443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.642302990 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.642359972 CEST44349741104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.679774046 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.679801941 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.679869890 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.680160046 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.680174112 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.903480053 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.903541088 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.905057907 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.905065060 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.905287027 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:37.906147003 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:37.952110052 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:38.143493891 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:38.143565893 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:38.143618107 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:38.203809977 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:38.203830957 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:38.203876972 CEST49742443192.168.2.4104.122.44.67
          Apr 29, 2024 10:38:38.203881979 CEST44349742104.122.44.67192.168.2.4
          Apr 29, 2024 10:38:40.048507929 CEST4973580192.168.2.43.231.1.210
          Apr 29, 2024 10:38:40.161895037 CEST4973780192.168.2.43.231.1.210
          Apr 29, 2024 10:38:40.257172108 CEST4973680192.168.2.43.231.1.210
          Apr 29, 2024 10:38:46.888835907 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:46.888899088 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:46.889044046 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:48.055105925 CEST4973580192.168.2.43.231.1.210
          Apr 29, 2024 10:38:48.062597036 CEST49740443192.168.2.4142.250.191.196
          Apr 29, 2024 10:38:48.062639952 CEST44349740142.250.191.196192.168.2.4
          Apr 29, 2024 10:38:48.170207024 CEST4973780192.168.2.43.231.1.210
          Apr 29, 2024 10:38:48.260001898 CEST4973680192.168.2.43.231.1.210
          Apr 29, 2024 10:38:54.066823959 CEST4974980192.168.2.435.153.152.137
          Apr 29, 2024 10:38:54.177587032 CEST4975080192.168.2.435.153.152.137
          Apr 29, 2024 10:38:54.272623062 CEST4975180192.168.2.435.153.152.137
          Apr 29, 2024 10:38:55.070379972 CEST4974980192.168.2.435.153.152.137
          Apr 29, 2024 10:38:55.176943064 CEST4975080192.168.2.435.153.152.137
          Apr 29, 2024 10:38:55.286230087 CEST4975180192.168.2.435.153.152.137
          Apr 29, 2024 10:38:57.084810019 CEST4974980192.168.2.435.153.152.137
          Apr 29, 2024 10:38:57.177314043 CEST4975080192.168.2.435.153.152.137
          Apr 29, 2024 10:38:57.287699938 CEST4975180192.168.2.435.153.152.137
          Apr 29, 2024 10:39:01.100394964 CEST4974980192.168.2.435.153.152.137
          Apr 29, 2024 10:39:01.178574085 CEST4975080192.168.2.435.153.152.137
          Apr 29, 2024 10:39:01.302387953 CEST4975180192.168.2.435.153.152.137
          Apr 29, 2024 10:39:09.100428104 CEST4974980192.168.2.435.153.152.137
          Apr 29, 2024 10:39:09.193563938 CEST4975080192.168.2.435.153.152.137
          Apr 29, 2024 10:39:09.303376913 CEST4975180192.168.2.435.153.152.137
          Apr 29, 2024 10:39:16.154695988 CEST4975280192.168.2.43.231.1.210
          Apr 29, 2024 10:39:16.156136990 CEST4975380192.168.2.43.231.1.210
          Apr 29, 2024 10:39:16.411761045 CEST4975480192.168.2.43.231.1.210
          Apr 29, 2024 10:39:17.162879944 CEST4975380192.168.2.43.231.1.210
          Apr 29, 2024 10:39:17.168827057 CEST4975280192.168.2.43.231.1.210
          Apr 29, 2024 10:39:17.417664051 CEST4975480192.168.2.43.231.1.210
          Apr 29, 2024 10:39:19.176785946 CEST4975380192.168.2.43.231.1.210
          Apr 29, 2024 10:39:19.176790953 CEST4975280192.168.2.43.231.1.210
          Apr 29, 2024 10:39:19.426966906 CEST4975480192.168.2.43.231.1.210
          Apr 29, 2024 10:39:23.177695990 CEST4975380192.168.2.43.231.1.210
          Apr 29, 2024 10:39:23.177851915 CEST4975280192.168.2.43.231.1.210
          Apr 29, 2024 10:39:23.428426981 CEST4975480192.168.2.43.231.1.210
          TimestampSource PortDest PortSource IPDest IP
          Apr 29, 2024 10:38:31.688884020 CEST53569531.1.1.1192.168.2.4
          Apr 29, 2024 10:38:31.852922916 CEST53545951.1.1.1192.168.2.4
          Apr 29, 2024 10:38:32.518965960 CEST53625161.1.1.1192.168.2.4
          Apr 29, 2024 10:38:32.882735968 CEST6291153192.168.2.41.1.1.1
          Apr 29, 2024 10:38:32.882953882 CEST5310753192.168.2.41.1.1.1
          Apr 29, 2024 10:38:32.998794079 CEST53531071.1.1.1192.168.2.4
          Apr 29, 2024 10:38:33.011956930 CEST53629111.1.1.1192.168.2.4
          Apr 29, 2024 10:38:36.516172886 CEST5757753192.168.2.41.1.1.1
          Apr 29, 2024 10:38:36.517704010 CEST6406853192.168.2.41.1.1.1
          Apr 29, 2024 10:38:36.626297951 CEST53575771.1.1.1192.168.2.4
          Apr 29, 2024 10:38:36.627814054 CEST53640681.1.1.1192.168.2.4
          Apr 29, 2024 10:38:50.679941893 CEST53622651.1.1.1192.168.2.4
          Apr 29, 2024 10:38:54.198376894 CEST138138192.168.2.4192.168.2.255
          Apr 29, 2024 10:39:09.462300062 CEST53611721.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 29, 2024 10:38:32.882735968 CEST192.168.2.41.1.1.10x4fc9Standard query (0)www.verifyrequest.comA (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:32.882953882 CEST192.168.2.41.1.1.10xa540Standard query (0)www.verifyrequest.com65IN (0x0001)false
          Apr 29, 2024 10:38:36.516172886 CEST192.168.2.41.1.1.10xd393Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:36.517704010 CEST192.168.2.41.1.1.10x3202Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 29, 2024 10:38:33.011956930 CEST1.1.1.1192.168.2.40x4fc9No error (0)www.verifyrequest.com3.231.1.210A (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:33.011956930 CEST1.1.1.1192.168.2.40x4fc9No error (0)www.verifyrequest.com35.153.152.137A (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:36.626297951 CEST1.1.1.1192.168.2.40xd393No error (0)www.google.com142.250.191.196A (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:36.627814054 CEST1.1.1.1192.168.2.40x3202No error (0)www.google.com65IN (0x0001)false
          Apr 29, 2024 10:38:46.984481096 CEST1.1.1.1192.168.2.40x8bc2No error (0)windowsupdatebg.s.llnwi.net208.111.186.128A (IP address)IN (0x0001)false
          Apr 29, 2024 10:38:47.407383919 CEST1.1.1.1192.168.2.40x61cfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 29, 2024 10:38:47.407383919 CEST1.1.1.1192.168.2.40x61cfNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 29, 2024 10:39:00.586483955 CEST1.1.1.1192.168.2.40xd620No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 29, 2024 10:39:00.586483955 CEST1.1.1.1192.168.2.40xd620No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 29, 2024 10:39:24.559272051 CEST1.1.1.1192.168.2.40x2408No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 29, 2024 10:39:24.559272051 CEST1.1.1.1192.168.2.40x2408No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449741104.122.44.67443
          TimestampBytes transferredDirectionData
          2024-04-29 08:38:37 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-29 08:38:37 UTC466INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0790)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=80761
          Date: Mon, 29 Apr 2024 08:38:37 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449742104.122.44.67443
          TimestampBytes transferredDirectionData
          2024-04-29 08:38:37 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-29 08:38:38 UTC530INHTTP/1.1 200 OK
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Content-Type: application/octet-stream
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=80858
          Date: Mon, 29 Apr 2024 08:38:38 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-29 08:38:38 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:10:38:25
          Start date:29/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:10:38:29
          Start date:29/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2024,i,16824128801002358642,17108538071278763702,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:10:38:31
          Start date:29/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.verifyrequest.com/"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly