Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY

Overview

General Information

Sample URL:https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY
Analysis ID:1438232
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1704 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,15263746694786473811,17346230832487893663,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeYHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 96.7.158.101:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 96.7.158.101:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.158.101
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeYAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gvc=Nzc2OTMwMDY4NDY3ODA0NzIzNjU2MzM2NDAxNjcyMjUyNzAx; t=baTzw7vjGg_mvZgRJdL6PS00; __Host-js_csrf=baTzw7vjGg_mvZgRJdL6PS00; __Host-ss=rnN5bSwxG8; locale=en
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.dropbox.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundStrict-Transport-Security: max-age=31536000; includeSubDomainsContent-Length: 1233Content-Type: text/htmlDate: Wed, 08 May 2024 11:49:15 GMTServer: envoyCache-Control: no-cache, no-storeVary: Accept-EncodingX-Dropbox-Response-Origin: remoteX-Dropbox-Request-Id: 5c4795812ef8443ea46f434c80a2e6a5Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 96.7.158.101:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 96.7.158.101:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,15263746694786473811,17346230832487893663,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,15263746694786473811,17346230832487893663,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www-env.dropbox-dns.com
    162.125.1.18
    truefalse
      unknown
      www.google.com
      142.250.217.68
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          www.dropbox.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://www.dropbox.com/favicon.icofalse
              high
              https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeYfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.217.68
                www.google.comUnited States
                15169GOOGLEUSfalse
                162.125.1.18
                www-env.dropbox-dns.comUnited States
                19679DROPBOXUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1438232
                Start date and time:2024-05-08 13:48:22 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 3s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:9
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/0@4/4
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.251.211.238, 142.250.69.195, 74.125.135.84, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.211.108, 20.242.39.171, 142.250.217.67
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                May 8, 2024 13:49:04.660212994 CEST49678443192.168.2.4104.46.162.224
                May 8, 2024 13:49:05.941464901 CEST49675443192.168.2.4173.222.162.32
                May 8, 2024 13:49:15.000835896 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.000874996 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.000936985 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.001307964 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.001346111 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.001399040 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.001554966 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.001568079 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.001817942 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.001837015 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.497632980 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.498064995 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.498090029 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.498096943 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.498264074 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.498287916 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.499074936 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.499141932 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.499370098 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.499423027 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.500246048 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.500310898 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.500459909 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.500519037 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.500577927 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.500586033 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.551444054 CEST49675443192.168.2.4173.222.162.32
                May 8, 2024 13:49:15.551445007 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.551457882 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.551470995 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.598247051 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.729150057 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.729180098 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.729262114 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.729264021 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.729310036 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.730521917 CEST49735443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.730545044 CEST44349735162.125.1.18192.168.2.4
                May 8, 2024 13:49:15.810261011 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:15.856120110 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:16.073501110 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:16.073594093 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:16.073647022 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:16.074304104 CEST49736443192.168.2.4162.125.1.18
                May 8, 2024 13:49:16.074321985 CEST44349736162.125.1.18192.168.2.4
                May 8, 2024 13:49:16.976968050 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:16.977011919 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:16.977062941 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:16.978737116 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:16.978749990 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.314905882 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.315320015 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:17.315336943 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.316245079 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.316303968 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:17.742010117 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:17.742341995 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.786115885 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:17.786140919 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:17.834141970 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:17.902915955 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:17.902971983 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:17.906196117 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:17.908610106 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:17.908632040 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.243386984 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.243581057 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.281558990 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.281582117 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.281853914 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.332156897 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.340265036 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.384121895 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.562171936 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.562246084 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.562376022 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.562551022 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.562570095 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.562602043 CEST49740443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.562608004 CEST4434974096.7.158.101192.168.2.4
                May 8, 2024 13:49:18.648983955 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.649023056 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:18.649122000 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.667450905 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.667490005 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:18.996007919 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:18.996085882 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.997458935 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:18.997467041 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:18.997697115 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:18.998814106 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:19.040129900 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:19.319911957 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:19.319977045 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:19.320029974 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:19.371387959 CEST49741443192.168.2.496.7.158.101
                May 8, 2024 13:49:19.371414900 CEST4434974196.7.158.101192.168.2.4
                May 8, 2024 13:49:27.327521086 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:27.327588081 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:49:27.327682018 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:27.413650036 CEST49739443192.168.2.4142.250.217.68
                May 8, 2024 13:49:27.413677931 CEST44349739142.250.217.68192.168.2.4
                May 8, 2024 13:50:16.849854946 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:16.849895000 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:16.849957943 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:16.850445032 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:16.850454092 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:17.185216904 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:17.185590982 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:17.185619116 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:17.185897112 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:17.186821938 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:17.186880112 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:17.237905025 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:23.597788095 CEST4972380192.168.2.4199.232.214.172
                May 8, 2024 13:50:23.761462927 CEST8049723199.232.214.172192.168.2.4
                May 8, 2024 13:50:23.761478901 CEST8049723199.232.214.172192.168.2.4
                May 8, 2024 13:50:23.761542082 CEST4972380192.168.2.4199.232.214.172
                May 8, 2024 13:50:27.192625999 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:27.192694902 CEST44349750142.250.217.68192.168.2.4
                May 8, 2024 13:50:27.192770004 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:27.411834002 CEST49750443192.168.2.4142.250.217.68
                May 8, 2024 13:50:27.411858082 CEST44349750142.250.217.68192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                May 8, 2024 13:49:13.327209949 CEST53512471.1.1.1192.168.2.4
                May 8, 2024 13:49:13.328103065 CEST53513811.1.1.1192.168.2.4
                May 8, 2024 13:49:14.325673103 CEST53615841.1.1.1192.168.2.4
                May 8, 2024 13:49:14.835570097 CEST5817653192.168.2.41.1.1.1
                May 8, 2024 13:49:14.835829973 CEST5272553192.168.2.41.1.1.1
                May 8, 2024 13:49:14.999984026 CEST53581761.1.1.1192.168.2.4
                May 8, 2024 13:49:15.000195026 CEST53527251.1.1.1192.168.2.4
                May 8, 2024 13:49:16.797369957 CEST5214853192.168.2.41.1.1.1
                May 8, 2024 13:49:16.797494888 CEST5894853192.168.2.41.1.1.1
                May 8, 2024 13:49:16.960030079 CEST53521481.1.1.1192.168.2.4
                May 8, 2024 13:49:16.960159063 CEST53589481.1.1.1192.168.2.4
                May 8, 2024 13:49:31.559478045 CEST53651331.1.1.1192.168.2.4
                May 8, 2024 13:49:35.205725908 CEST138138192.168.2.4192.168.2.255
                May 8, 2024 13:49:50.521692991 CEST53523401.1.1.1192.168.2.4
                May 8, 2024 13:50:12.670408010 CEST53630931.1.1.1192.168.2.4
                May 8, 2024 13:50:13.371022940 CEST53584011.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                May 8, 2024 13:49:14.835570097 CEST192.168.2.41.1.1.10x594aStandard query (0)www.dropbox.comA (IP address)IN (0x0001)false
                May 8, 2024 13:49:14.835829973 CEST192.168.2.41.1.1.10x9fc4Standard query (0)www.dropbox.com65IN (0x0001)false
                May 8, 2024 13:49:16.797369957 CEST192.168.2.41.1.1.10xd7f2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                May 8, 2024 13:49:16.797494888 CEST192.168.2.41.1.1.10x1744Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                May 8, 2024 13:49:14.999984026 CEST1.1.1.1192.168.2.40x594aNo error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:49:14.999984026 CEST1.1.1.1192.168.2.40x594aNo error (0)www-env.dropbox-dns.com162.125.1.18A (IP address)IN (0x0001)false
                May 8, 2024 13:49:15.000195026 CEST1.1.1.1192.168.2.40x9fc4No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:49:16.960030079 CEST1.1.1.1192.168.2.40xd7f2No error (0)www.google.com142.250.217.68A (IP address)IN (0x0001)false
                May 8, 2024 13:49:16.960159063 CEST1.1.1.1192.168.2.40x1744No error (0)www.google.com65IN (0x0001)false
                May 8, 2024 13:49:28.651698112 CEST1.1.1.1192.168.2.40x1e6cNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                May 8, 2024 13:49:28.651698112 CEST1.1.1.1192.168.2.40x1e6cNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                May 8, 2024 13:49:29.181971073 CEST1.1.1.1192.168.2.40x8693No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:49:29.181971073 CEST1.1.1.1192.168.2.40x8693No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 13:49:42.534320116 CEST1.1.1.1192.168.2.40xd965No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:49:42.534320116 CEST1.1.1.1192.168.2.40xd965No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 13:50:05.728952885 CEST1.1.1.1192.168.2.40x6ae2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:50:05.728952885 CEST1.1.1.1192.168.2.40x6ae2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 13:50:25.761125088 CEST1.1.1.1192.168.2.40x20b3No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 13:50:25.761125088 CEST1.1.1.1192.168.2.40x20b3No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • www.dropbox.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449735162.125.1.184431704C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 11:49:15 UTC703OUTGET /l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY HTTP/1.1
                Host: www.dropbox.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-05-08 11:49:15 UTC3260INHTTP/1.1 200 OK
                Content-Type: image/jpeg
                Content-Security-Policy: base-uri 'self' ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; connect-src https://* ws://127.0.0.1:*/ws wss://dsimports.dropbox.com/ ; default-src 'none' ; font-src https://* data: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; frame-src https://* carousel: dbapi-6: dbap [TRUNCATED]
                Content-Security-Policy: report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-8/uuYI1kiPUbLXjT/H9O' 'nonce-jskYFZbvN4Ovui+CU8Yb'
                Referrer-Policy: strict-origin-when-cross-origin
                Set-Cookie: gvc=Nzc2OTMwMDY4NDY3ODA0NzIzNjU2MzM2NDAxNjcyMjUyNzAx; expires=Mon, 07 May 2029 11:49:15 GMT; HttpOnly; Path=/; SameSite=None; Secure
                Set-Cookie: t=baTzw7vjGg_mvZgRJdL6PS00; Domain=dropbox.com; expires=Thu, 08 May 2025 11:49:15 GMT; HttpOnly; Path=/; SameSite=None; Secure
                Set-Cookie: __Host-js_csrf=baTzw7vjGg_mvZgRJdL6PS00; expires=Thu, 08 May 2025 11:49:15 GMT; Path=/; SameSite=None; Secure
                Set-Cookie: __Host-ss=rnN5bSwxG8; expires=Thu, 08 May 2025 11:49:15 GMT; HttpOnly; Path=/; SameSite=Strict; Secure
                Set-Cookie: locale=en; Domain=dropbox.com; expires=Mon, 07 May 2029 11:49:15 GMT; Path=/; SameSite=None; Secure
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-Permitted-Cross-Domain-Policies: none
                X-Server-Response-Time: 11
                X-Xss-Protection: 1; mode=block
                Date: Wed, 08 May 2024 11:49:15 GMT
                Server: envoy
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Cache-Control: no-cache, no-store
                X-Dropbox-Response-Origin: far_remote
                X-Dropbox-Request-Id: fd71062ef76e4f08b72928bcb059b4f0
                Connection: close
                Transfer-Encoding: chunked
                2024-05-08 11:49:15 UTC643INData Raw: 32 37 37 0d 0a ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff db 00 43 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff c0 00 11 08 00 01 00 01 03 01 22 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14
                Data Ascii: 277JFIFCC"}!1AQa"q


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449736162.125.1.184431704C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 11:49:15 UTC795OUTGET /favicon.ico HTTP/1.1
                Host: www.dropbox.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: gvc=Nzc2OTMwMDY4NDY3ODA0NzIzNjU2MzM2NDAxNjcyMjUyNzAx; t=baTzw7vjGg_mvZgRJdL6PS00; __Host-js_csrf=baTzw7vjGg_mvZgRJdL6PS00; __Host-ss=rnN5bSwxG8; locale=en
                2024-05-08 11:49:16 UTC357INHTTP/1.1 404 Not Found
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Content-Length: 1233
                Content-Type: text/html
                Date: Wed, 08 May 2024 11:49:15 GMT
                Server: envoy
                Cache-Control: no-cache, no-store
                Vary: Accept-Encoding
                X-Dropbox-Response-Origin: remote
                X-Dropbox-Request-Id: 5c4795812ef8443ea46f434c80a2e6a5
                Connection: close
                2024-05-08 11:49:16 UTC1233INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 44 72 6f 70 62 6f 78 20 2d 20 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 66 6c 2e 64 72 6f 70 62 6f 78 73 74 61 74 69 63 2e 63 6f 6d 2f 73 74 61 74 69 63 2f 6d 65 74 61 73 65 72 76 65
                Data Ascii: <!DOCTYPE html><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Dropbox - 404</title><link href="https://cfl.dropboxstatic.com/static/metaserve


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974096.7.158.101443
                TimestampBytes transferredDirectionData
                2024-05-08 11:49:18 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-05-08 11:49:18 UTC466INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (sac/2518)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=69264
                Date: Wed, 08 May 2024 11:49:18 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974196.7.158.101443
                TimestampBytes transferredDirectionData
                2024-05-08 11:49:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-05-08 11:49:19 UTC534INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0gZGqYgAAAAALDuImPJT0QKVHnlugaXU1UERYMzFFREdFMDIxMgBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                Cache-Control: public, max-age=52726
                Date: Wed, 08 May 2024 11:49:19 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-05-08 11:49:19 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:13:49:07
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:13:49:10
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,15263746694786473811,17346230832487893663,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:13:49:13
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAPQGgT9oT3BaO4KfadYWH4kh89k=%20pGiSeY"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly