Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xr

Overview

General Information

Sample URL:http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZC
Analysis ID:1486308
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6924 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7108 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1948,i,13333502836302520572,3213506443915938383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lEbLKk9+w4Vok3f&MD=GHUHXZz+ HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lEbLKk9+w4Vok3f&MD=GHUHXZz+ HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary HTTP/1.1Host: drip.laConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary HTTP/1.1Host: drip.laConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: drip.la
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 01 Aug 2024 20:51:26 GMTContent-Length: 0Connection: keep-alive
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 01 Aug 2024 20:52:42 GMTContent-Length: 0Connection: keep-alive
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/6@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1948,i,13333502836302520572,3213506443915938383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1948,i,13333502836302520572,3213506443915938383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.68
truefalse
    unknown
    drip.la
    3.219.207.173
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summaryfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.68
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        52.44.152.28
        unknownUnited States
        14618AMAZON-AESUSfalse
        3.219.207.173
        drip.laUnited States
        14618AMAZON-AESUSfalse
        IP
        192.168.2.16
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1486308
        Start date and time:2024-08-01 22:51:01 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 19s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:defaultwindowsinteractivecookbook.jbs
        Sample URL:http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:14
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@16/6@6/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.250.185.78, 64.233.167.84, 34.104.35.123, 199.232.210.172, 172.217.18.99, 216.58.212.174
        • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 19:51:27 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2673
        Entropy (8bit):3.9764511242722107
        Encrypted:false
        SSDEEP:48:8UdsTQ8DHxidAKZdA1FehwiZUklqehBy+3:8znvuy
        MD5:05CB5002B076DDE126397AEBD13E0476
        SHA1:D5FAA065744C6BF38F52409D08FCEC643A522077
        SHA-256:AEEDC0E20F75EB29A1D5387C2B00F7B03250F5FAA2049EB976206E0C2BAF1BCC
        SHA-512:748AAFA594C86E400F09BBB8728D61B4319605A4D2E5B4FB728B8503DE5C3802B52335D2EBB98F6EF95901A358B4E2118AF1F70BE290E54EEA96560A7D0362A8
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,....p5U.T...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yn............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 19:51:27 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2675
        Entropy (8bit):3.994406609820666
        Encrypted:false
        SSDEEP:48:8UdsTQ8DHxidAKZdA1seh/iZUkAQkqehey+2:8znZ9QHy
        MD5:FE69D474734079A22F6B3A79B78AC887
        SHA1:64FC0C088F7F2083967146AC0C48D268FDD82DCC
        SHA-256:D93498F924FC4C110F24A03B8AEDA2AA9683C7FE1C3FB3A3E4611C18F6407961
        SHA-512:89CCCEE0EC8FE10B851D251E173384097A960ACCCBE0A147A6555C6B68F1AFE04F658827E3B270526C5E6C174D56E6F97DFA7A5246BBC87BCBAB495E093C9D43
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....NI.T...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yn............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2689
        Entropy (8bit):4.003457843730548
        Encrypted:false
        SSDEEP:48:8CdsTQ8AHxidAKZdA14meh7sFiZUkmgqeh7sEy+BX:8tn8nCy
        MD5:928D6EA9BAE88535D0308CBFFD7E23E8
        SHA1:D3558403B1F4C8ACF2F56D605BA19D3DCA5A5F9E
        SHA-256:E3E501F38DDBB4286DD22E6E224268B37C06A75206D5BBDA90BC464350B9560D
        SHA-512:0694A79D6789BC60F9700627F771D5955B8030691FD9FCFA075340EB7AAC245E84CA25A1E7BEAFEEAB9DEDD9E305B3D24AC8B04C9272D0F61D47C0257587B4C1
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 19:51:27 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2677
        Entropy (8bit):3.9921784804375777
        Encrypted:false
        SSDEEP:48:8xdsTQ8DHxidAKZdA1TehDiZUkwqeh6y+R:8AnKcy
        MD5:FC3E9E5D287136BF4841CDB768ED640E
        SHA1:340A3BFB728A2DAA71510F32C8C27E04682820ED
        SHA-256:58831FEC68520BD46D12CAA1935453E4F49A54ABF4D8E4410E865EBAD441F754
        SHA-512:8F4519B12F5C965BCDFE6B0F7FD287D0310AFB55E1EB28AB3CB2C77D7E5744B1C9984C3D3297C3C0CA1214DA0A02C7DB383247AD20120AD6BA58AC7A7181DE2E
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,....A.C.T...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yn............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 19:51:27 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2677
        Entropy (8bit):3.979917854047306
        Encrypted:false
        SSDEEP:48:8PWdsTQ8DHxidAKZdA1dehBiZUk1W1qehYy+C:8PRnK94y
        MD5:5D6DF5DD9F6D12F478F2C725A261F07D
        SHA1:DB6DE826A738F63EE44200A76FE5FADA5F4E3EF1
        SHA-256:BEDA5F94026B6790EEE9B87D598BEBCB75F5CCB4504D618C74FB3C6A00DFA32D
        SHA-512:E45FA27650EC9409D2A8AA742F030A89D615FF12EAE3AD15798471C836ADFA733169CB4FEE597F904D3610E54895F3DC418655B66354A8A38D1A1BF62C1D044E
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....iO.T...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yn............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 19:51:27 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
        Category:dropped
        Size (bytes):2679
        Entropy (8bit):3.9897247173631305
        Encrypted:false
        SSDEEP:48:8d6dsTQ8DHxidAKZdA1duTeehOuTbbiZUk5OjqehOuTbCy+yT+:8dVnATfTbxWOvTbCy7T
        MD5:8C1543148D3712A708B88EAFAD933D5F
        SHA1:19F150FCFF0058D6DBF8972DBD8B03C716F8AF40
        SHA-256:C9401EDDD84CEA614CCE1EFC0527B4A1F8958F34A72EA3F08CE5620AC275CCA6
        SHA-512:0327E8D9E6D4C58FA18A0FC797F350C0232FF9AC8FF11E75448BCCB8121E23A83ADFAA094B792FB549E5A7F45E3ECCFFE8176C911C867BD1C65AC4A46ACC7AEC
        Malicious:false
        Reputation:low
        Preview:L..................F.@.. ...$+.,.....3:.T...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yf.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Ym.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Ym.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Ym............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yn............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............d.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Aug 1, 2024 22:51:26.106645107 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.108287096 CEST4970180192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.111588955 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:51:26.111926079 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.113518953 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.113751888 CEST80497013.219.207.173192.168.2.16
        Aug 1, 2024 22:51:26.113835096 CEST4970180192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.118314981 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:51:26.436079979 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:26.621368885 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:51:26.675133944 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:51:26.738653898 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:27.344652891 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:28.551681042 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:29.127824068 CEST4968980192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:30.917865038 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:30.917933941 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:30.918004036 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:30.918241978 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:30.918258905 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:30.956662893 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:31.610277891 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:31.610589027 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:31.610605955 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:31.612035990 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:31.612126112 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:31.613265991 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:31.613348961 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:31.658647060 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:31.658657074 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:31.706666946 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:32.671495914 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:32.671557903 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:32.671654940 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:32.673178911 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:32.673197031 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.377839088 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.378032923 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.383601904 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.383616924 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.384082079 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.419934034 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.464499950 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.648871899 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.649059057 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.649070024 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.649075985 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.649125099 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.649137020 CEST49709443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.649162054 CEST44349709184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.690037966 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.690083981 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:33.690171003 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.690447092 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:33.690464020 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.496181011 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.496274948 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.497590065 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.497605085 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.497834921 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.498871088 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.544523954 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.596935987 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:34.780981064 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.781146049 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.781255960 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.781948090 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.781968117 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.782006025 CEST49710443192.168.2.16184.28.90.27
        Aug 1, 2024 22:51:34.782013893 CEST44349710184.28.90.27192.168.2.16
        Aug 1, 2024 22:51:34.899863005 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:35.502825975 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:35.758675098 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:36.710680962 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:39.069978952 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:39.117716074 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:39.373806953 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:39.983712912 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:40.050637007 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.050669909 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:40.050775051 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.052478075 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.052495956 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:40.799767017 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:40.799860001 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.803745985 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.803760052 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:40.804183960 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:40.854691029 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.864186049 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:40.904556990 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104281902 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104336977 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104357004 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104394913 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104449987 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104501009 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.104513884 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104531050 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104537964 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.104582071 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.104588985 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104613066 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.104690075 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.104721069 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104835987 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.104892015 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.116697073 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.116722107 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.116734982 CEST49711443192.168.2.1652.165.165.26
        Aug 1, 2024 22:51:41.116741896 CEST4434971152.165.165.26192.168.2.16
        Aug 1, 2024 22:51:41.189698935 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:41.508843899 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:41.508908987 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:41.509000063 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:42.294593096 CEST49708443192.168.2.16142.250.185.68
        Aug 1, 2024 22:51:42.294629097 CEST44349708142.250.185.68192.168.2.16
        Aug 1, 2024 22:51:43.593686104 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:43.929749012 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:45.364835024 CEST49673443192.168.2.16204.79.197.203
        Aug 1, 2024 22:51:48.397733927 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:51:53.543694019 CEST49678443192.168.2.1620.189.173.10
        Aug 1, 2024 22:51:58.002789974 CEST4968080192.168.2.16192.229.211.108
        Aug 1, 2024 22:52:11.115761042 CEST4970180192.168.2.163.219.207.173
        Aug 1, 2024 22:52:11.120836020 CEST80497013.219.207.173192.168.2.16
        Aug 1, 2024 22:52:11.628829956 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:52:11.633874893 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:52:17.502824068 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:17.502887011 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:17.503118038 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:17.503456116 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:17.503477097 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.249650002 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.249834061 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.251564026 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.251571894 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.252062082 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.253945112 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.300510883 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.517767906 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.517823935 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.517864943 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.517978907 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.518007994 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.518074036 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.518811941 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.518897057 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.518907070 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.518932104 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.518975019 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.519073009 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.519134998 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.521553040 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.521569967 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:18.521596909 CEST49712443192.168.2.1652.165.165.26
        Aug 1, 2024 22:52:18.521601915 CEST4434971252.165.165.26192.168.2.16
        Aug 1, 2024 22:52:26.298360109 CEST4970180192.168.2.163.219.207.173
        Aug 1, 2024 22:52:26.305046082 CEST80497013.219.207.173192.168.2.16
        Aug 1, 2024 22:52:26.305203915 CEST4970180192.168.2.163.219.207.173
        Aug 1, 2024 22:52:26.666536093 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:52:26.666703939 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:52:28.308588028 CEST4970080192.168.2.163.219.207.173
        Aug 1, 2024 22:52:28.313797951 CEST80497003.219.207.173192.168.2.16
        Aug 1, 2024 22:52:30.964138985 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:30.964190006 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:30.964296103 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:30.964693069 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:30.964726925 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:31.620105982 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:31.620661974 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:31.620723009 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:31.621198893 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:31.621828079 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:31.621947050 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:31.667720079 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:41.542717934 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:41.542813063 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:41.542896032 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:42.296840906 CEST49714443192.168.2.16142.250.185.68
        Aug 1, 2024 22:52:42.296917915 CEST44349714142.250.185.68192.168.2.16
        Aug 1, 2024 22:52:42.419504881 CEST4971580192.168.2.1652.44.152.28
        Aug 1, 2024 22:52:42.419966936 CEST4971680192.168.2.1652.44.152.28
        Aug 1, 2024 22:52:42.427244902 CEST804971552.44.152.28192.168.2.16
        Aug 1, 2024 22:52:42.427352905 CEST4971580192.168.2.1652.44.152.28
        Aug 1, 2024 22:52:42.427550077 CEST4971580192.168.2.1652.44.152.28
        Aug 1, 2024 22:52:42.427719116 CEST804971652.44.152.28192.168.2.16
        Aug 1, 2024 22:52:42.427783966 CEST4971680192.168.2.1652.44.152.28
        Aug 1, 2024 22:52:42.432670116 CEST804971552.44.152.28192.168.2.16
        Aug 1, 2024 22:52:42.927288055 CEST804971552.44.152.28192.168.2.16
        Aug 1, 2024 22:52:42.972618103 CEST4971580192.168.2.1652.44.152.28
        Aug 1, 2024 22:53:27.433646917 CEST4971680192.168.2.1652.44.152.28
        Aug 1, 2024 22:53:27.438860893 CEST804971652.44.152.28192.168.2.16
        Aug 1, 2024 22:53:27.928641081 CEST4971580192.168.2.1652.44.152.28
        Aug 1, 2024 22:53:27.934685946 CEST804971552.44.152.28192.168.2.16
        TimestampSource PortDest PortSource IPDest IP
        Aug 1, 2024 22:51:26.081985950 CEST53500611.1.1.1192.168.2.16
        Aug 1, 2024 22:51:26.089921951 CEST5727653192.168.2.161.1.1.1
        Aug 1, 2024 22:51:26.090044022 CEST5594453192.168.2.161.1.1.1
        Aug 1, 2024 22:51:26.100274086 CEST53559441.1.1.1192.168.2.16
        Aug 1, 2024 22:51:26.102416992 CEST53621371.1.1.1192.168.2.16
        Aug 1, 2024 22:51:26.103507996 CEST53572761.1.1.1192.168.2.16
        Aug 1, 2024 22:51:27.123971939 CEST53574441.1.1.1192.168.2.16
        Aug 1, 2024 22:51:30.909452915 CEST5274053192.168.2.161.1.1.1
        Aug 1, 2024 22:51:30.909595013 CEST5949653192.168.2.161.1.1.1
        Aug 1, 2024 22:51:30.916759014 CEST53594961.1.1.1192.168.2.16
        Aug 1, 2024 22:51:30.917040110 CEST53527401.1.1.1192.168.2.16
        Aug 1, 2024 22:51:44.067306995 CEST53516451.1.1.1192.168.2.16
        Aug 1, 2024 22:52:03.097112894 CEST53615321.1.1.1192.168.2.16
        Aug 1, 2024 22:52:26.049906969 CEST53504751.1.1.1192.168.2.16
        Aug 1, 2024 22:52:26.083473921 CEST53503861.1.1.1192.168.2.16
        Aug 1, 2024 22:52:30.779551029 CEST138138192.168.2.16192.168.2.255
        Aug 1, 2024 22:52:42.393619061 CEST5483353192.168.2.161.1.1.1
        Aug 1, 2024 22:52:42.394114017 CEST5172253192.168.2.161.1.1.1
        Aug 1, 2024 22:52:42.408169985 CEST53548331.1.1.1192.168.2.16
        Aug 1, 2024 22:52:42.458257914 CEST53517221.1.1.1192.168.2.16
        Aug 1, 2024 22:52:55.459942102 CEST53549871.1.1.1192.168.2.16
        Aug 1, 2024 22:52:55.464869022 CEST53531471.1.1.1192.168.2.16
        TimestampSource IPDest IPChecksumCodeType
        Aug 1, 2024 22:52:42.458393097 CEST192.168.2.161.1.1.1c23d(Port unreachable)Destination Unreachable
        Aug 1, 2024 22:52:55.465128899 CEST192.168.2.161.1.1.1c22d(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Aug 1, 2024 22:51:26.089921951 CEST192.168.2.161.1.1.10x92afStandard query (0)drip.laA (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:26.090044022 CEST192.168.2.161.1.1.10x5c0dStandard query (0)drip.la65IN (0x0001)false
        Aug 1, 2024 22:51:30.909452915 CEST192.168.2.161.1.1.10x9e48Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:30.909595013 CEST192.168.2.161.1.1.10x86bStandard query (0)www.google.com65IN (0x0001)false
        Aug 1, 2024 22:52:42.393619061 CEST192.168.2.161.1.1.10x87bStandard query (0)drip.laA (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.394114017 CEST192.168.2.161.1.1.10x8047Standard query (0)drip.la65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Aug 1, 2024 22:51:26.103507996 CEST1.1.1.1192.168.2.160x92afNo error (0)drip.la3.219.207.173A (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:26.103507996 CEST1.1.1.1192.168.2.160x92afNo error (0)drip.la52.44.152.28A (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:26.103507996 CEST1.1.1.1192.168.2.160x92afNo error (0)drip.la35.171.111.24A (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:26.103507996 CEST1.1.1.1192.168.2.160x92afNo error (0)drip.la52.0.1.196A (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:26.103507996 CEST1.1.1.1192.168.2.160x92afNo error (0)drip.la3.226.93.59A (IP address)IN (0x0001)false
        Aug 1, 2024 22:51:30.916759014 CEST1.1.1.1192.168.2.160x86bNo error (0)www.google.com65IN (0x0001)false
        Aug 1, 2024 22:51:30.917040110 CEST1.1.1.1192.168.2.160x9e48No error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.408169985 CEST1.1.1.1192.168.2.160x87bNo error (0)drip.la52.44.152.28A (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.408169985 CEST1.1.1.1192.168.2.160x87bNo error (0)drip.la3.226.93.59A (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.408169985 CEST1.1.1.1192.168.2.160x87bNo error (0)drip.la3.219.207.173A (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.408169985 CEST1.1.1.1192.168.2.160x87bNo error (0)drip.la52.0.1.196A (IP address)IN (0x0001)false
        Aug 1, 2024 22:52:42.408169985 CEST1.1.1.1192.168.2.160x87bNo error (0)drip.la35.171.111.24A (IP address)IN (0x0001)false
        • fs.microsoft.com
        • slscr.update.microsoft.com
        • drip.la
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.16497003.219.207.173807108C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 1, 2024 22:51:26.113518953 CEST764OUTGET /c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary HTTP/1.1
        Host: drip.la
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Aug 1, 2024 22:51:26.621368885 CEST106INHTTP/1.1 404 Not Found
        Date: Thu, 01 Aug 2024 20:51:26 GMT
        Content-Length: 0
        Connection: keep-alive
        Aug 1, 2024 22:52:11.628829956 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.16497013.219.207.173807108C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 1, 2024 22:52:11.115761042 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.164971552.44.152.28807108C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 1, 2024 22:52:42.427550077 CEST790OUTGET /c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary HTTP/1.1
        Host: drip.la
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Aug 1, 2024 22:52:42.927288055 CEST106INHTTP/1.1 404 Not Found
        Date: Thu, 01 Aug 2024 20:52:42 GMT
        Content-Length: 0
        Connection: keep-alive
        Aug 1, 2024 22:53:27.928641081 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.164971652.44.152.28807108C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Aug 1, 2024 22:53:27.433646917 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.1649709184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-08-01 20:51:33 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-08-01 20:51:33 UTC468INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/0712)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus2-z1
        Cache-Control: public, max-age=209520
        Date: Thu, 01 Aug 2024 20:51:33 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.1649710184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-08-01 20:51:34 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-08-01 20:51:34 UTC515INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-weu-z1
        Cache-Control: public, max-age=209449
        Date: Thu, 01 Aug 2024 20:51:34 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-08-01 20:51:34 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.164971152.165.165.26443
        TimestampBytes transferredDirectionData
        2024-08-01 20:51:40 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lEbLKk9+w4Vok3f&MD=GHUHXZz+ HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
        Host: slscr.update.microsoft.com
        2024-08-01 20:51:41 UTC560INHTTP/1.1 200 OK
        Cache-Control: no-cache
        Pragma: no-cache
        Content-Type: application/octet-stream
        Expires: -1
        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
        ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
        MS-CorrelationId: bbba66ce-1978-4f93-93ff-605964e9e7b8
        MS-RequestId: 20fb6e1a-3298-46de-b5a4-5d36b43b3426
        MS-CV: G4g2tG/d6kiupaKF.0
        X-Microsoft-SLSClientCache: 2880
        Content-Disposition: attachment; filename=environment.cab
        X-Content-Type-Options: nosniff
        Date: Thu, 01 Aug 2024 20:51:40 GMT
        Connection: close
        Content-Length: 24490
        2024-08-01 20:51:41 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
        Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
        2024-08-01 20:51:41 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
        Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.164971252.165.165.26443
        TimestampBytes transferredDirectionData
        2024-08-01 20:52:18 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lEbLKk9+w4Vok3f&MD=GHUHXZz+ HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
        Host: slscr.update.microsoft.com
        2024-08-01 20:52:18 UTC560INHTTP/1.1 200 OK
        Cache-Control: no-cache
        Pragma: no-cache
        Content-Type: application/octet-stream
        Expires: -1
        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
        ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
        MS-CorrelationId: 2329f1f0-ec49-44d9-bde9-6cd9332ddea6
        MS-RequestId: a7d8e580-2828-4f4a-86d3-f01626bf89b1
        MS-CV: IRywBehb90KyPSxz.0
        X-Microsoft-SLSClientCache: 1440
        Content-Disposition: attachment; filename=environment.cab
        X-Content-Type-Options: nosniff
        Date: Thu, 01 Aug 2024 20:52:18 GMT
        Connection: close
        Content-Length: 30005
        2024-08-01 20:52:18 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
        Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
        2024-08-01 20:52:18 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
        Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:16:51:24
        Start date:01/08/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://drip.la/c/eyJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJkZXRvdXIiLCJpc3MiOiJtb25vbGl0aCIsInN1YiI6ImRldG91cl9saW5rIiwiaWF0IjoxNzIyMjg3Mzk4LCJuYmYiOjE3MjIyODczOTgsImFjY291bnRfaWQiOiIxNTQ3NjIzIiwidHJpZ2dlcl9pZCI6Ijg2NjcyOTg0NiIsImR5bmFtaWNfdXJsIjpudWxsLCJ1cmwiOiJodHRwOi8vc2hhbXZhZ29sZG1pbmUuY28uencvcmVkIn0.xrF3BcMcrAEXv980Abar-Yakj_pPuvmXyCnSKqoV5Sw%20URL%20summary
        Imagebase:0x7ff7f9810000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:1
        Start time:16:51:25
        Start date:01/08/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1948,i,13333502836302520572,3213506443915938383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff7f9810000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        No disassembly