Edit tour

Windows Analysis Report
http://x1.c.lencr.org

Overview

General Information

Sample URL:http://x1.c.lencr.org
Analysis ID:1330823
Infos:

Detection

Score:20
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Suspicious execution chain found
Creates files inside the system directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3492 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1948,i,1731013787910947869,11687859397111007845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • rundll32.exe (PID: 7104 cmdline: "C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCRL C:\Users\user\Downloads\download.crl MD5: EF3179D498793BF4234F708D3BE28633)
  • chrome.exe (PID: 6488 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x1.c.lencr.org MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: unknownHTTPS traffic detected: 23.52.160.85:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.52.160.85:443 -> 192.168.2.4:49748 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49751 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeChild: C:\Windows\System32\rundll32.exe
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 23.52.160.85
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wCskAv7S2rcV2uB&MD=8nW1lFUt HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wCskAv7S2rcV2uB&MD=8nW1lFUt HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk; 1P_JAR=2023-10-04-09
Source: unknownHTTPS traffic detected: 23.52.160.85:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.52.160.85:443 -> 192.168.2.4:49748 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49751 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_3492_51038637Jump to behavior
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: classification engineClassification label: sus20.expl.win@19/3@8/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCRL C:\Users\user\Downloads\download.crl
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1948,i,1731013787910947869,11687859397111007845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x1.c.lencr.org
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCRL C:\Users\user\Downloads\download.crl
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1948,i,1731013787910947869,11687859397111007845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCRL C:\Users\user\Downloads\download.crlJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\2e83a915-bbbf-4ba2-b516-f7c8a71e02dd.tmpJump to behavior
Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\system32\msftedit.dllJump to behavior
Source: C:\Windows\System32\rundll32.exeWindow found: window name: SysTabControl32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Exploitation for Client Execution
Path Interception1
Process Injection
11
Masquerading
OS Credential Dumping1
System Information Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Rundll32
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1330823 URL: http://x1.c.lencr.org Startdate: 23/10/2023 Architecture: WINDOWS Score: 20 28 Suspicious execution chain found 2->28 6 chrome.exe 13 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.4, 138, 443, 49723 unknown unknown 6->16 18 192.168.2.7 unknown unknown 6->18 20 3 other IPs or domains 6->20 11 chrome.exe 6->11         started        14 rundll32.exe 6->14         started        process5 dnsIp6 22 www.google.com 172.253.115.105, 443, 49746, 49753 GOOGLEUS United States 11->22 24 accounts.google.com 172.253.62.84, 443, 49738 GOOGLEUS United States 11->24 26 3 other IPs or domains 11->26

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://x1.c.lencr.org0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.253.62.84
truefalse
    high
    www.google.com
    172.253.115.105
    truefalse
      high
      clients.l.google.com
      172.253.63.100
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          x1.c.lencr.org
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.253.115.105
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                172.253.62.84
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                172.253.63.100
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.8
                192.168.2.7
                192.168.2.9
                192.168.2.4
                Joe Sandbox Version:38.0.0 Ammolite
                Analysis ID:1330823
                Start date and time:2023-10-23 22:05:05 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 3m 5s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://x1.c.lencr.org
                Analysis system description:Windows 10 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:11
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:SUS
                Classification:sus20.expl.win@19/3@8/8
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.251.16.94, 34.104.35.123, 104.108.107.41, 192.229.211.108
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, e8652.dscx.akamaiedge.net, ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, crl.root-x1.letsencrypt.org.edgekey.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                • VT rate limit hit for: http://x1.c.lencr.org
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:dropped
                Size (bytes):717
                Entropy (8bit):7.5050705422409765
                Encrypted:false
                SSDEEP:12:mmSc27TqU0YW/FQgCYTpZf0ZqAZvQqdVleICckto0G+4jR6qmgOGErkoLHj:YXfimgCYTpZfKtZvQuCcktoJ3OGe3rj
                MD5:60FE01DF86BE2E5331B0CDBE86165686
                SHA1:2A79F9713C3F192862FF80508062E64E8E0B29BD
                SHA-256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
                SHA-512:EF9F9A4DEDCBFE339F4F3D07FB614645596C6F2B15608BDCCDAD492578B735F7CB075BDAA07178C764582EE345857EC4665F90342694E6A60786BB3D9B3A3D23
                Malicious:false
                Reputation:low
                Preview:0...0.....0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X1..230411000000Z..240311235959Z./0-0...U.#..0...y.Y.{....s.....X..n0...U......g0...*.H.......................PA..........Z..U.i&=...1\_..ZN.7.,..2.8.R.j`.{...;S..}.26...`.9.Gr....Sv...F.G.0.,5.$.Z).3.r..#..B}.=m}..q1./#\7vu44y/...o=aHkK......3I.ID..Dy...1.4.$c.3....+e..}..(z.:R0.-.53...y<.......b..V!..4.j.m....V......<[...-S..D.jn...(.d7.........K0..y=9oF..A.<...6C+;.-Cd_.o=.Tt.xX.!.4.D!J..(....v.1w.*].p....6..L&..)..eoP..8.h..K...ai...,......1... ....]AC..(.4.oX...;u)2uc..*~.@.K....._y5Y. .T.X3...D.......'.].E..:l../..Q9.Sc. ....3.qf...s...-.^G..{..C.@&38.K..XvW.2..... .w.4....K.X3.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:dropped
                Size (bytes):717
                Entropy (8bit):7.5050705422409765
                Encrypted:false
                SSDEEP:12:mmSc27TqU0YW/FQgCYTpZf0ZqAZvQqdVleICckto0G+4jR6qmgOGErkoLHj:YXfimgCYTpZfKtZvQuCcktoJ3OGe3rj
                MD5:60FE01DF86BE2E5331B0CDBE86165686
                SHA1:2A79F9713C3F192862FF80508062E64E8E0B29BD
                SHA-256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
                SHA-512:EF9F9A4DEDCBFE339F4F3D07FB614645596C6F2B15608BDCCDAD492578B735F7CB075BDAA07178C764582EE345857EC4665F90342694E6A60786BB3D9B3A3D23
                Malicious:false
                Reputation:low
                Preview:0...0.....0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X1..230411000000Z..240311235959Z./0-0...U.#..0...y.Y.{....s.....X..n0...U......g0...*.H.......................PA..........Z..U.i&=...1\_..ZN.7.,..2.8.R.j`.{...;S..}.26...`.9.Gr....Sv...F.G.0.,5.$.Z).3.r..#..B}.=m}..q1./#\7vu44y/...o=aHkK......3I.ID..Dy...1.4.$c.3....+e..}..(z.:R0.-.53...y<.......b..V!..4.j.m....V......<[...-S..D.jn...(.d7.........K0..y=9oF..A.<...6C+;.-Cd_.o=.Tt.xX.!.4.D!J..(....v.1w.*].p....6..L&..)..eoP..8.h..K...ai...,......1... ....]AC..(.4.oX...;u)2uc..*~.@.K....._y5Y. .T.X3...D.......'.].E..:l../..Q9.Sc. ....3.qf...s...-.^G..{..C.@&38.K..XvW.2..... .w.4....K.X3.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 717
                Category:downloaded
                Size (bytes):738
                Entropy (8bit):7.674122582943747
                Encrypted:false
                SSDEEP:12:XgM4BY+/H3+3SauRoQffkyFxPKJMguXgyqmM1qhNMerekIp4/eQmHG7yl1:XgMeY+/OFKoCjPKyUhmMANMetA3N31
                MD5:1445914CF81596B8601950AF3317BBE4
                SHA1:CDB9E75488A6111B591873C14419B8836A48DBBF
                SHA-256:5A59FB3D743DD245EE7F0C8FEDF45BF7764EBBD20E32DC631232DC6AFABAA0E7
                SHA-512:8C705E373403150D2F5332CCE3B5CC21FA20831CF685C8E4D5B9D3F10AD8BC59BB38EA940BE1F564B0D4B742BBDC4074D2EB60D5C230EBE951B5B42D074409FC
                Malicious:false
                Reputation:low
                URL:http://x1.c.lencr.org/
                Preview:..........3hb:i.......S...;/##7+...!..'.s(..0Sh....:..%...W.Z..Z....\Z.YR...Z..X....^._Z`(j .R.,........_..a(.kdl`bhh..Q@...........e..}.].y.6Ye.......-...=}.X...qB*....y.\ .",.L..h.enbbdh.o..(......_..fp.;......gB_f.......0&.E .o../...F[,>.m.J.X...>Y..>...Ff..r-I.d..^te.#...2.W.n.mt.j0Y.t..(M!.E./*..w.....$WhxR_9....R_p..|.D.l.#....:3..s.......S.>7.j.P%..4c...]...k....`.d....].u....SY9E.OI:......#...G.\....^?...6.....3.uY...2.YC>.|5.4....y..}Zik..ve.&.c6..>.9k[..uN.o.].R.Z..\q....E..74.x.J.]2,....Y0..U....}...d.<u95?`.L..../.O=~...LD...............1...............F..\...;......x|.i.a..!.#.w...L...S..".).|..Z.r$.....h978y..\.._.o..fq.,..{.{3.}Yg..nvg..5c.=._NE.......z.t......&.Z..{o.0...........
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 105
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Oct 23, 2023 22:05:55.357923985 CEST49675443192.168.2.4173.222.162.32
                Oct 23, 2023 22:06:05.390516996 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.390564919 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.390631914 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.391330004 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.391345024 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.391766071 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.391813040 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.391877890 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.392050028 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.392066002 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.638258934 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.638358116 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.638942957 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.638958931 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.639060020 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.639076948 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.639499903 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.639581919 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.640942097 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.640975952 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.641019106 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.641105890 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.642162085 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.642252922 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.642416000 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.642426014 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.642539024 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.642630100 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.642750978 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.685033083 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.686460018 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.747551918 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.747575998 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.834645033 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.835092068 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.835155964 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.835391998 CEST49737443192.168.2.4172.253.63.100
                Oct 23, 2023 22:06:05.835413933 CEST44349737172.253.63.100192.168.2.4
                Oct 23, 2023 22:06:05.859751940 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.859857082 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.859890938 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.859999895 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:05.860049963 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.860838890 CEST49738443192.168.2.4172.253.62.84
                Oct 23, 2023 22:06:05.860856056 CEST44349738172.253.62.84192.168.2.4
                Oct 23, 2023 22:06:09.345350027 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.345387936 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.345475912 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.345952988 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.345966101 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.559221983 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.571367979 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.571398020 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.573112965 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.573230982 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.575139046 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.575242043 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.622364044 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:09.622379065 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:09.669050932 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:10.150435925 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.150474072 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.150566101 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.161700010 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.161716938 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.514583111 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.514717102 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.543853998 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.543890953 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.544907093 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.607007980 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.625962973 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.666455030 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.833631039 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.833713055 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.833797932 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.833915949 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.833940029 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.833954096 CEST49747443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.833961964 CEST4434974723.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.894701958 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.894747972 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:10.894839048 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.895518064 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:10.895534039 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.224450111 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.224561930 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.229607105 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.229617119 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.229962111 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.231729031 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.278453112 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.544075012 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.544146061 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.544250011 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.547725916 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.547749996 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:11.547790051 CEST49748443192.168.2.423.52.160.85
                Oct 23, 2023 22:06:11.547799110 CEST4434974823.52.160.85192.168.2.4
                Oct 23, 2023 22:06:19.309942007 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:19.310010910 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:19.310113907 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:19.313771009 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:19.313796997 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:19.555176020 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:19.555335999 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:19.555402040 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:19.879440069 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:19.879539013 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:19.882385969 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:19.882415056 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:19.882838011 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:19.934969902 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.025887966 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.066462040 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412750959 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412813902 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412832975 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412851095 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412889004 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412908077 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.412950039 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.413009882 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.413032055 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.413065910 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.413115978 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.413187981 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.413207054 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.413326025 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.413383961 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.439491034 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.439522028 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:20.439538956 CEST49749443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:20.439548016 CEST4434974940.68.123.157192.168.2.4
                Oct 23, 2023 22:06:21.485707045 CEST49746443192.168.2.4172.253.115.105
                Oct 23, 2023 22:06:21.485728025 CEST44349746172.253.115.105192.168.2.4
                Oct 23, 2023 22:06:50.314038992 CEST49732443192.168.2.4204.79.197.200
                Oct 23, 2023 22:06:57.005323887 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.005372047 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:57.005439043 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.007112026 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.007132053 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:57.565066099 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:57.565218925 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.567434072 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.567442894 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:57.567910910 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:57.570175886 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:57.610476017 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.099862099 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.099931002 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.099975109 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100012064 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.100039959 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100075006 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.100083113 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.100300074 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100354910 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100373030 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.100377083 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100415945 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.100423098 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100498915 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.100548029 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.105109930 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.105127096 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:06:58.105160952 CEST49751443192.168.2.440.68.123.157
                Oct 23, 2023 22:06:58.105166912 CEST4434975140.68.123.157192.168.2.4
                Oct 23, 2023 22:07:06.966346979 CEST4972380192.168.2.472.21.81.240
                Oct 23, 2023 22:07:06.966465950 CEST4972480192.168.2.472.21.81.240
                Oct 23, 2023 22:07:06.966547012 CEST4973180192.168.2.472.21.81.240
                Oct 23, 2023 22:07:06.966665030 CEST4973580192.168.2.472.21.81.240
                Oct 23, 2023 22:07:07.059173107 CEST804972372.21.81.240192.168.2.4
                Oct 23, 2023 22:07:07.059431076 CEST4972380192.168.2.472.21.81.240
                Oct 23, 2023 22:07:07.059487104 CEST804972472.21.81.240192.168.2.4
                Oct 23, 2023 22:07:07.059541941 CEST4972480192.168.2.472.21.81.240
                Oct 23, 2023 22:07:07.059809923 CEST804973572.21.81.240192.168.2.4
                Oct 23, 2023 22:07:07.059878111 CEST4973580192.168.2.472.21.81.240
                Oct 23, 2023 22:07:07.060751915 CEST804973172.21.81.240192.168.2.4
                Oct 23, 2023 22:07:07.060806990 CEST4973180192.168.2.472.21.81.240
                Oct 23, 2023 22:07:09.311897039 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:09.311949968 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.312057018 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:09.312525034 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:09.312541008 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.536962032 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.537307024 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:09.537353039 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.538060904 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.538491011 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:09.538589954 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:09.577860117 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:19.526343107 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:19.526508093 CEST44349753172.253.115.105192.168.2.4
                Oct 23, 2023 22:07:19.526576996 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:21.469604969 CEST49753443192.168.2.4172.253.115.105
                Oct 23, 2023 22:07:21.469639063 CEST44349753172.253.115.105192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Oct 23, 2023 22:06:05.290811062 CEST5656753192.168.2.41.1.1.1
                Oct 23, 2023 22:06:05.293432951 CEST5556653192.168.2.41.1.1.1
                Oct 23, 2023 22:06:05.294219017 CEST5285053192.168.2.41.1.1.1
                Oct 23, 2023 22:06:05.295670986 CEST5653153192.168.2.41.1.1.1
                Oct 23, 2023 22:06:05.367764950 CEST53581361.1.1.1192.168.2.4
                Oct 23, 2023 22:06:05.385281086 CEST53565671.1.1.1192.168.2.4
                Oct 23, 2023 22:06:05.388209105 CEST53528501.1.1.1192.168.2.4
                Oct 23, 2023 22:06:05.388842106 CEST53555661.1.1.1192.168.2.4
                Oct 23, 2023 22:06:05.390383005 CEST53565311.1.1.1192.168.2.4
                Oct 23, 2023 22:06:05.979923964 CEST53651181.1.1.1192.168.2.4
                Oct 23, 2023 22:06:06.736990929 CEST5643653192.168.2.41.1.1.1
                Oct 23, 2023 22:06:06.737298012 CEST5199953192.168.2.41.1.1.1
                Oct 23, 2023 22:06:09.249569893 CEST5654953192.168.2.41.1.1.1
                Oct 23, 2023 22:06:09.249825954 CEST5278353192.168.2.41.1.1.1
                Oct 23, 2023 22:06:09.343574047 CEST53565491.1.1.1192.168.2.4
                Oct 23, 2023 22:06:09.344050884 CEST53527831.1.1.1192.168.2.4
                Oct 23, 2023 22:06:18.570867062 CEST138138192.168.2.4192.168.2.255
                Oct 23, 2023 22:06:23.094253063 CEST53507731.1.1.1192.168.2.4
                Oct 23, 2023 22:06:42.227381945 CEST53642461.1.1.1192.168.2.4
                Oct 23, 2023 22:07:04.763765097 CEST53563841.1.1.1192.168.2.4
                Oct 23, 2023 22:07:04.959487915 CEST53502251.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Oct 23, 2023 22:06:05.290811062 CEST192.168.2.41.1.1.10xef5eStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.293432951 CEST192.168.2.41.1.1.10x1bd5Standard query (0)clients2.google.com65IN (0x0001)false
                Oct 23, 2023 22:06:05.294219017 CEST192.168.2.41.1.1.10xe9fbStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.295670986 CEST192.168.2.41.1.1.10xdbe8Standard query (0)accounts.google.com65IN (0x0001)false
                Oct 23, 2023 22:06:06.736990929 CEST192.168.2.41.1.1.10xea3fStandard query (0)x1.c.lencr.orgA (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:06.737298012 CEST192.168.2.41.1.1.10xada7Standard query (0)x1.c.lencr.org65IN (0x0001)false
                Oct 23, 2023 22:06:09.249569893 CEST192.168.2.41.1.1.10xde25Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.249825954 CEST192.168.2.41.1.1.10xe394Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.100A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.101A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.113A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.102A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.138A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.385281086 CEST1.1.1.1192.168.2.40xef5eNo error (0)clients.l.google.com172.253.63.139A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.388209105 CEST1.1.1.1192.168.2.40xe9fbNo error (0)accounts.google.com172.253.62.84A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:05.388842106 CEST1.1.1.1192.168.2.40x1bd5No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Oct 23, 2023 22:06:06.832247972 CEST1.1.1.1192.168.2.40xea3fNo error (0)x1.c.lencr.orgcrl.root-x1.letsencrypt.org.edgekey.netCNAME (Canonical name)IN (0x0001)false
                Oct 23, 2023 22:06:06.841778040 CEST1.1.1.1192.168.2.40xada7No error (0)x1.c.lencr.orgcrl.root-x1.letsencrypt.org.edgekey.netCNAME (Canonical name)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.105A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.147A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.99A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.103A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.104A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.343574047 CEST1.1.1.1192.168.2.40xde25No error (0)www.google.com172.253.115.106A (IP address)IN (0x0001)false
                Oct 23, 2023 22:06:09.344050884 CEST1.1.1.1192.168.2.40xe394No error (0)www.google.com65IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • fs.microsoft.com
                • slscr.update.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.449737172.253.63.100443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:05 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-117.0.5938.132
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.449738172.253.62.84443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:05 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk; 1P_JAR=2023-10-04-09
                2023-10-23 20:06:05 UTC1OUTData Raw: 20
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2172.253.63.100443192.168.2.449737C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:05 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-ubrVPiFD5wfCj36HRzpH6w' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 23 Oct 2023 20:06:05 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6139
                X-Daystart: 47165
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-10-23 20:06:05 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 33 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 37 31 36 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6139" elapsed_seconds="47165"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2023-10-23 20:06:05 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2023-10-23 20:06:05 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3172.253.62.84443192.168.2.449738C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:05 UTC2INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 23 Oct 2023 20:06:05 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Cross-Origin-Opener-Policy: same-origin
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-EVk0NcpboNnHX1PoUi2pLQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-10-23 20:06:05 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2023-10-23 20:06:05 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                4192.168.2.44974723.52.160.85443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:10 UTC4OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2023-10-23 20:06:10 UTC4INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: Kestrel
                X-CID: 11
                Cache-Control: public, max-age=96410
                Date: Mon, 23 Oct 2023 20:06:10 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortProcess
                5192.168.2.44974823.52.160.85443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:11 UTC5OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2023-10-23 20:06:11 UTC5INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=122278
                Date: Mon, 23 Oct 2023 20:06:11 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2023-10-23 20:06:11 UTC5INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Session IDSource IPSource PortDestination IPDestination PortProcess
                6192.168.2.44974940.68.123.157443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:20 UTC5OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wCskAv7S2rcV2uB&MD=8nW1lFUt HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2023-10-23 20:06:20 UTC6INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                MS-CorrelationId: 193eda6f-a688-46e1-b7fb-551d738ceab2
                MS-RequestId: 38674fc7-cba4-4dc3-88ca-5e970e83e0b9
                MS-CV: /fZIActUfUOL0D2r.0
                X-Microsoft-SLSClientCache: 2880
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Mon, 23 Oct 2023 20:06:19 GMT
                Connection: close
                Content-Length: 24490
                2023-10-23 20:06:20 UTC6INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                2023-10-23 20:06:20 UTC22INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                Session IDSource IPSource PortDestination IPDestination PortProcess
                7192.168.2.44975140.68.123.157443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-10-23 20:06:57 UTC30OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wCskAv7S2rcV2uB&MD=8nW1lFUt HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2023-10-23 20:06:58 UTC30INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
                MS-CorrelationId: 2ffd496e-3913-48a7-b4b5-dbc02faf639f
                MS-RequestId: f33021e1-eba2-4d51-a439-4614afbdc15f
                MS-CV: xYmPPASwukSj26Mf.0
                X-Microsoft-SLSClientCache: 2160
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Mon, 23 Oct 2023 20:06:57 GMT
                Connection: close
                Content-Length: 25457
                2023-10-23 20:06:58 UTC31INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
                Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
                2023-10-23 20:06:58 UTC46INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
                Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:0
                Start time:22:05:59
                Start date:23/10/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:22:06:02
                Start date:23/10/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1948,i,1731013787910947869,11687859397111007845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:22:06:05
                Start date:23/10/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://x1.c.lencr.org
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                Target ID:4
                Start time:22:06:09
                Start date:23/10/2023
                Path:C:\Windows\System32\rundll32.exe
                Wow64 process (32bit):false
                Commandline:"C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCRL C:\Users\user\Downloads\download.crl
                Imagebase:0x7ff6a8a90000
                File size:71'680 bytes
                MD5 hash:EF3179D498793BF4234F708D3BE28633
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                No disassembly