Edit tour

Windows Analysis Report
http://149.154.167.41

Overview

General Information

Sample URL:http://149.154.167.41
Analysis ID:1393633
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files inside the system directory
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1440 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2204,i,7489064456424810634,7995094544846090831,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4128 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://149.154.167.41 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://149.154.167.41/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: unknownTCP traffic detected without corresponding DNS query: 149.154.167.41
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 149.154.167.41Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 149.154.167.41Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://149.154.167.41/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: keep-aliveContent-Type: text/htmlServer: nginx/0.3.33Date: Fri, 16 Feb 2024 18:21:58 GMTContent-Length: 169Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 30 2e 33 2e 33 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx/0.3.33</center></body></html>
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: keep-aliveContent-Type: text/htmlServer: nginx/0.3.33Date: Fri, 16 Feb 2024 18:21:58 GMTContent-Length: 169Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 30 2e 33 2e 33 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx/0.3.33</center></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1440_1753894391Jump to behavior
Source: classification engineClassification label: clean1.win@16/10@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2204,i,7489064456424810634,7995094544846090831,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://149.154.167.41
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2204,i,7489064456424810634,7995094544846090831,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1393633 URL: http://149.154.167.41 Startdate: 16/02/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 9 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49682, 49703 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 149.154.167.41, 49710, 49711, 80 TELEGRAMRU United Kingdom 10->17 19 accounts.google.com 142.250.31.84, 443, 49707 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://149.154.167.410%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://149.154.167.41/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.31.84
truefalse
    high
    www.google.com
    142.251.40.228
    truefalse
      high
      clients.l.google.com
      142.251.40.238
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          windowsupdatebg.s.llnwi.net
          69.164.46.0
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                high
                http://149.154.167.41/false
                  unknown
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    http://149.154.167.41/favicon.icofalse
                    • Avira URL Cloud: safe
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    149.154.167.41
                    unknownUnited Kingdom
                    62041TELEGRAMRUfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.251.40.238
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    142.251.40.228
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    142.250.31.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.5
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1393633
                    Start date and time:2024-02-16 19:21:01 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 13s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://149.154.167.41
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean1.win@16/10@6/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.80.67, 34.104.35.123, 40.68.123.157, 23.206.121.32, 192.229.211.108, 69.164.46.0, 20.242.39.171, 72.21.81.240, 13.85.23.206, 23.206.121.5, 23.206.121.13, 23.206.121.15, 23.206.121.7, 23.206.121.10, 23.206.121.11, 23.206.121.61, 23.206.121.60, 23.206.121.8, 142.250.65.227, 104.102.251.17, 104.102.251.80, 104.102.251.73, 23.206.121.35, 23.206.121.29, 23.206.121.28, 23.206.121.30, 23.206.121.27, 23.206.121.46, 23.206.121.34, 23.206.121.31
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenFile calls found.
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://149.154.167.41
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 16 17:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2677
                    Entropy (8bit):3.978058406552975
                    Encrypted:false
                    SSDEEP:48:8rj2dtOTNKqR8HOsidAKZdA19ehwiZUklqehBy+3:8rhPouy
                    MD5:B7D57AA9AD4EE0BDF4B31589F6444195
                    SHA1:FB3FEA974694E3BFFC03982C2326EAD80BC7D1DF
                    SHA-256:22AABFBAF037030E801ED01F2C5A2EB48DFF066F41380579B483883A62C46B0B
                    SHA-512:5E97B92393341B685F4B6890F7A1061AFF80FC3F887E3EAE713E72DE9C926DEFD9ADCF4F3FBA1DCCCB31C764CE8675727DA4740F73483BF7FD17D7C7403620E6
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,........a..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 16 17:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2679
                    Entropy (8bit):3.9934171356667725
                    Encrypted:false
                    SSDEEP:48:8i2dtOTNKqR8HOsidAKZdA1weh/iZUkAQkqehey+2:88Pi9QHy
                    MD5:675F18DEB808E491E302EF3B875EE214
                    SHA1:ACB180C23CABE169C8D76EFDAC0449249F1F41DC
                    SHA-256:565EE8A73D6D1317228E5CC9093FEFCA909097FF7A42FF38770DF949B22270CD
                    SHA-512:2FC665F5DEFA56F0B400CC89D7D57C97B17D8E37939C2E50B673EA285AE3782D7EEE4E4E6E2622A6A43A97F3A54DD37934B047CC170D26DB1A177455FE8BCAA3
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.........a..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2693
                    Entropy (8bit):4.003531366802204
                    Encrypted:false
                    SSDEEP:48:8x+2dtOTNKqRsHOsidAKZdA14tseh7sFiZUkmgqeh7sEy+BX:8x4P6nCy
                    MD5:1BCE4545FC9FA8A5B3CCAE87F7B72269
                    SHA1:CA77DFCE3ECFD4093CCAE0DB7D2D92EC312A6E99
                    SHA-256:7B460DE4434C8FF60FBEA232A54485EBC6ACD3A4029285ECB973152AC00DCFE1
                    SHA-512:E015FDFBC0A780E4423E520204FD1C51B15FB7CF050A3ACE031D9DEADD606239F1B47E0D5302AC9C7A4C830DD4F5E2CD054109F930D603ABCBAB0300634225AA
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 16 17:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.9903102868592524
                    Encrypted:false
                    SSDEEP:48:8i2dtOTNKqR8HOsidAKZdA1vehDiZUkwqeh6y+R:88Ppcy
                    MD5:BA5BF73C0AC37F039D9F58C8214923A4
                    SHA1:8A13A8D5AB00604FD69E537D47D7B7CF925DDF8D
                    SHA-256:12FF2B4C085DB476B1A1441A77224A9BBD637A04B9548FA184576B3B7205926D
                    SHA-512:68D1798C9A2DADA8F4995E77098472320A448C6033AAF40D189B1297665CF0EE8125B1209E72C98FB40DC8255910884A611C50831E282B4C6C28135572C93A9B
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....d....a..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 16 17:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.9809299611761184
                    Encrypted:false
                    SSDEEP:48:842dtOTNKqR8HOsidAKZdA1hehBiZUk1W1qehYy+C:8ePZ94y
                    MD5:52107C203E6C9143C5456C1CB1C3F5C0
                    SHA1:B0E3B9FB687FB8338C540B8F6F0FE7C4BCC4E47E
                    SHA-256:10670AF0BE76D63ECFE90929F3D55E9FE4A2F654FE4CA1B2808AADC0C111C3ED
                    SHA-512:FB987EFCF329FBF79A8C26D41379DD22E42EF7023E1C5281EF89EE9A00C24FAB4B817E5F9A5FEA7842A57DFEF96077E3200EA5216E3161DC952B2D72D886A496
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.........a..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 16 17:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2683
                    Entropy (8bit):3.991784669074659
                    Encrypted:false
                    SSDEEP:48:8y2dtOTNKqR8HOsidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbCy+yT+:8MPlT/TbxWOvTbCy7T
                    MD5:0416DDA144CC29ADFACB8B8F0CC2F503
                    SHA1:567D9E37A33C15D09A794370E77D4B1804F82C82
                    SHA-256:854CB261BA803AE4DE75651C375A3B66B92473C43F557EE23780690F85D1A747
                    SHA-512:82CE2596DE5FF9C512710D84B31522A603BC8FF45B85234BF686DE2943FEC3F3FC5D22EE5105181EDDB64E35B28AFF3623C8838684C159B651B90D0F1016E6D0
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....w....a..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):169
                    Entropy (8bit):4.65038089552961
                    Encrypted:false
                    SSDEEP:3:qVoB3tURObOb0qHXboAc9FKEIHiHby4AqWrKb0GklIVLLP9iVawcWWGu:q43tIkObRHXiWHiHuwWObtklI5LPoapJ
                    MD5:C2A982D42F89274763EEF2A44FE01030
                    SHA1:86E6D53F6478CDD0C05611093D9C55A953454AF7
                    SHA-256:D8B55DE3A4D5331F3B450A86BB907AFE17DC964ADCA30F39D101A3D55A4A9D6A
                    SHA-512:C1E2F30DB797583EC9EAE6755DAB939A2D71F902B557B069EFC510E51127DB6781456116CBFD764C8B9FC397791DF492DF52D200AFD9E46734B0845912C76E24
                    Malicious:false
                    Reputation:low
                    URL:http://149.154.167.41/
                    Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/0.3.33</center>..</body>..</html>..
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):169
                    Entropy (8bit):4.65038089552961
                    Encrypted:false
                    SSDEEP:3:qVoB3tURObOb0qHXboAc9FKEIHiHby4AqWrKb0GklIVLLP9iVawcWWGu:q43tIkObRHXiWHiHuwWObtklI5LPoapJ
                    MD5:C2A982D42F89274763EEF2A44FE01030
                    SHA1:86E6D53F6478CDD0C05611093D9C55A953454AF7
                    SHA-256:D8B55DE3A4D5331F3B450A86BB907AFE17DC964ADCA30F39D101A3D55A4A9D6A
                    SHA-512:C1E2F30DB797583EC9EAE6755DAB939A2D71F902B557B069EFC510E51127DB6781456116CBFD764C8B9FC397791DF492DF52D200AFD9E46734B0845912C76E24
                    Malicious:false
                    Reputation:low
                    URL:http://149.154.167.41/favicon.ico
                    Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/0.3.33</center>..</body>..</html>..
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 98
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 16, 2024 19:21:48.511322021 CET49675443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:48.511331081 CET49674443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:48.620735884 CET49673443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:57.087954998 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.087996960 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.088056087 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.090506077 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.090533972 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.090584993 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.090792894 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.090821981 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.090996027 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.091006994 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.318655014 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.319499016 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.319508076 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.321372986 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.321458101 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.324139118 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.324214935 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.324958086 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.324961901 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.399843931 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.400135040 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.400170088 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.400660992 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.400728941 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.401654959 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.401705027 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.402832985 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.403023005 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.403033018 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.403078079 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.444169044 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.444176912 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.444211006 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.542789936 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.542898893 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.542910099 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.542959929 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.543097973 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.543807030 CET49707443192.168.2.5142.250.31.84
                    Feb 16, 2024 19:21:57.543816090 CET44349707142.250.31.84192.168.2.5
                    Feb 16, 2024 19:21:57.546344042 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.676018953 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.676192045 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:57.676345110 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.676683903 CET49706443192.168.2.5142.251.40.238
                    Feb 16, 2024 19:21:57.676727057 CET44349706142.251.40.238192.168.2.5
                    Feb 16, 2024 19:21:58.131313086 CET49674443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:58.146822929 CET49675443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:58.256208897 CET49673443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:58.466872931 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.467058897 CET4971180192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.629046917 CET8049710149.154.167.41192.168.2.5
                    Feb 16, 2024 19:21:58.629189968 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.629429102 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.630656958 CET8049711149.154.167.41192.168.2.5
                    Feb 16, 2024 19:21:58.631052971 CET4971180192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.791642904 CET8049710149.154.167.41192.168.2.5
                    Feb 16, 2024 19:21:58.856018066 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:58.860934973 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:59.023080111 CET8049710149.154.167.41192.168.2.5
                    Feb 16, 2024 19:21:59.070692062 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:21:59.347171068 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.347223043 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.347296000 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.347666979 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.347681999 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.591862917 CET4434970323.1.237.91192.168.2.5
                    Feb 16, 2024 19:21:59.591979980 CET49703443192.168.2.523.1.237.91
                    Feb 16, 2024 19:21:59.614346027 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.614619017 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.614641905 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.615525007 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.615581989 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.617188931 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.617250919 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.663275003 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:21:59.663291931 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:21:59.710154057 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:01.814667940 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:01.814701080 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:01.814868927 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:01.818310022 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:01.818325043 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.007466078 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.007611036 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.011148930 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.011157036 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.011558056 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.053608894 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.112047911 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.153914928 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.200742960 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.204437971 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.204467058 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.204484940 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.204665899 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.204718113 CET4434971523.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.204849005 CET49715443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.271044970 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.271080017 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.271152973 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.272229910 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.272247076 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.462282896 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.462368011 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.465343952 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.465351105 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.465666056 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.467108011 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.513914108 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.636220932 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.636337996 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.636390924 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.637903929 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.637919903 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:02.637928963 CET49716443192.168.2.523.199.50.2
                    Feb 16, 2024 19:22:02.637936115 CET4434971623.199.50.2192.168.2.5
                    Feb 16, 2024 19:22:09.612010002 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:09.612087965 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:09.612520933 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:09.824727058 CET49703443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:09.824873924 CET49703443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:09.825419903 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:09.825474977 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:09.825686932 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:09.826208115 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:09.826252937 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:09.977396965 CET4434970323.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:09.977475882 CET4434970323.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.146456003 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.146536112 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.180701971 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.180746078 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.181191921 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.181251049 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.181708097 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.181746006 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.181958914 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.181972027 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.483391047 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.483458042 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.483911991 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:10.483963013 CET4434972123.1.237.91192.168.2.5
                    Feb 16, 2024 19:22:10.484025002 CET49721443192.168.2.523.1.237.91
                    Feb 16, 2024 19:22:11.247833014 CET49713443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:11.247873068 CET44349713142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:43.632761955 CET4971180192.168.2.5149.154.167.41
                    Feb 16, 2024 19:22:43.797039986 CET8049711149.154.167.41192.168.2.5
                    Feb 16, 2024 19:22:44.038121939 CET4971080192.168.2.5149.154.167.41
                    Feb 16, 2024 19:22:44.200344086 CET8049710149.154.167.41192.168.2.5
                    Feb 16, 2024 19:22:59.224570036 CET4971180192.168.2.5149.154.167.41
                    Feb 16, 2024 19:22:59.308304071 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:59.308341026 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.308409929 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:59.309024096 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:59.309040070 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.388283968 CET8049711149.154.167.41192.168.2.5
                    Feb 16, 2024 19:22:59.388365984 CET4971180192.168.2.5149.154.167.41
                    Feb 16, 2024 19:22:59.580476999 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.582683086 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:59.582709074 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.583309889 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.584021091 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:22:59.584119081 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:22:59.627423048 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:23:09.567066908 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:23:09.567219019 CET44349726142.251.40.228192.168.2.5
                    Feb 16, 2024 19:23:09.567277908 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:23:11.211747885 CET49726443192.168.2.5142.251.40.228
                    Feb 16, 2024 19:23:11.211776018 CET44349726142.251.40.228192.168.2.5
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 16, 2024 19:21:56.998533010 CET4968253192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:56.998863935 CET6155453192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:56.999577045 CET6491253192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:56.999880075 CET6418453192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:57.076947927 CET53619561.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:57.086235046 CET53496821.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:57.087110996 CET53615541.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:57.088124037 CET53649121.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:57.088270903 CET53641841.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:57.835912943 CET53627161.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:59.257183075 CET5958653192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:59.257437944 CET5422653192.168.2.51.1.1.1
                    Feb 16, 2024 19:21:59.345247030 CET53595861.1.1.1192.168.2.5
                    Feb 16, 2024 19:21:59.346182108 CET53542261.1.1.1192.168.2.5
                    Feb 16, 2024 19:22:14.862035990 CET53626701.1.1.1192.168.2.5
                    Feb 16, 2024 19:22:33.785712957 CET53572421.1.1.1192.168.2.5
                    Feb 16, 2024 19:22:56.269793034 CET53554881.1.1.1192.168.2.5
                    Feb 16, 2024 19:22:56.409121990 CET53557561.1.1.1192.168.2.5
                    Feb 16, 2024 19:23:23.580241919 CET53641941.1.1.1192.168.2.5
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Feb 16, 2024 19:21:56.998533010 CET192.168.2.51.1.1.10x3533Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:56.998863935 CET192.168.2.51.1.1.10xd61eStandard query (0)clients2.google.com65IN (0x0001)false
                    Feb 16, 2024 19:21:56.999577045 CET192.168.2.51.1.1.10xa2beStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:56.999880075 CET192.168.2.51.1.1.10xcf9bStandard query (0)accounts.google.com65IN (0x0001)false
                    Feb 16, 2024 19:21:59.257183075 CET192.168.2.51.1.1.10xe4dcStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:59.257437944 CET192.168.2.51.1.1.10xafa3Standard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Feb 16, 2024 19:21:57.086235046 CET1.1.1.1192.168.2.50x3533No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 16, 2024 19:21:57.086235046 CET1.1.1.1192.168.2.50x3533No error (0)clients.l.google.com142.251.40.238A (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:57.087110996 CET1.1.1.1192.168.2.50xd61eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 16, 2024 19:21:57.088124037 CET1.1.1.1192.168.2.50xa2beNo error (0)accounts.google.com142.250.31.84A (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:59.345247030 CET1.1.1.1192.168.2.50xe4dcNo error (0)www.google.com142.251.40.228A (IP address)IN (0x0001)false
                    Feb 16, 2024 19:21:59.346182108 CET1.1.1.1192.168.2.50xafa3No error (0)www.google.com65IN (0x0001)false
                    Feb 16, 2024 19:22:09.500641108 CET1.1.1.1192.168.2.50x59f1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Feb 16, 2024 19:22:09.500641108 CET1.1.1.1192.168.2.50x59f1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Feb 16, 2024 19:22:09.555535078 CET1.1.1.1192.168.2.50xe204No error (0)windowsupdatebg.s.llnwi.net69.164.46.0A (IP address)IN (0x0001)false
                    Feb 16, 2024 19:22:09.555535078 CET1.1.1.1192.168.2.50xe204No error (0)windowsupdatebg.s.llnwi.net69.164.46.128A (IP address)IN (0x0001)false
                    • accounts.google.com
                    • clients2.google.com
                    • fs.microsoft.com
                    • https:
                      • www.bing.com
                    • 149.154.167.41
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.549710149.154.167.41802140C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Feb 16, 2024 19:21:58.629429102 CET429OUTGET / HTTP/1.1
                    Host: 149.154.167.41
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Feb 16, 2024 19:21:58.791642904 CET324INHTTP/1.1 404 Not Found
                    Connection: keep-alive
                    Content-Type: text/html
                    Server: nginx/0.3.33
                    Date: Fri, 16 Feb 2024 18:21:58 GMT
                    Content-Length: 169
                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 30 2e 33 2e 33 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx/0.3.33</center></body></html>
                    Feb 16, 2024 19:21:58.860934973 CET372OUTGET /favicon.ico HTTP/1.1
                    Host: 149.154.167.41
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Referer: http://149.154.167.41/
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Feb 16, 2024 19:21:59.023080111 CET324INHTTP/1.1 404 Not Found
                    Connection: keep-alive
                    Content-Type: text/html
                    Server: nginx/0.3.33
                    Date: Fri, 16 Feb 2024 18:21:58 GMT
                    Content-Length: 169
                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 30 2e 33 2e 33 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx/0.3.33</center></body></html>
                    Feb 16, 2024 19:22:44.038121939 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.549711149.154.167.41802140C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Feb 16, 2024 19:22:43.632761955 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.549707142.250.31.844432140C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-02-16 18:21:57 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
                    2024-02-16 18:21:57 UTC1OUTData Raw: 20
                    Data Ascii:
                    2024-02-16 18:21:57 UTC1799INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Fri, 16 Feb 2024 18:21:57 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Cross-Origin-Opener-Policy: same-origin
                    Content-Security-Policy: script-src 'report-sample' 'nonce-yJdDQ5Z8zAF217IYtAAfZA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQJiIR6Oo-f3rWMT-DCp8SEjALg1F8o"
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-02-16 18:21:57 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2024-02-16 18:21:57 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.549706142.251.40.2384432140C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-02-16 18:21:57 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-117.0.5938.132
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-02-16 18:21:57 UTC732INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-o_EQr9dcqlZH3eQSkwttOA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Fri, 16 Feb 2024 18:21:57 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6255
                    X-Daystart: 37317
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-02-16 18:21:57 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 35 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 37 33 31 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6255" elapsed_seconds="37317"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2024-02-16 18:21:57 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2024-02-16 18:21:57 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.54971523.199.50.2443
                    TimestampBytes transferredDirectionData
                    2024-02-16 18:22:02 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-02-16 18:22:02 UTC466INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/07A7)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus2-z1
                    Cache-Control: public, max-age=3792
                    Date: Fri, 16 Feb 2024 18:22:02 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.54971623.199.50.2443
                    TimestampBytes transferredDirectionData
                    2024-02-16 18:22:02 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-02-16 18:22:02 UTC658INHTTP/1.1 200 OK
                    Content-Type: application/octet-stream
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-CID: 7
                    X-CCC: US
                    X-Azure-Ref-OriginShield: Ref A: 974286BFDC254CDCB50C2B73CC4B4276 Ref B: MNZ221060605025 Ref C: 2023-03-13T15:26:50Z
                    X-MSEdge-Ref: Ref A: 87B54C6474A14C81B6E546C3B6B2F842 Ref B: BLUEDGE1720 Ref C: 2023-03-13T15:26:50Z
                    Cache-Control: public, max-age=3824
                    Date: Fri, 16 Feb 2024 18:22:02 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-02-16 18:22:02 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination Port
                    4192.168.2.54972123.1.237.91443
                    TimestampBytes transferredDirectionData
                    2024-02-16 18:22:10 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
                    Origin: https://www.bing.com
                    Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                    Accept: */*
                    Accept-Language: en-CH
                    Content-type: text/xml
                    X-Agent-DeviceId: 01000A410900D492
                    X-BM-CBT: 1696428841
                    X-BM-DateFormat: dd/MM/yyyy
                    X-BM-DeviceDimensions: 784x984
                    X-BM-DeviceDimensionsLogical: 784x984
                    X-BM-DeviceScale: 100
                    X-BM-DTZ: 120
                    X-BM-Market: CH
                    X-BM-Theme: 000000;0078d7
                    X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                    X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
                    X-Device-isOptin: false
                    X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                    X-Device-OSSKU: 48
                    X-Device-Touch: false
                    X-DeviceID: 01000A410900D492
                    X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
                    X-MSEdge-ExternalExpType: JointCoord
                    X-PositionerType: Desktop
                    X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                    X-Search-CortanaAvailableCapabilities: None
                    X-Search-SafeSearch: Moderate
                    X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
                    X-UserAgeClass: Unknown
                    Accept-Encoding: gzip, deflate, br
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                    Host: www.bing.com
                    Content-Length: 2484
                    Connection: Keep-Alive
                    Cache-Control: no-cache
                    Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1708107697944&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
                    2024-02-16 18:22:10 UTC1OUTData Raw: 3c
                    Data Ascii: <
                    2024-02-16 18:22:10 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
                    Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
                    2024-02-16 18:22:10 UTC475INHTTP/1.1 204 No Content
                    Access-Control-Allow-Origin: *
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    X-MSEdge-Ref: Ref A: 8CBD25F385E74C4D9111FE45551E8DD2 Ref B: BY3EDGE0220 Ref C: 2024-02-16T18:22:10Z
                    Date: Fri, 16 Feb 2024 18:22:10 GMT
                    Connection: close
                    Alt-Svc: h3=":443"; ma=93600
                    X-CDN-TraceID: 0.57ed0117.1708107730.30f3241


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0050100MB

                    Click to jump to process

                    Target ID:0
                    Start time:19:21:50
                    Start date:16/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:19:21:54
                    Start date:16/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2204,i,7489064456424810634,7995094544846090831,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:19:21:57
                    Start date:16/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://149.154.167.41
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly