Edit tour

Windows Analysis Report
http://c.go-mpulse.net

Overview

General Information

Sample URL:http://c.go-mpulse.net
Analysis ID:1412293
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6184 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1812 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2320,i,8627070888507480679,82149897595925973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4456 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://c.go-mpulse.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 69.192.108.161:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 69.192.108.161:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 69.192.108.161
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: c.go-mpulse.net
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1710930297039&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 69.192.108.161:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 69.192.108.161:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/6@4/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2320,i,8627070888507480679,82149897595925973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://c.go-mpulse.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2320,i,8627070888507480679,82149897595925973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1412293 URL: http://c.go-mpulse.net Startdate: 20/03/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 9 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49703, 49714 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.251.40.100, 443, 49714, 49726 GOOGLEUS United States 10->17 19 c.go-mpulse.net 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://c.go-mpulse.net0%Avira URL Cloudsafe
http://c.go-mpulse.net0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
c.go-mpulse.net0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.40.100
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    c.go-mpulse.net
    unknown
    unknownfalseunknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    142.251.40.100
    www.google.comUnited States
    15169GOOGLEUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    IP
    192.168.2.5
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1412293
    Start date and time:2024-03-20 11:24:25 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 2s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:http://c.go-mpulse.net
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:7
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:CLEAN
    Classification:clean1.win@16/6@4/3
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.250.176.195, 142.251.32.110, 142.251.111.84, 34.104.35.123, 96.17.64.187, 40.68.123.157, 104.102.251.73, 72.21.81.240, 192.229.211.108, 20.166.126.56, 20.3.187.198, 52.165.164.15, 142.250.80.67
    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, e4518.dscapi7.akamaiedge.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, wildcard46.go-mpulse.net.edgekey.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Mar 20 09:25:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2677
    Entropy (8bit):3.9732655214990444
    Encrypted:false
    SSDEEP:48:8id+oTesfyHjidAKZdA19ehwiZUklqehLy+3:8Kjy8y
    MD5:205817684239B18DD9E26A3B4F53F531
    SHA1:519B056EB9ACE28586005247154F50CA41A1F01E
    SHA-256:9FF8B05F1AD6637D825B07865C9BE9128C264B1B6C11EF88AFCF3CDD81AFD525
    SHA-512:5C153C301697C46E60B3A53E02DDFE63B133C73F22BFD0A45CF75B49BEEF577DA78E64358E4155E3C7BD65BA51F1224380C078B8C6B7785A0022941323113339
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,..... ..z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VtX(S...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Mar 20 09:25:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2679
    Entropy (8bit):3.991249119494067
    Encrypted:false
    SSDEEP:48:82Pd+oTesfyHjidAKZdA1weh/iZUkAQkqehsy+2:8sjo9Qly
    MD5:AA40BE5A2430F018F4995469EEE14657
    SHA1:BDAA3C17F6A9E13B5934242CA8E7099B1CB3FADE
    SHA-256:60559FBEC3ECA9B6565915BE5D63B07EFC5F65649BBD53B2C0F37F3C1874AF29
    SHA-512:4375746A848CE89CA04BB8DF66A6C0D0F5BBE12D32FAC120C33F17FB6E4B10858558856C50785453851A2D2B90117E2E0CF41A437CC2E81D22DC266C3859DB8C
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....<[..z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VtX(S...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2693
    Entropy (8bit):4.000329347622894
    Encrypted:false
    SSDEEP:48:8xAd+oTesfsHjidAKZdA14tseh7sFiZUkmgqeh7s+y+BX:8x8jenwy
    MD5:E6420ADD573267EFDDE4412B074224BA
    SHA1:43E9D5697B7042E328D8D837AEC7401774097FB5
    SHA-256:433C449E9A57BBC0F4D93A4CAFF61374AE7D144F5FECC201CEA2ACFF409F265E
    SHA-512:B0DC430CFD1B8C06E7AE9951E293630EF7FCFD7AAB762909ABBEE66652FDBAF6BBBC26CD7ECF81BDA44F8B40EA606E312C31CD367AF9A581C50A9C940A9D55B8
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Mar 20 09:25:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2681
    Entropy (8bit):3.989183923379386
    Encrypted:false
    SSDEEP:48:8HHd+oTesfyHjidAKZdA1vehDiZUkwqeh4y+R:8djzGy
    MD5:97769F34C757054E84DC342384351A7A
    SHA1:02C6B1FF8CA537793A270501300AA2C3516B4715
    SHA-256:6ED8F007785E5E856C15471DE050951BC1773F02BF71D0FB1508BA0E7ADB1860
    SHA-512:0D913C12502E060449EDE5B6CD1138E9F0E83033474AC7792102819CDE28D34BE7FB94121370FB265DD84542E5D1BFB85C2FFFC1C81A7AB78A5F3E8CF7F26274
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,........z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VtX(S...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Mar 20 09:25:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2681
    Entropy (8bit):3.975482397357466
    Encrypted:false
    SSDEEP:48:8bd+oTesfyHjidAKZdA1hehBiZUk1W1qehyy+C:8Bjj9Sy
    MD5:1358232CCF2000F59DA7363527E4B3E4
    SHA1:5861A3A3BD3A69E511E6D261B7523E9C65A1BA7F
    SHA-256:376EACBC206765B78C16E048DAEFE7A684BAADD3D37F280866ED39D8E9F3CD81
    SHA-512:95CD656C2BD27D514FD3BCFF22F4DCDBAEEA6C466B52C228057FB1493848D8A5059546CE251CD06CC32B4701CD44ECE1C870E937A7E915B5CCA5B168B86FDB85
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....NA..z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VtX(S...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Mar 20 09:25:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
    Category:dropped
    Size (bytes):2683
    Entropy (8bit):3.986908484260524
    Encrypted:false
    SSDEEP:48:8Jd+oTesfyHjidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbwy+yT+:8DjTT/TbxWOvTbwy7T
    MD5:74B85F4C8E012E59533835D85BE9A2C2
    SHA1:BD2851191A2EB415CF71B25C0483F7C1E50F9D22
    SHA-256:7DB5922D01E549CCD9985392373076488B2AD6FFCA9C12F3AABCBD57D2CED59B
    SHA-512:819940E2249E5DBC43D1DFA0661A43406E63AD22AC37A3890B4CABF4AFBCFBA591CC0358A316395A06A95B87890E4CCF81F59BD321C7BAFE139AB28F2402EACE
    Malicious:false
    Reputation:low
    Preview:L..................F.@.. ...$+.,....Rf..z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ItX%S....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VtX%S....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VtX%S....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VtX%S..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VtX(S...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........NB"......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
    No static file info

    Download Network PCAP: filteredfull

    • Total Packets: 44
    • 443 (HTTPS)
    • 53 (DNS)
    TimestampSource PortDest PortSource IPDest IP
    Mar 20, 2024 11:25:06.955502987 CET49674443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:06.955504894 CET49675443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:07.064883947 CET49673443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:15.701702118 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.701750994 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:15.701828003 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.702311993 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.702327013 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:15.970027924 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:15.970597029 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.970623016 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:15.971616983 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:15.971673965 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.973581076 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:15.973644972 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:16.016717911 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:16.016743898 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:16.063605070 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:16.563595057 CET49674443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:16.563599110 CET49675443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:16.672969103 CET49673443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:17.835123062 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:17.835170031 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:17.837616920 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:17.841556072 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:17.841567993 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.035773039 CET4434970323.1.237.91192.168.2.5
    Mar 20, 2024 11:25:18.035870075 CET49703443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:18.186316967 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.186398029 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.188671112 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.188679934 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.188888073 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.235081911 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.280232906 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.515990019 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.516062975 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.516119957 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.516246080 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.516272068 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.516282082 CET49715443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.516287088 CET4434971569.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.578067064 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.578164101 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.578269005 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.579262018 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.579310894 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.904622078 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.904705048 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.908478975 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.908508062 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.908754110 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:18.911689997 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:18.952264071 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:19.224008083 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:19.224087954 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:19.224478960 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:19.226001024 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:19.226043940 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:19.226099968 CET49716443192.168.2.569.192.108.161
    Mar 20, 2024 11:25:19.226116896 CET4434971669.192.108.161192.168.2.5
    Mar 20, 2024 11:25:25.975569010 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:25.975640059 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:25.975866079 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:27.510073900 CET49714443192.168.2.5142.251.40.100
    Mar 20, 2024 11:25:27.510140896 CET44349714142.251.40.100192.168.2.5
    Mar 20, 2024 11:25:28.524518967 CET49703443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.524913073 CET49703443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.525429964 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.525496006 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.525568008 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.525968075 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.525983095 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.678431988 CET4434970323.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.678556919 CET4434970323.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.844391108 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.844465971 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.911637068 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.911669016 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.912038088 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.912096024 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.914710045 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.914752960 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:28.914931059 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:28.914937019 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:29.229470968 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:29.229537010 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:29.229552031 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:29.229602098 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:29.253921032 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:29.253937960 CET4434972123.1.237.91192.168.2.5
    Mar 20, 2024 11:25:29.253947973 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:25:29.253990889 CET49721443192.168.2.523.1.237.91
    Mar 20, 2024 11:26:16.070452929 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:16.070499897 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.070694923 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:16.071615934 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:16.071643114 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.334316015 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.347058058 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:16.347088099 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.347419977 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.348475933 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:16.348542929 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:16.391372919 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:26.329781055 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:26.329852104 CET44349726142.251.40.100192.168.2.5
    Mar 20, 2024 11:26:26.329921961 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:27.237417936 CET49726443192.168.2.5142.251.40.100
    Mar 20, 2024 11:26:27.237451077 CET44349726142.251.40.100192.168.2.5
    TimestampSource PortDest PortSource IPDest IP
    Mar 20, 2024 11:25:13.162286997 CET53586581.1.1.1192.168.2.5
    Mar 20, 2024 11:25:13.174017906 CET53618591.1.1.1192.168.2.5
    Mar 20, 2024 11:25:13.720942020 CET53550901.1.1.1192.168.2.5
    Mar 20, 2024 11:25:14.538547993 CET5919853192.168.2.51.1.1.1
    Mar 20, 2024 11:25:14.538769960 CET6443853192.168.2.51.1.1.1
    Mar 20, 2024 11:25:15.612689018 CET5573453192.168.2.51.1.1.1
    Mar 20, 2024 11:25:15.612835884 CET5568153192.168.2.51.1.1.1
    Mar 20, 2024 11:25:15.700468063 CET53557341.1.1.1192.168.2.5
    Mar 20, 2024 11:25:15.700509071 CET53556811.1.1.1192.168.2.5
    Mar 20, 2024 11:25:30.966161013 CET53550861.1.1.1192.168.2.5
    Mar 20, 2024 11:25:49.758022070 CET53647731.1.1.1192.168.2.5
    Mar 20, 2024 11:26:12.121961117 CET53506901.1.1.1192.168.2.5
    Mar 20, 2024 11:26:12.673047066 CET53510941.1.1.1192.168.2.5
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Mar 20, 2024 11:25:14.538547993 CET192.168.2.51.1.1.10xc434Standard query (0)c.go-mpulse.netA (IP address)IN (0x0001)false
    Mar 20, 2024 11:25:14.538769960 CET192.168.2.51.1.1.10x3d6bStandard query (0)c.go-mpulse.net65IN (0x0001)false
    Mar 20, 2024 11:25:15.612689018 CET192.168.2.51.1.1.10xe88eStandard query (0)www.google.comA (IP address)IN (0x0001)false
    Mar 20, 2024 11:25:15.612835884 CET192.168.2.51.1.1.10x8f67Standard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Mar 20, 2024 11:25:14.626657009 CET1.1.1.1192.168.2.50xc434No error (0)c.go-mpulse.netwildcard46.go-mpulse.net.edgekey.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:25:14.626914024 CET1.1.1.1192.168.2.50x3d6bNo error (0)c.go-mpulse.netwildcard46.go-mpulse.net.edgekey.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:25:15.700468063 CET1.1.1.1192.168.2.50xe88eNo error (0)www.google.com142.251.40.100A (IP address)IN (0x0001)false
    Mar 20, 2024 11:25:15.700509071 CET1.1.1.1192.168.2.50x8f67No error (0)www.google.com65IN (0x0001)false
    Mar 20, 2024 11:25:28.051021099 CET1.1.1.1192.168.2.50x6cceNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:25:28.051021099 CET1.1.1.1192.168.2.50x6cceNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 20, 2024 11:25:41.542943001 CET1.1.1.1192.168.2.50xb713No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:25:41.542943001 CET1.1.1.1192.168.2.50xb713No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 20, 2024 11:26:04.871525049 CET1.1.1.1192.168.2.50x1194No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:26:04.871525049 CET1.1.1.1192.168.2.50x1194No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    Mar 20, 2024 11:26:25.308193922 CET1.1.1.1192.168.2.50xfcfcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 20, 2024 11:26:25.308193922 CET1.1.1.1192.168.2.50xfcfcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    • fs.microsoft.com
    • https:
      • www.bing.com
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.54971569.192.108.161443
    TimestampBytes transferredDirectionData
    2024-03-20 10:25:18 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-03-20 10:25:18 UTC467INHTTP/1.1 200 OK
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    Content-Type: application/octet-stream
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    Server: ECAcc (chd/079C)
    X-CID: 11
    X-Ms-ApiVersion: Distribute 1.2
    X-Ms-Region: prod-eus2-z1
    Cache-Control: public, max-age=32433
    Date: Wed, 20 Mar 2024 10:25:18 GMT
    Connection: close
    X-CID: 2


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    1192.168.2.54971669.192.108.161443
    TimestampBytes transferredDirectionData
    2024-03-20 10:25:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
    Range: bytes=0-2147483646
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-03-20 10:25:19 UTC530INHTTP/1.1 200 OK
    Content-Type: application/octet-stream
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    ApiVersion: Distribute 1.1
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
    Cache-Control: public, max-age=32382
    Date: Wed, 20 Mar 2024 10:25:19 GMT
    Content-Length: 55
    Connection: close
    X-CID: 2
    2024-03-20 10:25:19 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


    Session IDSource IPSource PortDestination IPDestination Port
    2192.168.2.54972123.1.237.91443
    TimestampBytes transferredDirectionData
    2024-03-20 10:25:28 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
    Origin: https://www.bing.com
    Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
    Accept: */*
    Accept-Language: en-CH
    Content-type: text/xml
    X-Agent-DeviceId: 01000A410900D492
    X-BM-CBT: 1696428841
    X-BM-DateFormat: dd/MM/yyyy
    X-BM-DeviceDimensions: 784x984
    X-BM-DeviceDimensionsLogical: 784x984
    X-BM-DeviceScale: 100
    X-BM-DTZ: 120
    X-BM-Market: CH
    X-BM-Theme: 000000;0078d7
    X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
    X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
    X-Device-isOptin: false
    X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
    X-Device-OSSKU: 48
    X-Device-Touch: false
    X-DeviceID: 01000A410900D492
    X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
    X-MSEdge-ExternalExpType: JointCoord
    X-PositionerType: Desktop
    X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
    X-Search-CortanaAvailableCapabilities: None
    X-Search-SafeSearch: Moderate
    X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
    X-UserAgeClass: Unknown
    Accept-Encoding: gzip, deflate, br
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
    Host: www.bing.com
    Content-Length: 2484
    Connection: Keep-Alive
    Cache-Control: no-cache
    Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1710930297039&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
    2024-03-20 10:25:28 UTC1OUTData Raw: 3c
    Data Ascii: <
    2024-03-20 10:25:28 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
    Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
    2024-03-20 10:25:29 UTC476INHTTP/1.1 204 No Content
    Access-Control-Allow-Origin: *
    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
    X-MSEdge-Ref: Ref A: 2E6985F6186940878B518B36AFAE1BFE Ref B: PAOEDGE0512 Ref C: 2024-03-20T10:25:29Z
    Date: Wed, 20 Mar 2024 10:25:29 GMT
    Connection: close
    Alt-Svc: h3=":443"; ma=93600
    X-CDN-TraceID: 0.57ed0117.1710930328.3d5f8962


    020406080s020406080100

    Click to jump to process

    020406080s0.0050100MB

    Click to jump to process

    Target ID:0
    Start time:11:25:07
    Start date:20/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:2
    Start time:11:25:10
    Start date:20/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2320,i,8627070888507480679,82149897595925973,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:3
    Start time:11:25:13
    Start date:20/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://c.go-mpulse.net"
    Imagebase:0x7ff715980000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    No disassembly