Edit tour

Windows Analysis Report
https://manage.kmail-lists.com/subscriΡtions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t

Overview

General Information

Sample URL:https://manage.kmail-lists.com/subscriΡtions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlighta
Analysis ID:1416073
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6292 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 5876 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=2020,i,7158565139567169839,16495825416727787881,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 2420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.6:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t HTTP/1.1Host: manage.kmail-lists.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t HTTP/1.1Host: topfloorlightandsound.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: manage.kmail-lists.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.6:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@17/4@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\6ea45fa1-2fb8-4ee7-9aeb-9efbaad6b87f.tmpJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=2020,i,7158565139567169839,16495825416727787881,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=2020,i,7158565139567169839,16495825416727787881,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1416073 URL: https://manage.kmail-lists.... Startdate: 26/03/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 13 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.6, 443, 49698, 49704 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 topfloorlightandsound.com 50.87.132.174, 443, 49706 UNIFIEDLAYER-AS-1US United States 10->17 19 www.google.com 142.251.16.106, 443, 49709, 49721 GOOGLEUS United States 10->19 21 manage.kmail-lists.com 54.243.145.247, 443, 49704, 49705 AMAZON-AESUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://topfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
topfloorlightandsound.com
50.87.132.174
truefalse
    unknown
    www.google.com
    142.251.16.106
    truefalse
      high
      manage.kmail-lists.com
      54.243.145.247
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29tfalse
            high
            https://topfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29tfalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            54.243.145.247
            manage.kmail-lists.comUnited States
            14618AMAZON-AESUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            50.87.132.174
            topfloorlightandsound.comUnited States
            46606UNIFIEDLAYER-AS-1USfalse
            142.251.16.106
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.6
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1416073
            Start date and time:2024-03-26 20:33:04 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 4s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://manage.kmail-lists.com/subscriΡtions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:9
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@17/4@6/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • URL not reachable
            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.62.94, 142.251.163.102, 142.251.163.139, 142.251.163.100, 142.251.163.138, 142.251.163.101, 142.251.163.113, 142.251.179.84, 34.104.35.123, 20.114.59.183, 72.21.81.240, 192.229.211.108, 52.165.164.15, 13.85.23.206, 172.253.122.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&amp;a=WkVYqE&amp;p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&amp;k=53b9cf0c5602fbaff2d592c0e9b9058a&amp;r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PHP script, ASCII text
            Category:dropped
            Size (bytes):1539
            Entropy (8bit):5.258450314188654
            Encrypted:false
            SSDEEP:24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D
            MD5:0A7DBE91D13815D631A35BCE7CD37500
            SHA1:8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA
            SHA-256:4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1
            SHA-512:3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565
            Malicious:false
            Reputation:low
            Preview:<?php./**. * @package Joomla.Administrator. *. * @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.. * @license GNU General Public License version 2 or later; see LICENSE.txt. */../**. * Define the application's minimum supported PHP version as a constant so it can be referenced within the application.. */.define('JOOMLA_MINIMUM_PHP', '5.3.10');..if (version_compare(PHP_VERSION, JOOMLA_MINIMUM_PHP, '<')).{..die('Your host needs to use PHP ' . JOOMLA_MINIMUM_PHP . ' or higher to run this version of Joomla!');.}..// Saves the start time and memory usage..$startTime = microtime(1);.$startMem = memory_get_usage();../**. * Constant that is checked in included files to prevent direct access.. * define() is used in the installation folder rather than "const" to not error for PHP 5.2 and lower. */.define('_JEXEC', 1);..if (file_exists(__DIR__ . '/defines.php')).{..include_once __DIR__ . '/defines.php';.}..if (!defined('_JDEFINES')).{..define('JPATH_BASE
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PHP script, ASCII text
            Category:dropped
            Size (bytes):1539
            Entropy (8bit):5.258450314188654
            Encrypted:false
            SSDEEP:24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D
            MD5:0A7DBE91D13815D631A35BCE7CD37500
            SHA1:8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA
            SHA-256:4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1
            SHA-512:3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565
            Malicious:false
            Reputation:low
            Preview:<?php./**. * @package Joomla.Administrator. *. * @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.. * @license GNU General Public License version 2 or later; see LICENSE.txt. */../**. * Define the application's minimum supported PHP version as a constant so it can be referenced within the application.. */.define('JOOMLA_MINIMUM_PHP', '5.3.10');..if (version_compare(PHP_VERSION, JOOMLA_MINIMUM_PHP, '<')).{..die('Your host needs to use PHP ' . JOOMLA_MINIMUM_PHP . ' or higher to run this version of Joomla!');.}..// Saves the start time and memory usage..$startTime = microtime(1);.$startMem = memory_get_usage();../**. * Constant that is checked in included files to prevent direct access.. * define() is used in the installation folder rather than "const" to not error for PHP 5.2 and lower. */.define('_JEXEC', 1);..if (file_exists(__DIR__ . '/defines.php')).{..include_once __DIR__ . '/defines.php';.}..if (!defined('_JDEFINES')).{..define('JPATH_BASE
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PHP script, ASCII text
            Category:downloaded
            Size (bytes):1539
            Entropy (8bit):5.258450314188654
            Encrypted:false
            SSDEEP:24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D
            MD5:0A7DBE91D13815D631A35BCE7CD37500
            SHA1:8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA
            SHA-256:4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1
            SHA-512:3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565
            Malicious:false
            Reputation:low
            URL:https://topfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t
            Preview:<?php./**. * @package Joomla.Administrator. *. * @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.. * @license GNU General Public License version 2 or later; see LICENSE.txt. */../**. * Define the application's minimum supported PHP version as a constant so it can be referenced within the application.. */.define('JOOMLA_MINIMUM_PHP', '5.3.10');..if (version_compare(PHP_VERSION, JOOMLA_MINIMUM_PHP, '<')).{..die('Your host needs to use PHP ' . JOOMLA_MINIMUM_PHP . ' or higher to run this version of Joomla!');.}..// Saves the start time and memory usage..$startTime = microtime(1);.$startMem = memory_get_usage();../**. * Constant that is checked in included files to prevent direct access.. * define() is used in the installation folder rather than "const" to not error for PHP 5.2 and lower. */.define('_JEXEC', 1);..if (file_exists(__DIR__ . '/defines.php')).{..include_once __DIR__ . '/defines.php';.}..if (!defined('_JDEFINES')).{..define('JPATH_BASE
            No static file info
            Icon Hash:00b29a8e86828200

            Download Network PCAP: filteredfull

            • Total Packets: 84
            • 443 (HTTPS)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Mar 26, 2024 20:33:46.932794094 CET49674443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:46.932801962 CET49673443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:47.260936022 CET49672443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:52.830485106 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.830485106 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.830508947 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:52.830509901 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:52.830615044 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.830636978 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.830988884 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.830993891 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:52.831038952 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:52.831043959 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.139692068 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.139990091 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.140002012 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.141083002 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.141231060 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.142184019 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.142236948 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.142302990 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.142432928 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.142668009 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.142673969 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.143721104 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.143836021 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.144691944 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.144738913 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.184246063 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.184286118 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.184293985 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.230314970 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.230314970 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.230323076 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.260603905 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.260704041 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.260752916 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.261282921 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.261292934 CET4434970554.243.145.247192.168.2.6
            Mar 26, 2024 20:33:53.261302948 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.261332989 CET49705443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.277036905 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:33:53.402718067 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.402729034 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.402780056 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.403103113 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.403115034 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.774946928 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.775572062 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.775580883 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.776664972 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.776750088 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.778023005 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.778085947 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.778469086 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:53.778479099 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:53.819884062 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:54.137471914 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:54.137490988 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:54.137548923 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:54.137561083 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:54.137573004 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:54.137623072 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:54.186587095 CET49706443192.168.2.650.87.132.174
            Mar 26, 2024 20:33:54.186595917 CET4434970650.87.132.174192.168.2.6
            Mar 26, 2024 20:33:55.498197079 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.498219013 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.498287916 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.498651981 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.498661995 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.719331980 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.719686985 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.719696999 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.720732927 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.720792055 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.723428011 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.723495007 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.775115967 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:55.775121927 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:33:55.821985960 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:33:56.089385986 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.089406013 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.089623928 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.091597080 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.091609955 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.291438103 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.291518927 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.301887989 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.301892996 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.302153111 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.353233099 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.540524960 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.540724993 CET49674443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:56.540747881 CET49673443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:56.584239006 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.637366056 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.637433052 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.637532949 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.657617092 CET49710443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.657629967 CET4434971023.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.741986036 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.742013931 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.742100000 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.742850065 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.742862940 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.868861914 CET49672443192.168.2.6173.222.162.64
            Mar 26, 2024 20:33:56.944840908 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.944920063 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.948368073 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.948375940 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.948636055 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:56.951613903 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:56.992242098 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:57.140558958 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:57.140641928 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:57.140706062 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:57.143316031 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:57.143336058 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:57.143346071 CET49711443192.168.2.623.221.242.90
            Mar 26, 2024 20:33:57.143352985 CET4434971123.221.242.90192.168.2.6
            Mar 26, 2024 20:33:58.306359053 CET44349698173.222.162.64192.168.2.6
            Mar 26, 2024 20:33:58.306463003 CET49698443192.168.2.6173.222.162.64
            Mar 26, 2024 20:34:05.749423027 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:05.749491930 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:05.749604940 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:07.668122053 CET49709443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:07.668140888 CET44349709142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:38.236355066 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:34:38.236365080 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:34:53.678793907 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:34:53.678888083 CET4434970454.243.145.247192.168.2.6
            Mar 26, 2024 20:34:53.679053068 CET49704443192.168.2.654.243.145.247
            Mar 26, 2024 20:34:55.449345112 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:55.449385881 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.449460030 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:55.449765921 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:55.449781895 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.656337976 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.658194065 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:55.658224106 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.658575058 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.658953905 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:34:55.659022093 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:34:55.703691959 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:35:05.656207085 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:35:05.656284094 CET44349721142.251.16.106192.168.2.6
            Mar 26, 2024 20:35:05.656402111 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:35:05.678910017 CET49721443192.168.2.6142.251.16.106
            Mar 26, 2024 20:35:05.678930044 CET44349721142.251.16.106192.168.2.6
            TimestampSource PortDest PortSource IPDest IP
            Mar 26, 2024 20:33:51.525468111 CET53606641.1.1.1192.168.2.6
            Mar 26, 2024 20:33:51.530858040 CET53536891.1.1.1192.168.2.6
            Mar 26, 2024 20:33:52.718739033 CET5537653192.168.2.61.1.1.1
            Mar 26, 2024 20:33:52.718969107 CET5867153192.168.2.61.1.1.1
            Mar 26, 2024 20:33:52.814480066 CET53553761.1.1.1192.168.2.6
            Mar 26, 2024 20:33:52.829386950 CET53586711.1.1.1192.168.2.6
            Mar 26, 2024 20:33:53.049422026 CET53532741.1.1.1192.168.2.6
            Mar 26, 2024 20:33:53.265662909 CET5285253192.168.2.61.1.1.1
            Mar 26, 2024 20:33:53.265999079 CET6260453192.168.2.61.1.1.1
            Mar 26, 2024 20:33:53.384975910 CET53528521.1.1.1192.168.2.6
            Mar 26, 2024 20:33:53.402180910 CET53626041.1.1.1192.168.2.6
            Mar 26, 2024 20:33:55.391053915 CET5064653192.168.2.61.1.1.1
            Mar 26, 2024 20:33:55.391551971 CET5080753192.168.2.61.1.1.1
            Mar 26, 2024 20:33:55.485965967 CET53506461.1.1.1192.168.2.6
            Mar 26, 2024 20:33:55.486519098 CET53508071.1.1.1192.168.2.6
            Mar 26, 2024 20:34:10.192095041 CET53637371.1.1.1192.168.2.6
            Mar 26, 2024 20:34:29.052376986 CET53504681.1.1.1192.168.2.6
            Mar 26, 2024 20:34:51.048151016 CET53627291.1.1.1192.168.2.6
            Mar 26, 2024 20:34:51.904627085 CET53562581.1.1.1192.168.2.6
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 26, 2024 20:33:52.718739033 CET192.168.2.61.1.1.10x2f4eStandard query (0)manage.kmail-lists.comA (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:52.718969107 CET192.168.2.61.1.1.10x39cfStandard query (0)manage.kmail-lists.com65IN (0x0001)false
            Mar 26, 2024 20:33:53.265662909 CET192.168.2.61.1.1.10xc0f4Standard query (0)topfloorlightandsound.comA (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:53.265999079 CET192.168.2.61.1.1.10x3815Standard query (0)topfloorlightandsound.com65IN (0x0001)false
            Mar 26, 2024 20:33:55.391053915 CET192.168.2.61.1.1.10xa7feStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.391551971 CET192.168.2.61.1.1.10xe981Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 26, 2024 20:33:52.814480066 CET1.1.1.1192.168.2.60x2f4eNo error (0)manage.kmail-lists.com54.243.145.247A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:52.814480066 CET1.1.1.1192.168.2.60x2f4eNo error (0)manage.kmail-lists.com54.205.206.182A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:52.814480066 CET1.1.1.1192.168.2.60x2f4eNo error (0)manage.kmail-lists.com54.157.61.255A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:52.814480066 CET1.1.1.1192.168.2.60x2f4eNo error (0)manage.kmail-lists.com52.54.202.246A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:53.384975910 CET1.1.1.1192.168.2.60xc0f4No error (0)topfloorlightandsound.com50.87.132.174A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.485965967 CET1.1.1.1192.168.2.60xa7feNo error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
            Mar 26, 2024 20:33:55.486519098 CET1.1.1.1192.168.2.60xe981No error (0)www.google.com65IN (0x0001)false
            Mar 26, 2024 20:34:08.014354944 CET1.1.1.1192.168.2.60x1fb1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 26, 2024 20:34:08.014354944 CET1.1.1.1192.168.2.60x1fb1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 26, 2024 20:34:20.856930017 CET1.1.1.1192.168.2.60xaf3bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 26, 2024 20:34:20.856930017 CET1.1.1.1192.168.2.60xaf3bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 26, 2024 20:34:44.198652029 CET1.1.1.1192.168.2.60x49cdNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 26, 2024 20:34:44.198652029 CET1.1.1.1192.168.2.60x49cdNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 26, 2024 20:35:03.704185963 CET1.1.1.1192.168.2.60x8f80No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 26, 2024 20:35:03.704185963 CET1.1.1.1192.168.2.60x8f80No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • manage.kmail-lists.com
            • topfloorlightandsound.com
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.64970554.243.145.2474435876C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-26 19:33:53 UTC886OUTGET /subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t HTTP/1.1
            Host: manage.kmail-lists.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-26 19:33:53 UTC487INHTTP/1.1 302 Found
            Allow: POST, GET, OPTIONS
            Content-Language: en-us
            Content-Security-Policy: base-uri 'none'; script-src 'report-sample' 'strict-dynamic' 'unsafe-eval' https://cdn.ampproject.org/; object-src 'none'; report-uri /csp/
            Content-Type: text/html; charset=utf-8
            Date: Tue, 26 Mar 2024 19:33:53 GMT
            Location: https://topfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t
            Server: nginx
            Vary: Accept-Language, Cookie
            Content-Length: 0
            Connection: Close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.64970650.87.132.1744435876C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-26 19:33:53 UTC708OUTGET /cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t HTTP/1.1
            Host: topfloorlightandsound.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-26 19:33:54 UTC335INHTTP/1.1 200 OK
            Date: Tue, 26 Mar 2024 19:33:54 GMT
            Server: Apache
            Upgrade: h2,h2c
            Connection: Upgrade, close
            Last-Modified: Tue, 26 Mar 2024 19:07:45 GMT
            Accept-Ranges: bytes
            Content-Length: 1539
            Cache-Control: max-age=1
            Expires: Tue, 26 Mar 2024 19:33:55 GMT
            Vary: Accept-Encoding
            Content-Type: application/x-httpd-php
            2024-03-26 19:33:54 UTC1539INData Raw: 3c 3f 70 68 70 0a 2f 2a 2a 0a 20 2a 20 40 70 61 63 6b 61 67 65 20 20 20 20 4a 6f 6f 6d 6c 61 2e 41 64 6d 69 6e 69 73 74 72 61 74 6f 72 0a 20 2a 0a 20 2a 20 40 63 6f 70 79 72 69 67 68 74 20 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 32 30 30 35 20 2d 20 32 30 31 38 20 4f 70 65 6e 20 53 6f 75 72 63 65 20 4d 61 74 74 65 72 73 2c 20 49 6e 63 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 0a 20 2a 20 40 6c 69 63 65 6e 73 65 20 20 20 20 47 4e 55 20 47 65 6e 65 72 61 6c 20 50 75 62 6c 69 63 20 4c 69 63 65 6e 73 65 20 76 65 72 73 69 6f 6e 20 32 20 6f 72 20 6c 61 74 65 72 3b 20 73 65 65 20 4c 49 43 45 4e 53 45 2e 74 78 74 0a 20 2a 2f 0a 0a 2f 2a 2a 0a 20 2a 20 44 65 66 69 6e 65 20 74 68 65 20 61 70 70 6c 69 63 61 74 69 6f 6e 27 73 20 6d 69 6e
            Data Ascii: <?php/** * @package Joomla.Administrator * * @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved. * @license GNU General Public License version 2 or later; see LICENSE.txt *//** * Define the application's min


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.64971023.221.242.90443
            TimestampBytes transferredDirectionData
            2024-03-26 19:33:56 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-26 19:33:56 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/073D)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=127849
            Date: Tue, 26 Mar 2024 19:33:56 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.64971123.221.242.90443
            TimestampBytes transferredDirectionData
            2024-03-26 19:33:56 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-26 19:33:57 UTC774INHTTP/1.1 200 OK
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-CID: 7
            X-CCC: US
            X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
            X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
            Content-Type: application/octet-stream
            X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=127803
            Date: Tue, 26 Mar 2024 19:33:57 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-03-26 19:33:57 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:0
            Start time:20:33:46
            Start date:26/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:20:33:49
            Start date:26/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=2020,i,7158565139567169839,16495825416727787881,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:20:33:51
            Start date:26/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://manage.kmail-lists.com/subscriptions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t"
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly