Edit tour

Windows Analysis Report
http://topquickly24.azurewebsites.net

Overview

General Information

Sample URL:http://topquickly24.azurewebsites.net
Analysis ID:1434744
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1900,i,834170623825917703,9133782242694304978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6524 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://topquickly24.azurewebsites.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://topquickly24.azurewebsites.netAvira URL Cloud: detection malicious, Label: malware
Source: https://topquickly24.azurewebsites.net/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.209.58.93
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=uXtfNlR9O6nBVx2&MD=y4xUdvGP HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=uXtfNlR9O6nBVx2&MD=y4xUdvGP HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: topquickly24.azurewebsites.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.209.58.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/4@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1900,i,834170623825917703,9133782242694304978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://topquickly24.azurewebsites.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1900,i,834170623825917703,9133782242694304978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1434744 URL: http://topquickly24.azurewe... Startdate: 01/05/2024 Architecture: WINDOWS Score: 48 26 Antivirus / Scanner detection for submitted sample 2->26 6 chrome.exe 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49741 unknown unknown 6->14 16 192.168.2.5 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 142.251.111.105, 443, 49741, 49752 GOOGLEUS United States 11->20 22 waws-prod-blu-577.sip.azurewebsites.windows.net 11->22 24 topquickly24.azurewebsites.net 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://topquickly24.azurewebsites.net100%Avira URL Cloudmalware
http://topquickly24.azurewebsites.net1%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
topquickly24.azurewebsites.net1%VirustotalBrowse
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.111.105
truefalse
    high
    topquickly24.azurewebsites.net
    unknown
    unknownfalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://topquickly24.azurewebsites.net/false
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.251.111.105
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      192.168.2.5
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1434744
      Start date and time:2024-05-01 17:29:37 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 5s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://topquickly24.azurewebsites.net
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal48.win@17/4@8/4
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.253.115.94, 142.251.16.100, 142.251.16.101, 142.251.16.139, 142.251.16.102, 142.251.16.113, 142.251.16.138, 142.251.111.84, 34.104.35.123, 20.119.16.58, 23.207.202.21, 192.229.211.108, 199.232.210.172, 64.233.180.94
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, waws-prod-blu-577-629d.eastus.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):555
      Entropy (8bit):4.742453633590748
      Encrypted:false
      SSDEEP:12:TjeRHVIdtklI5rxINGlTF5TF5TF5TF5TF5TFK:neRH68s7TPTPTPTPTPTc
      MD5:92D1240D0145792EE71E684CFCA8F575
      SHA1:868C60C9FF18397741C904E9F44409BF95D1CE2F
      SHA-256:023AE51653C14E6CE9DE83D964FB9146328DCC3A9C5166D958546B6BF609F549
      SHA-512:87BA1302E08FAF8309F4210B7E648DBEBCB249C781DE447A12B527F92E639A2DA9BC70A08B327F8FBE5EB71ED625540C7F674FB14FC7FDAFAFA69D8209FC9FA7
      Malicious:false
      Reputation:low
      URL:https://topquickly24.azurewebsites.net/favicon.ico
      Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.23.2</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):552
      Entropy (8bit):4.678812567774494
      Encrypted:false
      SSDEEP:12:TjeRHVIdtklI5INGlTF5TF5TF5TF5TF5TFK:neRH68iTPTPTPTPTPTc
      MD5:AD76203CBB9FEB6A77342842816F7B51
      SHA1:12150FB48E15B3DAA031A2AD5F3D011976A1C068
      SHA-256:A980B60A8922F510D2DA527E74EC9443A57DCC65444DBD6A3AE87DCEB28090EB
      SHA-512:85B1BD5C232A000551CA69D9832ECFBA1AE61C42EC8E91847DE76B4B711F5A39AA3D0BF71F4062F855584C64B3B526D4D11885309F7ABCDB42C7CFEFEFCAB088
      Malicious:false
      Reputation:low
      URL:https://topquickly24.azurewebsites.net/
      Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>openresty</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
      No static file info

      Download Network PCAP: filteredfull

      • Total Packets: 73
      • 443 (HTTPS)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      May 1, 2024 17:30:19.471472979 CEST49678443192.168.2.4104.46.162.224
      May 1, 2024 17:30:19.690207958 CEST49675443192.168.2.4173.222.162.32
      May 1, 2024 17:30:29.293329000 CEST49675443192.168.2.4173.222.162.32
      May 1, 2024 17:30:32.254901886 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.254939079 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.255016088 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.255234003 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.255248070 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.454102993 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.461457968 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.461479902 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.462519884 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.462587118 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.470400095 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.470484018 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.548423052 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:32.548439980 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:32.735961914 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:35.160531998 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.160578966 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.160645962 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.162393093 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.162406921 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.359364033 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.359422922 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.362030029 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.362037897 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.362272024 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.403820992 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.448111057 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.543095112 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.543160915 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.546025038 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.546025038 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.546137094 CEST49742443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.546154022 CEST4434974223.209.58.93192.168.2.4
      May 1, 2024 17:30:35.590718985 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.590754032 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.593916893 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.594464064 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.594472885 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.792448997 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.792565107 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.796068907 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.796081066 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.796293020 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.798307896 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:35.844110966 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.980149031 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.980320930 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:35.980663061 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:36.845716953 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:36.845746994 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:36.845763922 CEST49743443192.168.2.423.209.58.93
      May 1, 2024 17:30:36.845772028 CEST4434974323.209.58.93192.168.2.4
      May 1, 2024 17:30:41.799854040 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:41.799900055 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:41.799973965 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:41.801090002 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:41.801104069 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:42.374922991 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:42.375212908 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:42.378048897 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:42.378057003 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:42.378309965 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:42.423454046 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:42.451828003 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:42.451889992 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:30:42.452146053 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:42.738893986 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:42.780128956 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113763094 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113799095 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113821983 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113841057 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113859892 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.113893986 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113908052 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113918066 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.113924980 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113946915 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.113955021 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.113985062 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.113993883 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.113998890 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.114027023 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.114073038 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.343708992 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.343735933 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.343746901 CEST49744443192.168.2.440.127.169.103
      May 1, 2024 17:30:43.343754053 CEST4434974440.127.169.103192.168.2.4
      May 1, 2024 17:30:43.643807888 CEST49741443192.168.2.4142.251.111.105
      May 1, 2024 17:30:43.643842936 CEST44349741142.251.111.105192.168.2.4
      May 1, 2024 17:31:19.872976065 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:19.873023033 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:19.873150110 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:19.873884916 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:19.873898029 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:20.447179079 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:20.447263956 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:20.451131105 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:20.451138973 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:20.451376915 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:20.461616039 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:20.508120060 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011404991 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011416912 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011467934 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011523008 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:21.011540890 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011554003 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011560917 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.011560917 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:21.011612892 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:21.102835894 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:21.102850914 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:21.102888107 CEST49750443192.168.2.440.127.169.103
      May 1, 2024 17:31:21.102894068 CEST4434975040.127.169.103192.168.2.4
      May 1, 2024 17:31:31.800698996 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:31.800723076 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:31.800803900 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:31.801074982 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:31.801084042 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:31.994695902 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:31.994977951 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:31.994987965 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:31.995275974 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:31.995589018 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:31.995645046 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:32.049243927 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:41.993920088 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:41.993983984 CEST44349752142.251.111.105192.168.2.4
      May 1, 2024 17:31:41.994031906 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:43.807786942 CEST49752443192.168.2.4142.251.111.105
      May 1, 2024 17:31:43.807813883 CEST44349752142.251.111.105192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      May 1, 2024 17:30:27.557579994 CEST53585821.1.1.1192.168.2.4
      May 1, 2024 17:30:28.121164083 CEST53543021.1.1.1192.168.2.4
      May 1, 2024 17:30:28.728820086 CEST5247753192.168.2.41.1.1.1
      May 1, 2024 17:30:28.728950977 CEST5583753192.168.2.41.1.1.1
      May 1, 2024 17:30:28.841629028 CEST53558371.1.1.1192.168.2.4
      May 1, 2024 17:30:30.073792934 CEST5994753192.168.2.41.1.1.1
      May 1, 2024 17:30:30.073909044 CEST5890353192.168.2.41.1.1.1
      May 1, 2024 17:30:30.183413029 CEST53589031.1.1.1192.168.2.4
      May 1, 2024 17:30:30.440197945 CEST5464353192.168.2.41.1.1.1
      May 1, 2024 17:30:30.440375090 CEST5148153192.168.2.41.1.1.1
      May 1, 2024 17:30:30.548437119 CEST53514811.1.1.1192.168.2.4
      May 1, 2024 17:30:31.739923954 CEST6088353192.168.2.41.1.1.1
      May 1, 2024 17:30:31.740315914 CEST5256153192.168.2.41.1.1.1
      May 1, 2024 17:30:31.835515022 CEST53525611.1.1.1192.168.2.4
      May 1, 2024 17:30:31.836328030 CEST53608831.1.1.1192.168.2.4
      May 1, 2024 17:30:48.730794907 CEST53522581.1.1.1192.168.2.4
      May 1, 2024 17:30:49.993086100 CEST138138192.168.2.4192.168.2.255
      May 1, 2024 17:31:08.743463039 CEST53597541.1.1.1192.168.2.4
      May 1, 2024 17:31:27.300214052 CEST53642261.1.1.1192.168.2.4
      May 1, 2024 17:31:32.819149017 CEST53610351.1.1.1192.168.2.4
      TimestampSource IPDest IPChecksumCodeType
      May 1, 2024 17:30:30.182069063 CEST192.168.2.41.1.1.1c27c(Port unreachable)Destination Unreachable
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      May 1, 2024 17:30:28.728820086 CEST192.168.2.41.1.1.10xa8aaStandard query (0)topquickly24.azurewebsites.netA (IP address)IN (0x0001)false
      May 1, 2024 17:30:28.728950977 CEST192.168.2.41.1.1.10xbf92Standard query (0)topquickly24.azurewebsites.net65IN (0x0001)false
      May 1, 2024 17:30:30.073792934 CEST192.168.2.41.1.1.10xfaa1Standard query (0)topquickly24.azurewebsites.netA (IP address)IN (0x0001)false
      May 1, 2024 17:30:30.073909044 CEST192.168.2.41.1.1.10x349eStandard query (0)topquickly24.azurewebsites.net65IN (0x0001)false
      May 1, 2024 17:30:30.440197945 CEST192.168.2.41.1.1.10x3118Standard query (0)topquickly24.azurewebsites.netA (IP address)IN (0x0001)false
      May 1, 2024 17:30:30.440375090 CEST192.168.2.41.1.1.10x82f2Standard query (0)topquickly24.azurewebsites.net65IN (0x0001)false
      May 1, 2024 17:30:31.739923954 CEST192.168.2.41.1.1.10x5109Standard query (0)www.google.comA (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.740315914 CEST192.168.2.41.1.1.10x6066Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      May 1, 2024 17:30:28.834355116 CEST1.1.1.1192.168.2.40xa8aaNo error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:28.834355116 CEST1.1.1.1192.168.2.40xa8aaNo error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:28.841629028 CEST1.1.1.1192.168.2.40xbf92No error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:28.841629028 CEST1.1.1.1192.168.2.40xbf92No error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.181971073 CEST1.1.1.1192.168.2.40xfaa1No error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.181971073 CEST1.1.1.1192.168.2.40xfaa1No error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.183413029 CEST1.1.1.1192.168.2.40x349eNo error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.183413029 CEST1.1.1.1192.168.2.40x349eNo error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.548437119 CEST1.1.1.1192.168.2.40x82f2No error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.548437119 CEST1.1.1.1192.168.2.40x82f2No error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.550354958 CEST1.1.1.1192.168.2.40x3118No error (0)topquickly24.azurewebsites.netwaws-prod-blu-577.sip.azurewebsites.windows.netCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:30.550354958 CEST1.1.1.1192.168.2.40x3118No error (0)waws-prod-blu-577.sip.azurewebsites.windows.netwaws-prod-blu-577-629d.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
      May 1, 2024 17:30:31.835515022 CEST1.1.1.1192.168.2.40x6066No error (0)www.google.com65IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.105A (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.99A (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.104A (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.147A (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.103A (IP address)IN (0x0001)false
      May 1, 2024 17:30:31.836328030 CEST1.1.1.1192.168.2.40x5109No error (0)www.google.com142.251.111.106A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • slscr.update.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44974223.209.58.93443
      TimestampBytes transferredDirectionData
      2024-05-01 15:30:35 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-05-01 15:30:35 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/079C)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=142433
      Date: Wed, 01 May 2024 15:30:35 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974323.209.58.93443
      TimestampBytes transferredDirectionData
      2024-05-01 15:30:35 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-05-01 15:30:35 UTC774INHTTP/1.1 200 OK
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-CID: 7
      X-CCC: US
      X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
      X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
      Content-Type: application/octet-stream
      X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=142356
      Date: Wed, 01 May 2024 15:30:35 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-05-01 15:30:35 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.44974440.127.169.103443
      TimestampBytes transferredDirectionData
      2024-05-01 15:30:42 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=uXtfNlR9O6nBVx2&MD=y4xUdvGP HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
      Host: slscr.update.microsoft.com
      2024-05-01 15:30:43 UTC560INHTTP/1.1 200 OK
      Cache-Control: no-cache
      Pragma: no-cache
      Content-Type: application/octet-stream
      Expires: -1
      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
      ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
      MS-CorrelationId: 211b97d7-804f-42c9-b0ce-7f1d55a25e89
      MS-RequestId: b16c5063-0200-4496-9c25-d421d521e0b8
      MS-CV: 6/YwfAe2MUWI7O7L.0
      X-Microsoft-SLSClientCache: 2880
      Content-Disposition: attachment; filename=environment.cab
      X-Content-Type-Options: nosniff
      Date: Wed, 01 May 2024 15:30:42 GMT
      Connection: close
      Content-Length: 24490
      2024-05-01 15:30:43 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
      Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
      2024-05-01 15:30:43 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
      Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.44975040.127.169.103443
      TimestampBytes transferredDirectionData
      2024-05-01 15:31:20 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=uXtfNlR9O6nBVx2&MD=y4xUdvGP HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
      Host: slscr.update.microsoft.com
      2024-05-01 15:31:21 UTC560INHTTP/1.1 200 OK
      Cache-Control: no-cache
      Pragma: no-cache
      Content-Type: application/octet-stream
      Expires: -1
      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
      ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
      MS-CorrelationId: 0e526ed4-0a16-40f2-ad47-0273e85e0ec4
      MS-RequestId: 461eb3f2-06a4-4d66-a94e-7ead23c77d4c
      MS-CV: h2gWPZKQBE+mzQth.0
      X-Microsoft-SLSClientCache: 2160
      Content-Disposition: attachment; filename=environment.cab
      X-Content-Type-Options: nosniff
      Date: Wed, 01 May 2024 15:31:19 GMT
      Connection: close
      Content-Length: 25457
      2024-05-01 15:31:21 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
      Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
      2024-05-01 15:31:21 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
      Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


      020406080s020406080100

      Click to jump to process

      020406080s0.0050100MB

      Click to jump to process

      Target ID:0
      Start time:17:30:20
      Start date:01/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:17:30:25
      Start date:01/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1900,i,834170623825917703,9133782242694304978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:17:30:27
      Start date:01/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://topquickly24.azurewebsites.net"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly