Edit tour

Windows Analysis Report
https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg

Overview

General Information

Sample URL:https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg
Analysis ID:1456985
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port
HTTP GET or POST without a user agent

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2224,i,311137775402865680,14180682605251535301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6376 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRgHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:57575 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:57573 -> 1.1.1.1:53
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ipinfo.ioConnection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ipinfo.ioConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 57575 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57584
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57575
Source: unknownNetwork traffic detected: HTTP traffic on port 57584 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:57575 version: TLS 1.2
Source: classification engineClassification label: clean1.win@21/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2224,i,311137775402865680,14180682605251535301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2224,i,311137775402865680,14180682605251535301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1456985 URL: https://www.gstatic.com/og/... Startdate: 14/06/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49741 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 142.250.184.228, 443, 57584 GOOGLEUS United States 10->17 19 www.google.com 142.250.186.164, 443, 49741 GOOGLEUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://ipinfo.io/0%URL Reputationsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.186.164
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://ipinfo.io/false
        • URL Reputation: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.186.164
        www.google.comUnited States
        15169GOOGLEUSfalse
        142.250.184.228
        unknownUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1456985
        Start date and time:2024-06-14 01:05:25 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 11s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:9
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean1.win@21/4@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.185.131, 66.102.1.84, 172.217.16.206, 142.250.185.227, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.221.95, 20.242.39.171, 13.95.31.18, 40.68.123.157, 142.250.184.227, 20.114.59.183
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:ASCII text, with very long lines (2133), with no line terminators
        Category:downloaded
        Size (bytes):2133
        Entropy (8bit):5.191759202293887
        Encrypted:false
        SSDEEP:48:YZUJVKLLJEconBdbeJyY8ZUvGCUvGU7HgbOW:zJY2co3zY8q6gbOW
        MD5:AE5FB6E198729BFFE5FAF94DB067CBD7
        SHA1:0C4B950BFC4B91F98A49BCDA9F922DCAFD12EE1E
        SHA-256:7F6451F157181FC3A7E60E249631AB7F065CFA2730E1E3CB3E9D970C2E6BBEAA
        SHA-512:EF48334D1FA9AAB180108EBEFFD36DB1C59ED08E34E551E071EDD0A123DC54B60BE858C37AB7785345F36956DE2064C811BE46C9754B21BF565A2ABA3A69F286
        Malicious:false
        Reputation:low
        URL:"https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg"
        Preview:.gb_q{display:none!important}.gb_3e{background:rgba(60,64,67,.9);-webkit-border-radius:4px;border-radius:4px;color:#fff;font:500 12px "Roboto",arial,sans-serif;letter-spacing:.8px;line-height:16px;margin-top:4px;min-height:14px;padding:4px 8px;position:absolute;z-index:1000;-webkit-font-smoothing:antialiased}.gb_Hc{text-align:left}.gb_Hc>*{color:#bdc1c6;line-height:16px}.gb_Hc div:first-child{color:white}.gb_pa{background:none;border:1px solid transparent;-webkit-border-radius:50%;border-radius:50%;-webkit-box-sizing:border-box;box-sizing:border-box;cursor:pointer;height:40px;margin:8px;outline:none;padding:1px;position:absolute;right:0;top:0;width:40px}.gb_pa:hover{background-color:rgba(68,71,70,.08)}.gb_pa:focus,.gb_pa:active{background-color:rgba(68,71,70,.12)}.gb_pa:focus-visible{border-color:#0b57d0;outline:1px solid transparent;outline-offset:-1px}.gb_i .gb_pa:hover,.gb_i .gb_pa:focus,.gb_i .gb_pa:active{background-color:rgba(227,227,227,.08)}.gb_i .gb_pa:focus-visible{border-col
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1136)
        Category:downloaded
        Size (bytes):1572
        Entropy (8bit):5.2647442020070505
        Encrypted:false
        SSDEEP:24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xTOS8f:3qD+2+pUAew85zsT9A
        MD5:13FEC0C2FBF5C47C4608CE0C9405E5A7
        SHA1:DAFB6CA27CFD22E88A2D53150C4350FCA3D32A21
        SHA-256:7F25FD0260C4EF8C26A87A5A126634E846BA539C75E5D508103F4D98831654A5
        SHA-512:7B9C5B92CDB7C3CEA0B6B862EBE67F75D92C1F1A8D5AAFE771CA50A724E4AF7F3C1CA280CBC53BF3EA3FB6344C41D1BA06BC032FC9B408C3B30BD301239CD001
        Malicious:false
        Reputation:low
        URL:https://www.gstatic.com/favicon.ico
        Preview:<!DOCTYPE html>.<html lang=en>. <meta charset=utf-8>. <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">. <title>Error 404 (Not Found)!!1</title>. <style>. *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 49
        • 443 (HTTPS)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Jun 14, 2024 01:06:11.899302006 CEST49675443192.168.2.4173.222.162.32
        Jun 14, 2024 01:06:21.502074003 CEST49675443192.168.2.4173.222.162.32
        Jun 14, 2024 01:06:23.799909115 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:23.799961090 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:23.802786112 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:23.816107988 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:23.816155910 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.355907917 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:24.355998039 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:24.356103897 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:24.358833075 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:24.358908892 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:24.683408022 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.684796095 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:24.684828997 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.686356068 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.686687946 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:24.695591927 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:24.695700884 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.743283033 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:24.743314028 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:24.790173054 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:24.923403978 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:24.928219080 CEST53575731.1.1.1192.168.2.4
        Jun 14, 2024 01:06:24.928282022 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:24.928311110 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:24.933168888 CEST53575731.1.1.1192.168.2.4
        Jun 14, 2024 01:06:25.211214066 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.211296082 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.214704990 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.214764118 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.215174913 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.258932114 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.262624979 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.308501959 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.504090071 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.504235983 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.504514933 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.504514933 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.504515886 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.504606962 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.530308962 CEST53575731.1.1.1192.168.2.4
        Jun 14, 2024 01:06:25.571413994 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:25.590018988 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:25.595282078 CEST53575731.1.1.1192.168.2.4
        Jun 14, 2024 01:06:25.595340014 CEST5757353192.168.2.41.1.1.1
        Jun 14, 2024 01:06:25.671922922 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.672009945 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.672138929 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.672816992 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.672852993 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:25.800704002 CEST49742443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:25.800770998 CEST44349742184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.505341053 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.505441904 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:26.506545067 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:26.506577969 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.506927013 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.507920027 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:26.552501917 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.747698069 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.747769117 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:26.747824907 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:26.753123999 CEST57575443192.168.2.4184.28.90.27
        Jun 14, 2024 01:06:26.753158092 CEST44357575184.28.90.27192.168.2.4
        Jun 14, 2024 01:06:35.466114998 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:35.466247082 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:06:35.466296911 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:35.853015900 CEST49741443192.168.2.4142.250.186.164
        Jun 14, 2024 01:06:35.853045940 CEST44349741142.250.186.164192.168.2.4
        Jun 14, 2024 01:07:23.834157944 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:23.834253073 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:23.834328890 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:23.834882975 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:23.834922075 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:24.693178892 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:24.693481922 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:24.693552971 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:24.694025993 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:24.694427967 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:24.694525957 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:24.742084026 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:34.675709963 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:34.675779104 CEST44357584142.250.184.228192.168.2.4
        Jun 14, 2024 01:07:34.675838947 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:36.694293022 CEST57584443192.168.2.4142.250.184.228
        Jun 14, 2024 01:07:36.694341898 CEST44357584142.250.184.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jun 14, 2024 01:06:19.599411964 CEST53583081.1.1.1192.168.2.4
        Jun 14, 2024 01:06:19.645387888 CEST53653641.1.1.1192.168.2.4
        Jun 14, 2024 01:06:20.668658018 CEST53545241.1.1.1192.168.2.4
        Jun 14, 2024 01:06:20.876790047 CEST53629711.1.1.1192.168.2.4
        Jun 14, 2024 01:06:23.764229059 CEST5233153192.168.2.41.1.1.1
        Jun 14, 2024 01:06:23.771795034 CEST53523311.1.1.1192.168.2.4
        Jun 14, 2024 01:06:23.782763958 CEST5135953192.168.2.41.1.1.1
        Jun 14, 2024 01:06:23.789887905 CEST53513591.1.1.1192.168.2.4
        Jun 14, 2024 01:06:24.923058987 CEST53499121.1.1.1192.168.2.4
        Jun 14, 2024 01:06:38.937272072 CEST138138192.168.2.4192.168.2.255
        Jun 14, 2024 01:07:19.034791946 CEST53580421.1.1.1192.168.2.4
        Jun 14, 2024 01:07:23.825351000 CEST5666453192.168.2.41.1.1.1
        Jun 14, 2024 01:07:23.825592995 CEST6137953192.168.2.41.1.1.1
        Jun 14, 2024 01:07:23.832478046 CEST53613791.1.1.1192.168.2.4
        Jun 14, 2024 01:07:23.832870960 CEST53566641.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jun 14, 2024 01:06:23.764229059 CEST192.168.2.41.1.1.10x8d43Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Jun 14, 2024 01:06:23.782763958 CEST192.168.2.41.1.1.10xb6dcStandard query (0)www.google.com65IN (0x0001)false
        Jun 14, 2024 01:07:23.825351000 CEST192.168.2.41.1.1.10x1a9eStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Jun 14, 2024 01:07:23.825592995 CEST192.168.2.41.1.1.10x49a4Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jun 14, 2024 01:06:23.771795034 CEST1.1.1.1192.168.2.40x8d43No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
        Jun 14, 2024 01:06:23.789887905 CEST1.1.1.1192.168.2.40xb6dcNo error (0)www.google.com65IN (0x0001)false
        Jun 14, 2024 01:06:35.558186054 CEST1.1.1.1192.168.2.40x59eaNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Jun 14, 2024 01:06:35.558186054 CEST1.1.1.1192.168.2.40x59eaNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Jun 14, 2024 01:06:37.532219887 CEST1.1.1.1192.168.2.40x8a1bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Jun 14, 2024 01:06:37.532219887 CEST1.1.1.1192.168.2.40x8a1bNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Jun 14, 2024 01:06:50.343693018 CEST1.1.1.1192.168.2.40x49feNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Jun 14, 2024 01:06:50.343693018 CEST1.1.1.1192.168.2.40x49feNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Jun 14, 2024 01:07:23.832478046 CEST1.1.1.1192.168.2.40x49a4No error (0)www.google.com65IN (0x0001)false
        Jun 14, 2024 01:07:23.832870960 CEST1.1.1.1192.168.2.40x1a9eNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
        • ipinfo.io
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.44973034.117.186.192443
        TimestampBytes transferredDirectionData
        2024-06-13 23:06:10 UTC59OUTGET / HTTP/1.1
        Host: ipinfo.io
        Connection: Keep-Alive
        2024-06-13 23:06:10 UTC513INHTTP/1.1 200 OK
        server: nginx/1.24.0
        date: Thu, 13 Jun 2024 23:06:10 GMT
        content-type: application/json; charset=utf-8
        Content-Length: 314
        access-control-allow-origin: *
        x-frame-options: SAMEORIGIN
        x-xss-protection: 1; mode=block
        x-content-type-options: nosniff
        referrer-policy: strict-origin-when-cross-origin
        x-envoy-upstream-service-time: 1
        via: 1.1 google
        strict-transport-security: max-age=2592000; includeSubDomains
        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
        Connection: close
        2024-06-13 23:06:10 UTC314INData Raw: 7b 0a 20 20 22 69 70 22 3a 20 22 31 37 33 2e 32 35 34 2e 32 35 30 2e 39 31 22 2c 0a 20 20 22 68 6f 73 74 6e 61 6d 65 22 3a 20 22 31 37 33 2e 32 35 34 2e 32 35 30 2e 39 31 2e 73 74 61 74 69 63 2e 71 75 61 64 72 61 6e 65 74 2e 63 6f 6d 22 2c 0a 20 20 22 63 69 74 79 22 3a 20 22 44 61 6c 6c 61 73 22 2c 0a 20 20 22 72 65 67 69 6f 6e 22 3a 20 22 54 65 78 61 73 22 2c 0a 20 20 22 63 6f 75 6e 74 72 79 22 3a 20 22 55 53 22 2c 0a 20 20 22 6c 6f 63 22 3a 20 22 33 32 2e 38 31 35 32 2c 2d 39 36 2e 38 37 30 33 22 2c 0a 20 20 22 6f 72 67 22 3a 20 22 41 53 38 31 30 30 20 51 75 61 64 72 61 4e 65 74 20 45 6e 74 65 72 70 72 69 73 65 73 20 4c 4c 43 22 2c 0a 20 20 22 70 6f 73 74 61 6c 22 3a 20 22 37 35 32 34 37 22 2c 0a 20 20 22 74 69 6d 65 7a 6f 6e 65 22 3a 20 22 41 6d 65 72
        Data Ascii: { "ip": "173.254.250.91", "hostname": "173.254.250.91.static.quadranet.com", "city": "Dallas", "region": "Texas", "country": "US", "loc": "32.8152,-96.8703", "org": "AS8100 QuadraNet Enterprises LLC", "postal": "75247", "timezone": "Amer


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449742184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-06-13 23:06:25 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-06-13 23:06:25 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-neu-z1
        Cache-Control: public, max-age=234207
        Date: Thu, 13 Jun 2024 23:06:25 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.457575184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-06-13 23:06:26 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-06-13 23:06:26 UTC515INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-weu-z1
        Cache-Control: public, max-age=234175
        Date: Thu, 13 Jun 2024 23:06:26 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-06-13 23:06:26 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:0
        Start time:19:06:14
        Start date:13/06/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:19:06:17
        Start date:13/06/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2224,i,311137775402865680,14180682605251535301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:19:06:19
        Start date:13/06/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.gstatic.com/og/_/ss/k=og.qtm.0zhx-kg7174.L.W.O/m=qcwid/excm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/ct=zgms/rs=AA2YrTsFPCAfY7WVNwPZg_szF81wTTLGRg"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly