Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://13.89.179.14

Overview

General Information

Sample URL:http://13.89.179.14
Analysis ID:1467812
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2800 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2220,i,6200660111485196733,2155855620605984432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://13.89.179.14" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownTCP traffic detected without corresponding DNS query: 13.89.179.14
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 13.89.179.14Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 13.89.179.14Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 13.89.179.14Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@18/0@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2220,i,6200660111485196733,2155855620605984432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://13.89.179.14"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2220,i,6200660111485196733,2155855620605984432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://13.89.179.140%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://13.89.179.14/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    www.google.com
    142.250.186.132
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://13.89.179.14/false
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        13.89.179.14
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        142.250.186.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1467812
        Start date and time:2024-07-04 20:06:38 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 31s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://13.89.179.14
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@18/0@2/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 74.125.71.84, 216.58.206.67, 216.58.206.46, 34.104.35.123, 40.68.123.157, 199.232.214.172, 13.85.23.206, 192.229.221.95, 20.242.39.171
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: http://13.89.179.14
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jul 4, 2024 20:07:24.162111998 CEST49675443192.168.2.4173.222.162.32
        Jul 4, 2024 20:07:33.159451962 CEST4973380192.168.2.413.89.179.14
        Jul 4, 2024 20:07:33.159579039 CEST4973480192.168.2.413.89.179.14
        Jul 4, 2024 20:07:33.164515018 CEST804973313.89.179.14192.168.2.4
        Jul 4, 2024 20:07:33.164763927 CEST804973413.89.179.14192.168.2.4
        Jul 4, 2024 20:07:33.164861917 CEST4973380192.168.2.413.89.179.14
        Jul 4, 2024 20:07:33.164861917 CEST4973480192.168.2.413.89.179.14
        Jul 4, 2024 20:07:33.167834997 CEST4973480192.168.2.413.89.179.14
        Jul 4, 2024 20:07:33.172871113 CEST804973413.89.179.14192.168.2.4
        Jul 4, 2024 20:07:33.763797998 CEST49675443192.168.2.4173.222.162.32
        Jul 4, 2024 20:07:35.318795919 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.318830013 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:35.318912983 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.319104910 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.319119930 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:35.970052004 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:35.970386982 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.970407963 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:35.971271992 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:35.971348047 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.972726107 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:35.972784996 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:36.022247076 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:36.022257090 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:36.069138050 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:38.503361940 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:38.503422022 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:38.503511906 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:38.533304930 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:38.533328056 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.209880114 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.209956884 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.241025925 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.241058111 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.241290092 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.285727978 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.560203075 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.600507021 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.752135992 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.752420902 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.752597094 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.752597094 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.752644062 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.752661943 CEST49740443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.752670050 CEST44349740184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.901563883 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.901597977 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:39.901825905 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.901943922 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:39.901957989 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.550158024 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.550235033 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:40.552869081 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:40.552885056 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.553114891 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.557358980 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:40.600503922 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.829910994 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.829969883 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:40.830014944 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:40.831487894 CEST49741443192.168.2.4184.28.90.27
        Jul 4, 2024 20:07:40.831506968 CEST44349741184.28.90.27192.168.2.4
        Jul 4, 2024 20:07:46.776197910 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:46.776264906 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:46.776318073 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:47.752295971 CEST49738443192.168.2.4142.250.186.132
        Jul 4, 2024 20:07:47.752327919 CEST44349738142.250.186.132192.168.2.4
        Jul 4, 2024 20:07:54.595756054 CEST804973313.89.179.14192.168.2.4
        Jul 4, 2024 20:07:54.595916986 CEST4973380192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.599607944 CEST804973413.89.179.14192.168.2.4
        Jul 4, 2024 20:07:54.599710941 CEST4973480192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.600235939 CEST4973480192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.600435019 CEST4973380192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.600816965 CEST4974880192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.604931116 CEST804973413.89.179.14192.168.2.4
        Jul 4, 2024 20:07:54.605602026 CEST804973313.89.179.14192.168.2.4
        Jul 4, 2024 20:07:54.605612040 CEST804974813.89.179.14192.168.2.4
        Jul 4, 2024 20:07:54.605716944 CEST4974880192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.608433962 CEST4974880192.168.2.413.89.179.14
        Jul 4, 2024 20:07:54.613226891 CEST804974813.89.179.14192.168.2.4
        Jul 4, 2024 20:08:16.064930916 CEST804974813.89.179.14192.168.2.4
        Jul 4, 2024 20:08:16.064996004 CEST4974880192.168.2.413.89.179.14
        Jul 4, 2024 20:08:16.065371037 CEST4974880192.168.2.413.89.179.14
        Jul 4, 2024 20:08:16.070703030 CEST804974813.89.179.14192.168.2.4
        Jul 4, 2024 20:08:17.096061945 CEST4974980192.168.2.413.89.179.14
        Jul 4, 2024 20:08:17.096477985 CEST4975080192.168.2.413.89.179.14
        Jul 4, 2024 20:08:17.101001978 CEST804974913.89.179.14192.168.2.4
        Jul 4, 2024 20:08:17.101243019 CEST4974980192.168.2.413.89.179.14
        Jul 4, 2024 20:08:17.101244926 CEST804975013.89.179.14192.168.2.4
        Jul 4, 2024 20:08:17.101339102 CEST4975080192.168.2.413.89.179.14
        Jul 4, 2024 20:08:17.128998041 CEST4975080192.168.2.413.89.179.14
        Jul 4, 2024 20:08:17.135068893 CEST804975013.89.179.14192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jul 4, 2024 20:07:31.089891911 CEST53526971.1.1.1192.168.2.4
        Jul 4, 2024 20:07:31.091280937 CEST53564761.1.1.1192.168.2.4
        Jul 4, 2024 20:07:32.237904072 CEST53531891.1.1.1192.168.2.4
        Jul 4, 2024 20:07:35.310646057 CEST5983153192.168.2.41.1.1.1
        Jul 4, 2024 20:07:35.310775042 CEST6489853192.168.2.41.1.1.1
        Jul 4, 2024 20:07:35.317610979 CEST53648981.1.1.1192.168.2.4
        Jul 4, 2024 20:07:35.317652941 CEST53598311.1.1.1192.168.2.4
        Jul 4, 2024 20:07:49.238281012 CEST53553891.1.1.1192.168.2.4
        Jul 4, 2024 20:07:50.871763945 CEST138138192.168.2.4192.168.2.255
        Jul 4, 2024 20:08:08.013560057 CEST53574571.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jul 4, 2024 20:07:35.310646057 CEST192.168.2.41.1.1.10x98eStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Jul 4, 2024 20:07:35.310775042 CEST192.168.2.41.1.1.10x9ea8Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jul 4, 2024 20:07:35.317610979 CEST1.1.1.1192.168.2.40x9ea8No error (0)www.google.com65IN (0x0001)false
        Jul 4, 2024 20:07:35.317652941 CEST1.1.1.1192.168.2.40x98eNo error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
        Jul 4, 2024 20:07:47.772490978 CEST1.1.1.1192.168.2.40xd479No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Jul 4, 2024 20:07:47.772490978 CEST1.1.1.1192.168.2.40xd479No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Jul 4, 2024 20:07:49.426609039 CEST1.1.1.1192.168.2.40x47f6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Jul 4, 2024 20:07:49.426609039 CEST1.1.1.1192.168.2.40x47f6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Jul 4, 2024 20:08:04.374279022 CEST1.1.1.1192.168.2.40x792No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Jul 4, 2024 20:08:04.374279022 CEST1.1.1.1192.168.2.40x792No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Jul 4, 2024 20:08:23.138015032 CEST1.1.1.1192.168.2.40xfa1eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Jul 4, 2024 20:08:23.138015032 CEST1.1.1.1192.168.2.40xfa1eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        • fs.microsoft.com
        • 13.89.179.14
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973413.89.179.14805236C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jul 4, 2024 20:07:33.167834997 CEST427OUTGET / HTTP/1.1
        Host: 13.89.179.14
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44974813.89.179.14805236C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jul 4, 2024 20:07:54.608433962 CEST427OUTGET / HTTP/1.1
        Host: 13.89.179.14
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.44975013.89.179.14805236C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jul 4, 2024 20:08:17.128998041 CEST453OUTGET / HTTP/1.1
        Host: 13.89.179.14
        Connection: keep-alive
        Cache-Control: max-age=0
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449740184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-07-04 18:07:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-07-04 18:07:39 UTC466INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/0758)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus-z1
        Cache-Control: public, max-age=46583
        Date: Thu, 04 Jul 2024 18:07:39 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449741184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-07-04 18:07:40 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-07-04 18:07:40 UTC514INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-weu-z1
        Cache-Control: public, max-age=46603
        Date: Thu, 04 Jul 2024 18:07:40 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-07-04 18:07:40 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:14:07:26
        Start date:04/07/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:14:07:29
        Start date:04/07/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2220,i,6200660111485196733,2155855620605984432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:14:07:32
        Start date:04/07/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://13.89.179.14"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly