Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd

Overview

General Information

Sample URL:https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd
Analysis ID:1468064
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 764 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1992,i,5588072409586940604,816282141291767438,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5908 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: global trafficTCP traffic: 192.168.2.5:49710 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.5:49671 -> 1.1.1.1:53
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.cognitoforms.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1720165847803&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: classification engineClassification label: unknown1.win@17/6@4/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1992,i,5588072409586940604,816282141291767438,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1992,i,5588072409586940604,816282141291767438,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1468064 URL: https://www.cognitoforms.co... Startdate: 05/07/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 8 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49671, 49703 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 172.217.16.132, 443, 49715 GOOGLEUS United States 10->17 19 www.cognitoforms.com 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd0%Avira URL Cloudsafe
https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
www.google.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
www.cognitoforms.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
www.google.com
172.217.16.132
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
www.cognitoforms.com
unknown
unknownfalseunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
239.255.255.250
unknownReserved
unknownunknownfalse
172.217.16.132
www.google.comUnited States
15169GOOGLEUSfalse
IP
192.168.2.5
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1468064
Start date and time:2024-07-05 09:50:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:browseurl.jbs
Sample URL:https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:UNKNOWN
Classification:unknown1.win@17/6@4/3
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • URL browsing timeout or error
  • URL not reachable
  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 142.250.184.227, 64.233.166.84, 172.217.18.14, 34.104.35.123, 20.246.218.104, 2.19.85.159, 40.127.169.103, 192.229.221.95, 199.232.210.172, 20.242.39.171, 20.3.187.198, 13.85.23.206
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, agcognitoformsprod.eastus.cloudapp.azure.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtSetInformationFile calls found.
No simulations
No context
No context
No context
No context
No context
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jul 5 06:51:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2677
Entropy (8bit):3.9726857427358047
Encrypted:false
SSDEEP:48:8XudxT59FHnidAKZdA19ehwiZUklqehny+3:8ULLUy
MD5:55F34FF4218A7D2527F074D4113EED70
SHA1:1C63041CFDE3D2777A96B6AAAF676658983FCFE5
SHA-256:612439E6521EC99328820918C0B501901D520A7C5B2664C694EB8294CD202776
SHA-512:FEA6B4CD5F4B0AB9A18553BB45DA7BD92419241E56DB99B0AA30C5098F7E1EB81C32BE65051759D87D1BE71E4D92DC250780C01AB7D05502F8D8494F35D84FD1
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......y.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xc>...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jul 5 06:51:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2679
Entropy (8bit):3.985889156599839
Encrypted:false
SSDEEP:48:80dxT59FHnidAKZdA1weh/iZUkAQkqehEy+2:8mL59QVy
MD5:9D0EE6A0489827E89391E1B785C50F7D
SHA1:8B38B99248AB32502FE799D3604B8AD1D7FD31D8
SHA-256:CAF971C93D372ADFC7A73441F403BD437D0F3D7063FF2D71EE46D8E3B10A383A
SHA-512:C4FC28272B84C92634EBC1FAE5566B0C968281802DE09A14997132A7888FA4C7E7F7B2FE2D9E18F466C7C6BE33F7C226BD27B2B1EB04D4433C8ED1E158717476
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......k.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xc>...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2693
Entropy (8bit):3.999419161319498
Encrypted:false
SSDEEP:48:8x2dxT59sHnidAKZdA14tseh7sFiZUkmgqeh7sqy+BX:8x8Lanwy
MD5:60B7BC34FACC72DA30B7BAEE962552B0
SHA1:74BD04360CAA7A6311D3C63DF59F7AB3A0FB3C96
SHA-256:D404F13B25736A3A4B7AEA68BBA0051EA2CE18EA6A4692C9CDD2060F7CDF1ABB
SHA-512:335DAF2FB159BB5DA2877EEB2DC38D3126CAF1A4ED4531B50F044DF3F66B637DB3C1DEA8981E960EC8F6A408F64436432D82355E35D5BFC126071E98FBE9C9F4
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jul 5 06:51:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2681
Entropy (8bit):3.9862065659684878
Encrypted:false
SSDEEP:48:8WzdxT59FHnidAKZdA1vehDiZUkwqehIy+R:8WjLaiy
MD5:D2A6555B4C926E8D31E113EF66016F20
SHA1:43189247E5DFFF4856772722376DA3B54C66C3B1
SHA-256:23174A7D47886F947BAD706C7709E39549BCC7168B618DABEB26A62C36876E6C
SHA-512:41F25AA91C9A74DA83B3C1872554CF789BD084E42FE493F29B5680B2A55EC22AF32F7D9EC5602AE46F61F3E3CCF9163C22FF493ACD5355D4EA47096660284553
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......f.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xc>...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jul 5 06:51:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2681
Entropy (8bit):3.9734378942622413
Encrypted:false
SSDEEP:48:8gdxT59FHnidAKZdA1hehBiZUk1W1qehGy+C:8iLa9my
MD5:39C51194E35B042E86A63B5C5B06780E
SHA1:1768CA7480EF8C153BE51974B836198E8962F9F7
SHA-256:E3714C9D5EE0BE0B40FF210AB836CFF05C2DC5EA6FBA6217BD6179DF8624430A
SHA-512:E4B80D2926C626882E48D25E0DD554855EB47AC9E7F5DB6FA34CEAE24E478F5B4073A489E4C475430BEE508F23E2F19FA5941423C76E202C20BD4B503DB64CFC
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......t.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xc>...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jul 5 06:51:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2683
Entropy (8bit):3.9854761567715995
Encrypted:false
SSDEEP:48:84NdxT59FHnidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbwy+yT+:8WLkT/TbxWOvTbwy7T
MD5:C353D952A56559500800E02D2832E6AD
SHA1:7727BA8B5F96A484EEFB0E25A1972C6D9F9CE576
SHA-256:161437485E222848C2A6F1223D515C036D4299BD71A752CB29E4226C878A8778
SHA-512:742A8DDF664A00B60228C950A904E5AA0291793D7ECF7070D23F35E0E892027C14428D6CE0621AD6D752F220A6D2FAF344CEAA3E2315C2FE7688E70647405B3F
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,.....L^.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xa>....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xa>....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xa>....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xa>..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xc>...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........l=!&.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
No static file info
TimestampSource PortDest PortSource IPDest IP
Jul 5, 2024 09:50:57.920178890 CEST49674443192.168.2.523.1.237.91
Jul 5, 2024 09:50:57.922063112 CEST49675443192.168.2.523.1.237.91
Jul 5, 2024 09:50:58.092070103 CEST49673443192.168.2.523.1.237.91
Jul 5, 2024 09:51:04.651412964 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.657350063 CEST53497101.1.1.1192.168.2.5
Jul 5, 2024 09:51:04.657423973 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.657525063 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.657579899 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.663223028 CEST53497101.1.1.1192.168.2.5
Jul 5, 2024 09:51:04.663233995 CEST53497101.1.1.1192.168.2.5
Jul 5, 2024 09:51:05.149331093 CEST53497101.1.1.1192.168.2.5
Jul 5, 2024 09:51:05.149663925 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:05.155035019 CEST53497101.1.1.1192.168.2.5
Jul 5, 2024 09:51:05.155106068 CEST4971053192.168.2.51.1.1.1
Jul 5, 2024 09:51:07.530699968 CEST49675443192.168.2.523.1.237.91
Jul 5, 2024 09:51:07.530702114 CEST49674443192.168.2.523.1.237.91
Jul 5, 2024 09:51:07.702616930 CEST49673443192.168.2.523.1.237.91
Jul 5, 2024 09:51:07.705316067 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:07.705348969 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:07.712227106 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:07.712680101 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:07.712697983 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.363168001 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.408716917 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:08.507805109 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:08.507817030 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.509047031 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.509068012 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.509180069 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:08.511640072 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:08.511713982 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.562208891 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:08.562216043 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:08.608824968 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:09.368407965 CEST4434970323.1.237.91192.168.2.5
Jul 5, 2024 09:51:09.368488073 CEST49703443192.168.2.523.1.237.91
Jul 5, 2024 09:51:18.265145063 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:18.265202999 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:18.266048908 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:19.443331003 CEST49703443192.168.2.523.1.237.91
Jul 5, 2024 09:51:19.443840027 CEST49703443192.168.2.523.1.237.91
Jul 5, 2024 09:51:19.444669962 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:19.444684029 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:19.444838047 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:19.446569920 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:19.446579933 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:19.448194027 CEST4434970323.1.237.91192.168.2.5
Jul 5, 2024 09:51:19.448875904 CEST4434970323.1.237.91192.168.2.5
Jul 5, 2024 09:51:19.644820929 CEST49715443192.168.2.5172.217.16.132
Jul 5, 2024 09:51:19.644848108 CEST44349715172.217.16.132192.168.2.5
Jul 5, 2024 09:51:20.046530008 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.046617031 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.279822111 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.279836893 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.280227900 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.280287027 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.352231026 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.352286100 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.352644920 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.352653027 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.620696068 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.620769978 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.621481895 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.621521950 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:20.621540070 CEST4434972123.1.237.91192.168.2.5
Jul 5, 2024 09:51:20.621598005 CEST49721443192.168.2.523.1.237.91
Jul 5, 2024 09:51:22.741914034 CEST4967153192.168.2.51.1.1.1
Jul 5, 2024 09:51:22.746742964 CEST53496711.1.1.1192.168.2.5
Jul 5, 2024 09:51:22.746942043 CEST4967153192.168.2.51.1.1.1
Jul 5, 2024 09:51:22.746942043 CEST4967153192.168.2.51.1.1.1
Jul 5, 2024 09:51:22.751735926 CEST53496711.1.1.1192.168.2.5
Jul 5, 2024 09:51:23.209341049 CEST53496711.1.1.1192.168.2.5
Jul 5, 2024 09:51:23.209986925 CEST4967153192.168.2.51.1.1.1
Jul 5, 2024 09:51:23.215183973 CEST53496711.1.1.1192.168.2.5
Jul 5, 2024 09:51:23.215259075 CEST4967153192.168.2.51.1.1.1
TimestampSource PortDest PortSource IPDest IP
Jul 5, 2024 09:51:03.348664045 CEST53540791.1.1.1192.168.2.5
Jul 5, 2024 09:51:03.384696007 CEST53535901.1.1.1192.168.2.5
Jul 5, 2024 09:51:04.650865078 CEST53574151.1.1.1192.168.2.5
Jul 5, 2024 09:51:04.852941990 CEST5829253192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.853128910 CEST6520553192.168.2.51.1.1.1
Jul 5, 2024 09:51:04.879539967 CEST53652051.1.1.1192.168.2.5
Jul 5, 2024 09:51:07.194983006 CEST6042453192.168.2.51.1.1.1
Jul 5, 2024 09:51:07.195301056 CEST6151453192.168.2.51.1.1.1
Jul 5, 2024 09:51:07.302552938 CEST53615141.1.1.1192.168.2.5
Jul 5, 2024 09:51:07.303234100 CEST53604241.1.1.1192.168.2.5
Jul 5, 2024 09:51:21.689873934 CEST53607121.1.1.1192.168.2.5
Jul 5, 2024 09:51:22.741353035 CEST53578601.1.1.1192.168.2.5
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Jul 5, 2024 09:51:04.852941990 CEST192.168.2.51.1.1.10x4bd7Standard query (0)www.cognitoforms.comA (IP address)IN (0x0001)false
Jul 5, 2024 09:51:04.853128910 CEST192.168.2.51.1.1.10xa3a7Standard query (0)www.cognitoforms.com65IN (0x0001)false
Jul 5, 2024 09:51:07.194983006 CEST192.168.2.51.1.1.10x9612Standard query (0)www.google.comA (IP address)IN (0x0001)false
Jul 5, 2024 09:51:07.195301056 CEST192.168.2.51.1.1.10xf7fcStandard query (0)www.google.com65IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Jul 5, 2024 09:51:04.879295111 CEST1.1.1.1192.168.2.50x4bd7No error (0)www.cognitoforms.comagcognitoformsprod.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
Jul 5, 2024 09:51:04.879539967 CEST1.1.1.1192.168.2.50xa3a7No error (0)www.cognitoforms.comagcognitoformsprod.eastus.cloudapp.azure.comCNAME (Canonical name)IN (0x0001)false
Jul 5, 2024 09:51:07.302552938 CEST1.1.1.1192.168.2.50xf7fcNo error (0)www.google.com65IN (0x0001)false
Jul 5, 2024 09:51:07.303234100 CEST1.1.1.1192.168.2.50x9612No error (0)www.google.com172.217.16.132A (IP address)IN (0x0001)false
Jul 5, 2024 09:51:18.754574060 CEST1.1.1.1192.168.2.50x9451No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
Jul 5, 2024 09:51:18.754574060 CEST1.1.1.1192.168.2.50x9451No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
Jul 5, 2024 09:51:19.222383976 CEST1.1.1.1192.168.2.50x61b0No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
Jul 5, 2024 09:51:19.222383976 CEST1.1.1.1192.168.2.50x61b0No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
  • https:
    • www.bing.com
Session IDSource IPSource PortDestination IPDestination Port
0192.168.2.54972123.1.237.91443
TimestampBytes transferredDirectionData
2024-07-05 07:51:20 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
Origin: https://www.bing.com
Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
Accept: */*
Accept-Language: en-CH
Content-type: text/xml
X-Agent-DeviceId: 01000A410900D492
X-BM-CBT: 1696428841
X-BM-DateFormat: dd/MM/yyyy
X-BM-DeviceDimensions: 784x984
X-BM-DeviceDimensionsLogical: 784x984
X-BM-DeviceScale: 100
X-BM-DTZ: 120
X-BM-Market: CH
X-BM-Theme: 000000;0078d7
X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
X-Device-isOptin: false
X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
X-Device-OSSKU: 48
X-Device-Touch: false
X-DeviceID: 01000A410900D492
X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
X-MSEdge-ExternalExpType: JointCoord
X-PositionerType: Desktop
X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
X-Search-CortanaAvailableCapabilities: None
X-Search-SafeSearch: Moderate
X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
X-UserAgeClass: Unknown
Accept-Encoding: gzip, deflate, br
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
Host: www.bing.com
Content-Length: 2484
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1720165847803&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
2024-07-05 07:51:20 UTC1OUTData Raw: 3c
Data Ascii: <
2024-07-05 07:51:20 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
2024-07-05 07:51:20 UTC480INHTTP/1.1 204 No Content
Access-Control-Allow-Origin: *
Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
X-MSEdge-Ref: Ref A: 411BEF606FE5467E9D71BC4AF16EE017 Ref B: LAX311000108051 Ref C: 2024-07-05T07:51:20Z
Date: Fri, 05 Jul 2024 07:51:20 GMT
Connection: close
Alt-Svc: h3=":443"; ma=93600
X-CDN-TraceID: 0.57ed0117.1720165880.290fb9cc


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:03:50:58
Start date:05/07/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:03:51:01
Start date:05/07/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1992,i,5588072409586940604,816282141291767438,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:3
Start time:03:51:03
Start date:05/07/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.cognitoforms.com/ScutumUKLtd/ScutumUKLtd"
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly