Edit tour

Windows Analysis Report
https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0

Overview

General Information

Sample URL:https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0
Analysis ID:1516609
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7032 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1872,i,6622761000618728035,9722359374662057473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6612 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: global trafficHTTP traffic detected: GET /scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0 HTTP/1.1Host: dl.dropboxusercontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /www/en-us/illustrations/spot/look-magnifying-glass.svg HTTP/1.1Host: assets.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /www/en-us/illustrations/spot/look-magnifying-glass.svg HTTP/1.1Host: assets.dropbox.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lc+v+fM+Ueyt4eP&MD=2+d5wtC3 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lc+v+fM+Ueyt4eP&MD=2+d5wtC3 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: dl.dropboxusercontent.com
Source: global trafficDNS traffic detected: DNS query: cfl.dropboxstatic.com
Source: global trafficDNS traffic detected: DNS query: assets.dropbox.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlContent-Security-Policy: sandbox allow-forms allow-scriptsDate: Tue, 24 Sep 2024 11:19:40 GMTServer: envoyContent-Length: 1457Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Robots-Tag: noindex, nofollow, noimageindexVary: Accept-EncodingX-Dropbox-Response-Origin: far_remoteX-Dropbox-Request-Id: c70e3475d46b42369b5e10ebff4f5ca6Connection: close
Source: chromecache_58.1.drString found in binary or memory: https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg
Source: chromecache_58.1.drString found in binary or memory: https://cfl.dropboxstatic.com/static/images/favicon.ico
Source: chromecache_58.1.drString found in binary or memory: https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/business?_tk=fof
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/help?_tk=fof
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/home?_tk=fof
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/login?_tk=fof
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/plus?_tk=fof
Source: chromecache_58.1.drString found in binary or memory: https://www.dropbox.com/register?_tk=fof
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/10@14/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1872,i,6622761000618728035,9722359374662057473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1872,i,6622761000618728035,9722359374662057473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1516609 URL: https://dl.dropboxuserconte... Startdate: 24/09/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 9 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.16, 138, 443, 49204 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.186.100, 443, 49721, 49728 GOOGLEUS United States 10->17 19 216.58.206.36, 443, 49730 GOOGLEUS United States 10->19 21 5 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=00%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.dropbox.com/plus?_tk=fof0%Avira URL Cloudsafe
https://www.dropbox.com/business?_tk=fof0%Avira URL Cloudsafe
https://cfl.dropboxstatic.com/static/images/favicon.ico0%Avira URL Cloudsafe
https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css0%Avira URL Cloudsafe
https://www.dropbox.com/home?_tk=fof0%Avira URL Cloudsafe
https://www.dropbox.com/register?_tk=fof0%Avira URL Cloudsafe
https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg0%Avira URL Cloudsafe
https://www.dropbox.com/help?_tk=fof0%Avira URL Cloudsafe
https://www.dropbox.com/login?_tk=fof0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
edge-block-www-env.dropbox-dns.com
162.125.66.15
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      unknown
      assets.dropbox.com
      52.222.236.19
      truefalse
        unknown
        dl.dropboxusercontent.com
        unknown
        unknownfalse
          unknown
          cfl.dropboxstatic.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svgfalse
            • Avira URL Cloud: safe
            unknown
            https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0false
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://www.dropbox.com/login?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.dropbox.com/plus?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.dropbox.com/business?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://cfl.dropboxstatic.com/static/images/favicon.icochromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.dropbox.com/home?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://cfl.dropboxstatic.com/static/metaserver/static/css/error.csschromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.dropbox.com/register?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.dropbox.com/help?_tk=fofchromecache_58.1.drfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              162.125.66.15
              edge-block-www-env.dropbox-dns.comUnited States
              19679DROPBOXUSfalse
              216.58.206.36
              unknownUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              52.222.236.51
              unknownUnited States
              16509AMAZON-02USfalse
              52.222.236.19
              assets.dropbox.comUnited States
              16509AMAZON-02USfalse
              142.250.186.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.16
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1516609
              Start date and time:2024-09-24 13:19:06 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 35s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Sample URL:https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:13
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@17/10@14/7
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.181.227, 142.250.185.206, 74.125.71.84, 34.104.35.123, 104.16.100.29, 104.16.99.29, 142.250.186.131, 142.250.186.78
              • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, cfl.dropboxstatic.com.cdn.cloudflare.net, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • VT rate limit hit for: https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&amp;st=s5ax4axs&amp;dl=0
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Sep 24 10:19:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2673
              Entropy (8bit):3.9830286054038924
              Encrypted:false
              SSDEEP:48:8XYd5ThRVHYUidAKZdA1FehwiZUklqehiy+3:82ri6py
              MD5:39EC88F429F2A2AE9C0D7302D7DA16F7
              SHA1:2C9D5D627A9EB7FAA0D4296A5AB35E2C740552D3
              SHA-256:7821A5A28516B0B1A763CD9DBFE03C183BB7DE1C7DEF88FB82DF7CCF0E0EE2E1
              SHA-512:5E8142F7761D4E3E9CBDA33CEFACE9F54978DEBCE101AA9FD7DE2C4A6BB6BB66AFBBCC7B040D99EF2FC4A25F152687AD56F5956F320D5CED45340684C6631085
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....V.s...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V8YuZ...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Sep 24 10:19:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2675
              Entropy (8bit):3.9984726750303796
              Encrypted:false
              SSDEEP:48:8nd5ThRVHYUidAKZdA1seh/iZUkAQkqehZy+2:8zri09Qsy
              MD5:F4547B68A9B4C8533101FA7AE8CEEDC6
              SHA1:382B6B7F966E70DE51B7D6A15FCF6FA59B6C8507
              SHA-256:8AE30093C91B299B7CC53C9367C67E6CBAD0EBFAD5E07C8033660447407B60A7
              SHA-512:9F40CB28E35977556763EBDCD7F195E1CD40BEB887A8385407800100C20F17507C676628491D6F799496F1EBF3B064AC08A8D3F309524FD5CCA3AB4A2CDE056E
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.......s...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V8YuZ...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2689
              Entropy (8bit):4.007314155566643
              Encrypted:false
              SSDEEP:48:8vd5ThRAHYUidAKZdA14meh7sFiZUkmgqeh7sLy+BX:8brj4ndy
              MD5:417FD0026B4E8BCDF39906337A64A6EF
              SHA1:1DC847671688FA80E69484913C01A6E854E96A51
              SHA-256:B1E9E64C75E9A729353A523B757AFE3143677C39CF1184BF633E136BBCF43283
              SHA-512:BA5F61E5286F575BE539CACDB0189822B651131C8F62991F15FD833326E271F408F0A57E327D04AAEC520FC5DD592ACB8B779E578CAD214E677236BCE3DAC95B
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Sep 24 10:19:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.9949797862109784
              Encrypted:false
              SSDEEP:48:8Wd5ThRVHYUidAKZdA1TehDiZUkwqehFy+R:8UrivTy
              MD5:8CAB1E7DA3DA6CFE92F0603AC5F79926
              SHA1:EA25097AEFEC2BDAC31DC6FC5FBA58E7857BE172
              SHA-256:F8DDA1609CC059287BEEE400F3355955B31EFDE14AB440D2BBB3FD5695260857
              SHA-512:C78366E037FF86D0B869F9E057AC5568E1C099DACE766B2AB4B8F6B8B22AB0AB70E6209FFCA89C83BD574FB1CDE704657AD1992A45BAAA3264396E297BD8BBF1
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....2..s...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V8YuZ...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Sep 24 10:19:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.985443200707457
              Encrypted:false
              SSDEEP:48:8Qd5ThRVHYUidAKZdA1dehBiZUk1W1qehPy+C:8+riv9vy
              MD5:36EA64F7F7BA050F32A9A3299B0BCD36
              SHA1:6453F64CCCB1229E93B8505E4965308906961513
              SHA-256:4642C7750910F7E1155ADB1D6924B6990A900FB8A834DAFB921566612F3903A1
              SHA-512:FBC1E0CE827801D1420ABF7611296BAD68126BF54301BB1B16CFC9B25E79FC3C379A383B279DD635E386291ADB45D8A4E3E5B368379249086F36AE75116E2B8F
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....O..s...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V8YuZ...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Sep 24 10:19:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2679
              Entropy (8bit):3.995261642194944
              Encrypted:false
              SSDEEP:48:8wd5ThRVHYUidAKZdA1duTeehOuTbbiZUk5OjqehOuTbdy+yT+:8eriTTfTbxWOvTbdy7T
              MD5:17FA582570D957F1C4AE6E9B313E93CA
              SHA1:5D6B34C065C32F7734CD29B3D5351E254EB0F4C2
              SHA-256:B3EC95ADF0141CAA2DB61BE3676DF95E846DF335A9FD9877473FBE4B1EE45D93
              SHA-512:D198F1FFB087D82F8229007D1C595549DE89B26ACCA23ECE3C5139142D796FCE6A46E0C85C7514C4FB9CF22B9C78DFE42800D05ECAC539707EAACAB07B8AC3FF
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....(..s...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I8YjZ....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V8YsZ....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V8YsZ....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V8YsZ..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V8YuZ...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............-.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:SVG Scalable Vector Graphics image
              Category:dropped
              Size (bytes):10635
              Entropy (8bit):3.7708640282312342
              Encrypted:false
              SSDEEP:192:lwsp3KmiWvmeX8ogtlAt0ZpbQryQN4P49kPidCgRvFxInbHP:asJrvvXFht0Zpj040k6VRvFxE
              MD5:91BE8BB57512787AEA2A3765FD9850A5
              SHA1:422D9E3C077D09B9D8CEC7C2F4273506203EC696
              SHA-256:51CF6CE31001DD4D93E4C6B873F734F64522948A804F75D03104C1DD8A95D616
              SHA-512:342C7FECA0B37FC53F7422ED6C1A8463061DF9C7EBA4FEAB17F8CA0B115594B75C808422F43AACD284C08D42CB7834DFA7C4DBDE627EAD1845C592951C3CB27B
              Malicious:false
              Reputation:low
              Preview:<svg viewBox="0 0 500 500" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M246.62 107.482c-30.685-9.455-69.799-4.018-95.508 16.935-22.036 17.997-34.61 47.497-36.367 75.517-4.526 72.018 43.802 144.627 121.053 151.276 24.437 2.115 46.96 8.138 60.783 29.607 2.721 4.188 4.968 10.863 9.187 14.06 6.36 4.877 15.857 5.41 21.97 11.203 12.224 11.618 9.776 25.107 30.177 26.624 21.748 1.608 25.849-19.57 14.508-34.589-6.907-9.157-18.217-13.172-25.828-21.586-6.289-6.979-10.136-16.147-13.997-24.559-7.722-16.859-5.665-46.91-21.084-58.356-6.297-4.679-24.416-6.911-21.953-19.381 1.159-5.892 18.548-17.896 23.59-22.042 25.511-20.924 46.388-56.647 25.323-88.757-13.125-20.043-44.597-22.384-63.582-34.88-10.633-6.893-13.093-16.397-28.272-21.072z" fill="#E39D77"/><path d="M298.683 273.654c.402 5.763.939 11.325 1.174 16.853.302 6.299.201 12.598.537 18.864.503 9.012 1.208 18.025 1.879 27.004.302 3.987.805 7.975 1.006 11.995.168 3.083-.167 3.384-2.885 4.49-.503.201-1.007.435-1.543.536-4.932.938-9.864 1.84
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
              Category:dropped
              Size (bytes):4286
              Entropy (8bit):3.6767668884768048
              Encrypted:false
              SSDEEP:48:wFFFFFFFFFFFFFFFFtJdFdFSFfyFbK9MFDFCFbXFbFexKFdFcFQrDFaFNGCF7sF9:nudyjwG+jeWqQmGDB5
              MD5:F25511F4158C2DFAB6AA11A07D026E4A
              SHA1:99F63CF1694FA5E52F43EB967462EA0D9EEF7513
              SHA-256:C0906D540D89DBE1F09B24F17B7F35B81350E8D381C1558B075C28EA913C450D
              SHA-512:0BFB19AEC453A1C4D4B8F39602BF8BBF0A98182A98E29E1E1708EABFD99E3168855994A56061ED462C29B099137C226E25DDD274B46ED2F443C2C515A530B731
              Malicious:false
              Reputation:low
              Preview:...... .... .........(... ...@..... .........%...%............a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...Q...R...`...b...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...b...]...P....C...=..T...\...b...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a..._...T...a...................a...T..._...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...a...b...[
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):1457
              Entropy (8bit):4.776404629803053
              Encrypted:false
              SSDEEP:24:hYjkspFAuaDg5+DCpdgcxtYKvjHpe02Xl2Xhs2XOj2X+3f2XJeA2Xp:4pl5lxNle0UwszfvmM
              MD5:52CFBC1B4884C4516016E2C8A7515B9F
              SHA1:E129A780A626E1869EEE0852DE0462970A0D5501
              SHA-256:C8C3BCDB856B9ACFFA853124ED13A0CC96641691233004CBE9BF8E018EDB8F1B
              SHA-512:CE1DD89707D51148A5336C91FE37C800BB82BD78E25451ED13793F4D7EA9373DF33AA9945C60BB1EB47615C98F4DABA3E5C9B136F270D4CB865B7A4185E6251B
              Malicious:false
              Reputation:low
              URL:https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0
              Preview:<!DOCTYPE html>.<html>.<head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">.<meta name="viewport" content="width=device-width, initial-scale=1" />.<title>Dropbox - 404</title>.<link href="https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css" rel="stylesheet" type="text/css"/>.<link rel="shortcut icon" href="https://cfl.dropboxstatic.com/static/images/favicon.ico"/>.</head>.<body>.<div class="figure">.<img src="https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg" alt="Error: 404"/>.</div>.<div id="errorbox">.<div class="not-found">. <h1>Error (404)</h1>. We can't find the page you're looking for.. <div class="not-found--links">. Here are a few links that may be helpful:. <ul>. <li><a href="https://www.dropbox.com/home?_tk=fof">Home</a></li>. <li><a href="https://www.dropbox.com/help?_tk=fof">Help center</a></li>.
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 152
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Sep 24, 2024 13:19:38.056181908 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:38.359877110 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:38.964879990 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:39.481264114 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.481312990 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:39.481390953 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.481663942 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.481725931 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:39.481801987 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.481919050 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.481936932 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:39.482124090 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:39.482156992 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.128479004 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.128849983 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.128889084 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.130564928 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.130682945 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.130722046 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.130784988 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.131896973 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.132013083 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.132179022 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.132205963 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.139797926 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.140083075 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.140100956 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.141563892 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.141642094 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.141650915 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.141691923 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.142000914 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.142080069 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.169038057 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:40.184889078 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.184910059 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.184935093 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.231884956 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.616290092 CEST4968980192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:40.915612936 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.915667057 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.915739059 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.915822029 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.915859938 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.915921926 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.922068119 CEST49707443192.168.2.16162.125.66.15
              Sep 24, 2024 13:19:40.922110081 CEST44349707162.125.66.15192.168.2.16
              Sep 24, 2024 13:19:40.960659027 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:40.960717916 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:40.960776091 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:40.961133957 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:40.961154938 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.605134964 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.605456114 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.605519056 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.607119083 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.607192039 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.608259916 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.608355999 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.609071016 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.609081030 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.654880047 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.871779919 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890178919 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890191078 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890233994 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890256882 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890338898 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.890363932 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.890363932 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.890400887 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.890563011 CEST49711443192.168.2.1652.222.236.19
              Sep 24, 2024 13:19:41.890582085 CEST4434971152.222.236.19192.168.2.16
              Sep 24, 2024 13:19:41.915169954 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:41.915247917 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:41.915345907 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:41.915535927 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:41.915565968 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.552917004 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.553196907 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.553258896 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.556911945 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.556993008 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.557370901 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.557524920 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.557543993 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.577897072 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:42.608886957 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.608923912 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.656897068 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.827996969 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828100920 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828120947 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828155994 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828176022 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828177929 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.828234911 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828264952 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.828264952 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.828367949 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:42.828430891 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.828795910 CEST49715443192.168.2.1652.222.236.51
              Sep 24, 2024 13:19:42.828828096 CEST4434971552.222.236.51192.168.2.16
              Sep 24, 2024 13:19:43.416356087 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:43.416470051 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:43.416541100 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:43.416754961 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:43.416790009 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.064943075 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.065216064 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:44.065295935 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.066946030 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.067065001 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:44.067959070 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:44.068053961 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.108897924 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:44.108923912 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:44.156941891 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:44.348830938 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:44.348927021 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:44.349029064 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:44.351476908 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:44.351509094 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.008717060 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.008850098 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.011970043 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.011997938 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.012413979 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.061280012 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.107407093 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.278094053 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.278248072 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.278367043 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.278477907 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.278506041 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.278522968 CEST49723443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.278531075 CEST44349723184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.400876999 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.400926113 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:45.401026964 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.403043985 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:45.403067112 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.046335936 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.046427011 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.047595024 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.047612906 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.048511028 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.049887896 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.091418028 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.224216938 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:46.319633007 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.319715977 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.319823980 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.320794106 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.320816994 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.320835114 CEST49724443192.168.2.16184.28.90.27
              Sep 24, 2024 13:19:46.320841074 CEST44349724184.28.90.27192.168.2.16
              Sep 24, 2024 13:19:46.525911093 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:47.127954006 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:47.287097931 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:47.287216902 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:47.287350893 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:47.288527966 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:47.288564920 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:47.382906914 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:19:47.906322002 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:47.906395912 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:47.917766094 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:47.917785883 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:47.918051004 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:47.968920946 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.011328936 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.055411100 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206841946 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206878901 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206886053 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206895113 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206937075 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.206968069 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.206993103 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.207031012 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.207093954 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.207483053 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.207541943 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.207547903 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.207602978 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.207653046 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.225008011 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.225034952 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.225054026 CEST49725443192.168.2.1620.12.23.50
              Sep 24, 2024 13:19:48.225060940 CEST4434972520.12.23.50192.168.2.16
              Sep 24, 2024 13:19:48.336934090 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:50.687231064 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:50.750905991 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:50.990907907 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:51.595977068 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:52.807991028 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:53.987898111 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:53.988065958 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:53.988169909 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:54.913480043 CEST49721443192.168.2.16142.250.186.100
              Sep 24, 2024 13:19:54.913547039 CEST44349721142.250.186.100192.168.2.16
              Sep 24, 2024 13:19:55.215991020 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:19:55.565967083 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:19:56.988943100 CEST49673443192.168.2.16204.79.197.203
              Sep 24, 2024 13:20:00.025044918 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:20:05.174062014 CEST49678443192.168.2.1620.189.173.10
              Sep 24, 2024 13:20:09.625988960 CEST4968080192.168.2.16192.229.211.108
              Sep 24, 2024 13:20:24.766876936 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:24.766918898 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:24.767041922 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:24.767483950 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:24.767498970 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:24.993300915 CEST4969780192.168.2.16199.232.210.172
              Sep 24, 2024 13:20:24.993300915 CEST4969880192.168.2.16199.232.210.172
              Sep 24, 2024 13:20:24.998398066 CEST8049697199.232.210.172192.168.2.16
              Sep 24, 2024 13:20:24.998491049 CEST4969780192.168.2.16199.232.210.172
              Sep 24, 2024 13:20:24.998878002 CEST8049698199.232.210.172192.168.2.16
              Sep 24, 2024 13:20:24.998976946 CEST4969880192.168.2.16199.232.210.172
              Sep 24, 2024 13:20:25.185008049 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:20:25.185025930 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:20:25.372284889 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.372385979 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.374063969 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.374073029 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.374465942 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.375873089 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.423405886 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.576122999 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.576178074 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.576220989 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.576261044 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.576273918 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.576303959 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.576319933 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.577545881 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.577589989 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.577613115 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.577617884 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.577641964 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.577785015 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.577838898 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.579319000 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.579330921 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:25.579351902 CEST49726443192.168.2.1620.12.23.50
              Sep 24, 2024 13:20:25.579356909 CEST4434972620.12.23.50192.168.2.16
              Sep 24, 2024 13:20:40.903563023 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:20:40.903798103 CEST44349706162.125.66.15192.168.2.16
              Sep 24, 2024 13:20:40.903892994 CEST49706443192.168.2.16162.125.66.15
              Sep 24, 2024 13:20:43.461293936 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:43.461333036 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:43.461451054 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:43.461683035 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:43.461698055 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:44.102813959 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:44.103157997 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:44.103174925 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:44.103888988 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:44.104214907 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:44.104305983 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:44.147273064 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:54.013293982 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:54.013448954 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:20:54.013641119 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:54.914921999 CEST49728443192.168.2.16142.250.186.100
              Sep 24, 2024 13:20:54.914937019 CEST44349728142.250.186.100192.168.2.16
              Sep 24, 2024 13:21:16.090451002 CEST4970080192.168.2.16192.229.221.95
              Sep 24, 2024 13:21:16.095776081 CEST8049700192.229.221.95192.168.2.16
              Sep 24, 2024 13:21:16.095865965 CEST4970080192.168.2.16192.229.221.95
              Sep 24, 2024 13:21:43.526621103 CEST49730443192.168.2.16216.58.206.36
              Sep 24, 2024 13:21:43.526715040 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:43.526828051 CEST49730443192.168.2.16216.58.206.36
              Sep 24, 2024 13:21:43.527091980 CEST49730443192.168.2.16216.58.206.36
              Sep 24, 2024 13:21:43.527113914 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:44.171946049 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:44.172329903 CEST49730443192.168.2.16216.58.206.36
              Sep 24, 2024 13:21:44.172363997 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:44.173877001 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:44.174462080 CEST49730443192.168.2.16216.58.206.36
              Sep 24, 2024 13:21:44.174900055 CEST44349730216.58.206.36192.168.2.16
              Sep 24, 2024 13:21:44.228231907 CEST49730443192.168.2.16216.58.206.36
              TimestampSource PortDest PortSource IPDest IP
              Sep 24, 2024 13:19:38.641017914 CEST53540631.1.1.1192.168.2.16
              Sep 24, 2024 13:19:38.653647900 CEST53531411.1.1.1192.168.2.16
              Sep 24, 2024 13:19:39.460300922 CEST5037853192.168.2.161.1.1.1
              Sep 24, 2024 13:19:39.460513115 CEST6189153192.168.2.161.1.1.1
              Sep 24, 2024 13:19:39.468828917 CEST53503781.1.1.1192.168.2.16
              Sep 24, 2024 13:19:39.480635881 CEST53618911.1.1.1192.168.2.16
              Sep 24, 2024 13:19:39.705233097 CEST53509761.1.1.1192.168.2.16
              Sep 24, 2024 13:19:40.938575029 CEST5273853192.168.2.161.1.1.1
              Sep 24, 2024 13:19:40.939407110 CEST6491453192.168.2.161.1.1.1
              Sep 24, 2024 13:19:40.940828085 CEST5403453192.168.2.161.1.1.1
              Sep 24, 2024 13:19:40.941229105 CEST6517053192.168.2.161.1.1.1
              Sep 24, 2024 13:19:40.950196028 CEST53651701.1.1.1192.168.2.16
              Sep 24, 2024 13:19:40.960220098 CEST53540341.1.1.1192.168.2.16
              Sep 24, 2024 13:19:41.895853996 CEST4920453192.168.2.161.1.1.1
              Sep 24, 2024 13:19:41.896009922 CEST5346453192.168.2.161.1.1.1
              Sep 24, 2024 13:19:41.903052092 CEST53534641.1.1.1192.168.2.16
              Sep 24, 2024 13:19:41.914664984 CEST53492041.1.1.1192.168.2.16
              Sep 24, 2024 13:19:43.333067894 CEST6014053192.168.2.161.1.1.1
              Sep 24, 2024 13:19:43.333209991 CEST5972453192.168.2.161.1.1.1
              Sep 24, 2024 13:19:43.406640053 CEST6444053192.168.2.161.1.1.1
              Sep 24, 2024 13:19:43.406769037 CEST5767653192.168.2.161.1.1.1
              Sep 24, 2024 13:19:43.413736105 CEST53644401.1.1.1192.168.2.16
              Sep 24, 2024 13:19:43.415729046 CEST53576761.1.1.1192.168.2.16
              Sep 24, 2024 13:19:56.788877010 CEST53544391.1.1.1192.168.2.16
              Sep 24, 2024 13:20:15.802886009 CEST53649491.1.1.1192.168.2.16
              Sep 24, 2024 13:20:38.568806887 CEST53591381.1.1.1192.168.2.16
              Sep 24, 2024 13:20:38.804150105 CEST53552741.1.1.1192.168.2.16
              Sep 24, 2024 13:20:42.383850098 CEST138138192.168.2.16192.168.2.255
              Sep 24, 2024 13:21:07.403579950 CEST53624751.1.1.1192.168.2.16
              Sep 24, 2024 13:21:43.516273975 CEST6184953192.168.2.161.1.1.1
              Sep 24, 2024 13:21:43.516479969 CEST5726353192.168.2.161.1.1.1
              Sep 24, 2024 13:21:43.525033951 CEST53618491.1.1.1192.168.2.16
              Sep 24, 2024 13:21:43.525738955 CEST53572631.1.1.1192.168.2.16
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 24, 2024 13:19:39.460300922 CEST192.168.2.161.1.1.10xd973Standard query (0)dl.dropboxusercontent.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:39.460513115 CEST192.168.2.161.1.1.10x93acStandard query (0)dl.dropboxusercontent.com65IN (0x0001)false
              Sep 24, 2024 13:19:40.938575029 CEST192.168.2.161.1.1.10xec31Standard query (0)cfl.dropboxstatic.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:40.939407110 CEST192.168.2.161.1.1.10x661eStandard query (0)cfl.dropboxstatic.com65IN (0x0001)false
              Sep 24, 2024 13:19:40.940828085 CEST192.168.2.161.1.1.10x1d3fStandard query (0)assets.dropbox.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:40.941229105 CEST192.168.2.161.1.1.10x78f0Standard query (0)assets.dropbox.com65IN (0x0001)false
              Sep 24, 2024 13:19:41.895853996 CEST192.168.2.161.1.1.10xbd29Standard query (0)assets.dropbox.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:41.896009922 CEST192.168.2.161.1.1.10x12d3Standard query (0)assets.dropbox.com65IN (0x0001)false
              Sep 24, 2024 13:19:43.333067894 CEST192.168.2.161.1.1.10x9ce8Standard query (0)cfl.dropboxstatic.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:43.333209991 CEST192.168.2.161.1.1.10x1812Standard query (0)cfl.dropboxstatic.com65IN (0x0001)false
              Sep 24, 2024 13:19:43.406640053 CEST192.168.2.161.1.1.10x6f8Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:43.406769037 CEST192.168.2.161.1.1.10x35e7Standard query (0)www.google.com65IN (0x0001)false
              Sep 24, 2024 13:21:43.516273975 CEST192.168.2.161.1.1.10x600aStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 24, 2024 13:21:43.516479969 CEST192.168.2.161.1.1.10x582Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 24, 2024 13:19:39.468828917 CEST1.1.1.1192.168.2.160xd973No error (0)dl.dropboxusercontent.comedge-block-www-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:39.468828917 CEST1.1.1.1192.168.2.160xd973No error (0)edge-block-www-env.dropbox-dns.com162.125.66.15A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:39.480635881 CEST1.1.1.1192.168.2.160x93acNo error (0)dl.dropboxusercontent.comedge-block-www-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:40.948230982 CEST1.1.1.1192.168.2.160x661eNo error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:40.949345112 CEST1.1.1.1192.168.2.160xec31No error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:40.960220098 CEST1.1.1.1192.168.2.160x1d3fNo error (0)assets.dropbox.com52.222.236.19A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:40.960220098 CEST1.1.1.1192.168.2.160x1d3fNo error (0)assets.dropbox.com52.222.236.51A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:40.960220098 CEST1.1.1.1192.168.2.160x1d3fNo error (0)assets.dropbox.com52.222.236.37A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:40.960220098 CEST1.1.1.1192.168.2.160x1d3fNo error (0)assets.dropbox.com52.222.236.76A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:41.914664984 CEST1.1.1.1192.168.2.160xbd29No error (0)assets.dropbox.com52.222.236.51A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:41.914664984 CEST1.1.1.1192.168.2.160xbd29No error (0)assets.dropbox.com52.222.236.76A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:41.914664984 CEST1.1.1.1192.168.2.160xbd29No error (0)assets.dropbox.com52.222.236.37A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:41.914664984 CEST1.1.1.1192.168.2.160xbd29No error (0)assets.dropbox.com52.222.236.19A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:43.340756893 CEST1.1.1.1192.168.2.160x1812No error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:43.340975046 CEST1.1.1.1192.168.2.160x9ce8No error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 13:19:43.413736105 CEST1.1.1.1192.168.2.160x6f8No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
              Sep 24, 2024 13:19:43.415729046 CEST1.1.1.1192.168.2.160x35e7No error (0)www.google.com65IN (0x0001)false
              Sep 24, 2024 13:21:43.525033951 CEST1.1.1.1192.168.2.160x600aNo error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
              Sep 24, 2024 13:21:43.525738955 CEST1.1.1.1192.168.2.160x582No error (0)www.google.com65IN (0x0001)false
              • dl.dropboxusercontent.com
              • assets.dropbox.com
              • fs.microsoft.com
              • slscr.update.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.1649707162.125.66.154437032C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:40 UTC785OUTGET /scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0 HTTP/1.1
              Host: dl.dropboxusercontent.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 11:19:40 UTC442INHTTP/1.1 404 Not Found
              Content-Type: text/html
              Content-Security-Policy: sandbox allow-forms allow-scripts
              Date: Tue, 24 Sep 2024 11:19:40 GMT
              Server: envoy
              Content-Length: 1457
              Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
              X-Robots-Tag: noindex, nofollow, noimageindex
              Vary: Accept-Encoding
              X-Dropbox-Response-Origin: far_remote
              X-Dropbox-Request-Id: c70e3475d46b42369b5e10ebff4f5ca6
              Connection: close
              2024-09-24 11:19:40 UTC1457INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 44 72 6f 70 62 6f 78 20 2d 20 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 66 6c 2e 64 72 6f 70 62 6f 78 73 74 61 74 69 63 2e 63 6f 6d 2f 73 74 61 74 69 63 2f 6d 65 74 61 73 65 72 76 65
              Data Ascii: <!DOCTYPE html><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Dropbox - 404</title><link href="https://cfl.dropboxstatic.com/static/metaserve


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.164971152.222.236.194437032C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:41 UTC596OUTGET /www/en-us/illustrations/spot/look-magnifying-glass.svg HTTP/1.1
              Host: assets.dropbox.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: cross-site
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 11:19:41 UTC741INHTTP/1.1 200 OK
              Content-Type: image/svg+xml
              Content-Length: 10635
              Connection: close
              Date: Tue, 24 Sep 2024 11:02:03 GMT
              Server: Apache
              X-Dispatcher: dispatcher2uswest1-28645028
              X-Vhost: dropbox-prod.adobemsbasic.com
              Content-Disposition: attachment; filename="look-magnifying-glass.svg"
              X-Content-Type-Options: nosniff
              Last-Modified: Tue, 08 Jun 2021 16:59:13 GMT
              Accept-Ranges: bytes
              Cache-Control: max-age=86400
              Expires: Wed, 25 Sep 2024 11:02:03 GMT
              X-Frame-Options: SAMEORIGIN
              ETag: "298b"
              Vary: Accept-Encoding
              X-Cache: Hit from cloudfront
              Via: 1.1 d9bcd0a29e17b9290f8c9f1617335954.cloudfront.net (CloudFront)
              X-Amz-Cf-Pop: FRA56-P4
              X-Amz-Cf-Id: UK92mlWmsbZ2SiSvd7QCmSQs-1NSjHB53eCGxQlAu1WomZVQ8KfFoQ==
              Age: 4796
              2024-09-24 11:19:41 UTC9594INData Raw: 3c 73 76 67 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 35 30 30 20 35 30 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 3e 3c 70 61 74 68 20 64 3d 22 4d 32 34 36 2e 36 32 20 31 30 37 2e 34 38 32 63 2d 33 30 2e 36 38 35 2d 39 2e 34 35 35 2d 36 39 2e 37 39 39 2d 34 2e 30 31 38 2d 39 35 2e 35 30 38 20 31 36 2e 39 33 35 2d 32 32 2e 30 33 36 20 31 37 2e 39 39 37 2d 33 34 2e 36 31 20 34 37 2e 34 39 37 2d 33 36 2e 33 36 37 20 37 35 2e 35 31 37 2d 34 2e 35 32 36 20 37 32 2e 30 31 38 20 34 33 2e 38 30 32 20 31 34 34 2e 36 32 37 20 31 32 31 2e 30 35 33 20 31 35 31 2e 32 37 36 20 32 34 2e 34 33 37 20 32 2e 31 31 35 20 34 36 2e 39 36 20 38 2e 31 33 38 20 36 30 2e 37 38
              Data Ascii: <svg viewBox="0 0 500 500" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M246.62 107.482c-30.685-9.455-69.799-4.018-95.508 16.935-22.036 17.997-34.61 47.497-36.367 75.517-4.526 72.018 43.802 144.627 121.053 151.276 24.437 2.115 46.96 8.138 60.78
              2024-09-24 11:19:41 UTC1041INData Raw: 2e 31 33 36 2d 34 2e 31 35 35 20 33 39 2e 33 38 38 2d 31 2e 31 30 36 20 34 2e 39 39 39 20 31 2e 31 33 39 20 39 2e 39 33 31 20 32 2e 34 31 32 20 31 34 2e 34 36 31 20 34 2e 39 32 35 20 32 2e 32 38 31 20 31 2e 32 34 20 34 2e 36 39 37 20 32 2e 32 31 32 20 37 2e 34 38 31 20 33 2e 34 38 35 2d 2e 32 36 38 2d 32 2e 35 38 2d 2e 38 30 35 2d 34 2e 33 35 36 2d 32 2e 39 35 32 2d 35 2e 33 32 38 2d 32 2e 31 34 37 2d 2e 39 37 31 2d 34 2e 33 32 38 2d 31 2e 39 37 36 2d 36 2e 33 37 35 2d 33 2e 31 31 35 2d 37 2e 34 34 38 2d 34 2e 31 38 38 2d 31 35 2e 36 30 31 2d 36 2e 34 36 37 2d 32 33 2e 39 32 31 2d 37 2e 34 37 32 2d 31 33 2e 34 32 2d 31 2e 36 34 32 2d 32 36 2e 34 33 38 2e 33 36 39 2d 33 38 2e 34 31 35 20 37 2e 30 33 36 2d 32 2e 32 38 32 20 31 2e 32 37 33 2d 34 2e 32 39 35
              Data Ascii: .136-4.155 39.388-1.106 4.999 1.139 9.931 2.412 14.461 4.925 2.281 1.24 4.697 2.212 7.481 3.485-.268-2.58-.805-4.356-2.952-5.328-2.147-.971-4.328-1.976-6.375-3.115-7.448-4.188-15.601-6.467-23.921-7.472-13.42-1.642-26.438.369-38.415 7.036-2.282 1.273-4.295


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.164971552.222.236.514437032C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:42 UTC396OUTGET /www/en-us/illustrations/spot/look-magnifying-glass.svg HTTP/1.1
              Host: assets.dropbox.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 11:19:42 UTC741INHTTP/1.1 200 OK
              Content-Type: image/svg+xml
              Content-Length: 10635
              Connection: close
              Date: Tue, 24 Sep 2024 11:02:03 GMT
              Server: Apache
              X-Dispatcher: dispatcher2uswest1-28645028
              X-Vhost: dropbox-prod.adobemsbasic.com
              Content-Disposition: attachment; filename="look-magnifying-glass.svg"
              X-Content-Type-Options: nosniff
              Last-Modified: Tue, 08 Jun 2021 16:59:13 GMT
              Accept-Ranges: bytes
              Cache-Control: max-age=86400
              Expires: Wed, 25 Sep 2024 11:02:03 GMT
              X-Frame-Options: SAMEORIGIN
              ETag: "298b"
              Vary: Accept-Encoding
              X-Cache: Hit from cloudfront
              Via: 1.1 bb3ac1595bb014e3b09608a0358d33da.cloudfront.net (CloudFront)
              X-Amz-Cf-Pop: FRA56-P4
              X-Amz-Cf-Id: Zu6MfyWd9ca46lZQivIf1PG4BL8QDlNHl6DS5WC5MQNYxBEinhxlcg==
              Age: 4797
              2024-09-24 11:19:42 UTC10635INData Raw: 3c 73 76 67 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 35 30 30 20 35 30 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 3e 3c 70 61 74 68 20 64 3d 22 4d 32 34 36 2e 36 32 20 31 30 37 2e 34 38 32 63 2d 33 30 2e 36 38 35 2d 39 2e 34 35 35 2d 36 39 2e 37 39 39 2d 34 2e 30 31 38 2d 39 35 2e 35 30 38 20 31 36 2e 39 33 35 2d 32 32 2e 30 33 36 20 31 37 2e 39 39 37 2d 33 34 2e 36 31 20 34 37 2e 34 39 37 2d 33 36 2e 33 36 37 20 37 35 2e 35 31 37 2d 34 2e 35 32 36 20 37 32 2e 30 31 38 20 34 33 2e 38 30 32 20 31 34 34 2e 36 32 37 20 31 32 31 2e 30 35 33 20 31 35 31 2e 32 37 36 20 32 34 2e 34 33 37 20 32 2e 31 31 35 20 34 36 2e 39 36 20 38 2e 31 33 38 20 36 30 2e 37 38
              Data Ascii: <svg viewBox="0 0 500 500" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M246.62 107.482c-30.685-9.455-69.799-4.018-95.508 16.935-22.036 17.997-34.61 47.497-36.367 75.517-4.526 72.018 43.802 144.627 121.053 151.276 24.437 2.115 46.96 8.138 60.78


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.1649723184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:45 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-24 11:19:45 UTC466INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF67)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=19576
              Date: Tue, 24 Sep 2024 11:19:45 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.1649724184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:46 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-24 11:19:46 UTC514INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=25933
              Date: Tue, 24 Sep 2024 11:19:46 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-24 11:19:46 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.164972520.12.23.50443
              TimestampBytes transferredDirectionData
              2024-09-24 11:19:48 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lc+v+fM+Ueyt4eP&MD=2+d5wtC3 HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
              Host: slscr.update.microsoft.com
              2024-09-24 11:19:48 UTC560INHTTP/1.1 200 OK
              Cache-Control: no-cache
              Pragma: no-cache
              Content-Type: application/octet-stream
              Expires: -1
              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
              ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
              MS-CorrelationId: 0d160c06-b256-4bfb-a193-71f9d69816ba
              MS-RequestId: f7dc43d4-4ba2-4c03-8e78-ae2c8837ae08
              MS-CV: waRhg1fZY0GLct40.0
              X-Microsoft-SLSClientCache: 2880
              Content-Disposition: attachment; filename=environment.cab
              X-Content-Type-Options: nosniff
              Date: Tue, 24 Sep 2024 11:19:47 GMT
              Connection: close
              Content-Length: 24490
              2024-09-24 11:19:48 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
              Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
              2024-09-24 11:19:48 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
              Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.164972620.12.23.50443
              TimestampBytes transferredDirectionData
              2024-09-24 11:20:25 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lc+v+fM+Ueyt4eP&MD=2+d5wtC3 HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
              Host: slscr.update.microsoft.com
              2024-09-24 11:20:25 UTC560INHTTP/1.1 200 OK
              Cache-Control: no-cache
              Pragma: no-cache
              Content-Type: application/octet-stream
              Expires: -1
              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
              ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
              MS-CorrelationId: 791b187a-a127-4acd-ad45-4bdd0911f8b0
              MS-RequestId: ec41034d-b009-43f1-956c-b17832c5cba5
              MS-CV: QbF6jRJyTUqIDgrg.0
              X-Microsoft-SLSClientCache: 1440
              Content-Disposition: attachment; filename=environment.cab
              X-Content-Type-Options: nosniff
              Date: Tue, 24 Sep 2024 11:20:24 GMT
              Connection: close
              Content-Length: 30005
              2024-09-24 11:20:25 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
              Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
              2024-09-24 11:20:25 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
              Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


              050100s020406080100

              Click to jump to process

              050100s0.0050100MB

              Click to jump to process

              Target ID:0
              Start time:07:19:37
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff7f9810000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:1
              Start time:07:19:37
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1872,i,6622761000618728035,9722359374662057473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff7f9810000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:07:19:38
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0"
              Imagebase:0x7ff7f9810000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly