Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
1El22bCuSq.html

Overview

General Information

Sample name:1El22bCuSq.html
renamed because original name is a hash value
Original sample name:7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318.html
Analysis ID:1542810
MD5:d208d81ab739dc43291c2076a8c01e62
SHA1:36074c3c2f409c773e42f962e7ce446783a29d5f
SHA256:7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318
Tags:blogview-shophtmluser-JAMESWT_MHT
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 7004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\1El22bCuSq.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2088 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1872,i,8697468142556874598,11642264719129557555,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 1El22bCuSq.htmlReversingLabs: Detection: 13%
Source: 1El22bCuSq.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/1El22bCuSq.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.8:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.8:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.8:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.8:49726 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.226
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.226
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.226
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wZMFbbHUo+x8dtS&MD=YEGWvUo5 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wZMFbbHUo+x8dtS&MD=YEGWvUo5 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: 1El22bCuSq.htmlString found in binary or memory: https://blogview.shop/api/values/id
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.8:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.8:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.8:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.8:49726 version: TLS 1.2
Source: classification engineClassification label: mal48.winHTML@22/6@2/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: 1El22bCuSq.htmlReversingLabs: Detection: 13%
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\1El22bCuSq.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1872,i,8697468142556874598,11642264719129557555,262144 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1872,i,8697468142556874598,11642264719129557555,262144 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
1El22bCuSq.html13%ReversingLabsScript-WScript.Trojan.Asthma
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.164
truefalse
    unknown
    NameMaliciousAntivirus DetectionReputation
    file:///C:/Users/user/Desktop/1El22bCuSq.htmltrue
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      https://blogview.shop/api/values/id1El22bCuSq.htmlfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.186.164
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.8
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1542810
        Start date and time:2024-10-26 13:49:37 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 5m 17s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:defaultwindowshtmlcookbook.jbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:9
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Sample name:1El22bCuSq.html
        renamed because original name is a hash value
        Original Sample Name:7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318.html
        Detection:MAL
        Classification:mal48.winHTML@22/6@2/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • Found application associated with file extension: .html
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.78, 108.177.15.84, 142.250.181.227, 34.104.35.123, 199.232.214.172, 172.217.16.138, 142.250.185.74, 142.250.186.42, 142.250.185.106, 142.250.181.234, 142.250.185.202, 142.250.184.202, 142.250.186.74, 142.250.185.234, 142.250.185.138, 216.58.206.42, 172.217.18.10, 142.250.185.170, 142.250.186.106, 142.250.186.138, 216.58.212.138, 192.229.221.95, 142.250.186.131, 93.184.221.240, 172.217.23.110
        • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, optimizationguide-pa.googleapis.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: 1El22bCuSq.html
        No simulations
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        239.255.255.250ZtefPP1HI7.cmdGet hashmaliciousUnknownBrowse
          J1IrCccVO6.batGet hashmaliciousUnknownBrowse
            IDfVY125HU.htmlGet hashmaliciousWinSearchAbuseBrowse
              https://www.google.co.uk/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/taxigiarebienhoa.vn/nini/ybmex/captcha/Z3VsYW1yYXN1bC5jaGVwdXdhbGFAY2V2YWxvZ2lzdGljcy5jb20Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                8m9f0jVE2G.exeGet hashmaliciousUnknownBrowse
                  gI1wz7QtZV.lnkGet hashmaliciousLonePageBrowse
                    846754Ea6k.lnkGet hashmaliciousLonePageBrowse
                      35ZnVKToSL.lnkGet hashmaliciousLonePageBrowse
                        8m9f0jVE2G.exeGet hashmaliciousUnknownBrowse
                          T52Z708x2p.exeGet hashmaliciousPhorpiex, XmrigBrowse
                            No context
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            28a2c9bd18a11de089ef85a160da29e4ZtefPP1HI7.cmdGet hashmaliciousUnknownBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            J1IrCccVO6.batGet hashmaliciousUnknownBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            IDfVY125HU.htmlGet hashmaliciousWinSearchAbuseBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            https://www.google.co.uk/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/taxigiarebienhoa.vn/nini/ybmex/captcha/Z3VsYW1yYXN1bC5jaGVwdXdhbGFAY2V2YWxvZ2lzdGljcy5jb20Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            8m9f0jVE2G.exeGet hashmaliciousUnknownBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            gI1wz7QtZV.lnkGet hashmaliciousLonePageBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            846754Ea6k.lnkGet hashmaliciousLonePageBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            35ZnVKToSL.lnkGet hashmaliciousLonePageBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            8m9f0jVE2G.exeGet hashmaliciousUnknownBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            http://fleurifleuri.com/Get hashmaliciousUnknownBrowse
                            • 20.109.210.53
                            • 184.28.90.27
                            No context
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Oct 26 10:50:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2677
                            Entropy (8bit):3.981444858911369
                            Encrypted:false
                            SSDEEP:48:8e0daTmqzHLidAKZdA1oehwiZUklqeh6y+3:8epXA5y
                            MD5:10BED557B37A243C923FB416887E6C4A
                            SHA1:D6CC09B00DC93074777CFAA6CDE52C0AE2D0613E
                            SHA-256:60A33CCF152C50345037BB6F2CF9DFE4FC440B163FF6275ADE21D60008263D7D
                            SHA-512:90543F19C1EA533BDD4E8A2676FC497EA62CFC54FFB3D7C358513108606FA0FC7E290E2DE31FA84B09D767B1DB051BC24CAA555F00365BDC94FD176FC2D69B7A
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,......H.'..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VZYU^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Oct 26 10:50:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2679
                            Entropy (8bit):3.995758167987962
                            Encrypted:false
                            SSDEEP:48:8Z0daTmqzHLidAKZdA1leh/iZUkAQkqehpy+2:8ZpX69Q8y
                            MD5:2ADC7534F55BC20A70CD78193BA296F8
                            SHA1:E48ABC2660AABDFD0C9543DCAEA9F01B74B8BC44
                            SHA-256:06221C2C850B94E382FE9386446DFB6BB941EBD179975FEABF342AF3950A7BE3
                            SHA-512:00E9E810D6246E8C633E06AF7AECFB860CCA8A1DEDD52A263F4B29324A7933CBE6ADBEBA22DB35C3FAABC16901256C21C071D05C9EA1DA0687E4C7FCD4510625
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,.....\.H.'..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VZYU^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2693
                            Entropy (8bit):4.006938521370165
                            Encrypted:false
                            SSDEEP:48:8P0daTmqbHLidAKZdA14t5eh7sFiZUkmgqeh7sTy+BX:8PpXqnFy
                            MD5:43B239A14CBD2B3E6798530604861D03
                            SHA1:5CAA94DB84FD838FEE7F0FB1E5035EA15BB42637
                            SHA-256:9B7E4A4398BA433CBDAB673C60DBCA5791918C31C16646191138E8F2A2851FCD
                            SHA-512:3230E8D06CA85478059CDEC18CED96C00A16F5FD8889149C956D66E5A7561E8B1A5C561FB5E7FD32298F0982A0A84C2C131831C8AE2BA4B2FFF8CCE22453362A
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,.....C..b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEW.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Oct 26 10:50:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2681
                            Entropy (8bit):3.9935064596147725
                            Encrypted:false
                            SSDEEP:48:8a0daTmqzHLidAKZdA16ehDiZUkwqeh9y+R:8apXxry
                            MD5:FDE20BF73E5AE34FEBDDC42523F7393D
                            SHA1:33CE853227FCC210A609D89B2728EBEA10E1D2EB
                            SHA-256:91A1FA2896BED617F7B999A174333046ED55999964A41ED4BDE1D6940405557D
                            SHA-512:3BE82F5C3F002338ABCE980E8BE8454570F35E1920F47305BCA151B6663CC7FC5DE6FA58FD86DE3749AD8E2EF529F7465AEDEEF6C88904BCF686042C39725A9E
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,.......H.'..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VZYU^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Oct 26 10:50:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2681
                            Entropy (8bit):3.983547418123504
                            Encrypted:false
                            SSDEEP:48:8A0daTmqzHLidAKZdA1UehBiZUk1W1qeh/y+C:8ApXx9fy
                            MD5:C0D3B0F86B808D2AF8BBDF021E8267F1
                            SHA1:3173EF7CB3942DEA1130120E9A7D1D87F596895E
                            SHA-256:81EE1F14D45E0752770A11B28AD736F2A9A0822D82B6B6CF423612B827CA0806
                            SHA-512:CB987DE2FD4BE51FD389B9095BD895CD4A7BF99F3E4296FE20C7FA1CE5CCB914EF3B982A7D456ADE5122AA004996BA9674D6A6A6CDF46C6C526CDE80BB14461F
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,....2!.H.'..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VZYU^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Oct 26 10:50:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                            Category:dropped
                            Size (bytes):2683
                            Entropy (8bit):3.9945064162904806
                            Encrypted:false
                            SSDEEP:48:8Z0daTmqzHLidAKZdA1duTrehOuTbbiZUk5OjqehOuTbFy+yT+:8ZpXOTYTbxWOvTbFy7T
                            MD5:1607B855DDE5EBF898E56EAB7069408F
                            SHA1:6358CC821DA77E6979627553061D0D2634B50DB5
                            SHA-256:D7DC4903950ABA85A7E7E9F27ECAECE36B7B559DECB65A3D300CF32F60C121A9
                            SHA-512:D478F97F671F399BB69E808AB6035ABEAF1770B2A0A5EDBB85C5DFA9E9947B4CB8C18BCFB48C26F5300C62EAE629C2652ED4319DFA69A5BF776A0B2FCBE01EAD
                            Malicious:false
                            Reputation:low
                            Preview:L..................F.@.. ...$+.,....q..H.'..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....EW)C..PROGRA~1..t......O.IZYT^....B...............J.....V...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VZYT^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VZYT^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VZYT^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VZYU^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@.h.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                            File type:HTML document, Unicode text, UTF-8 text, with very long lines (1264)
                            Entropy (8bit):5.786919620216169
                            TrID:
                            • HyperText Markup Language (15015/1) 37.99%
                            • HyperText Markup Language with DOCTYPE (12503/2) 31.64%
                            • HyperText Markup Language (12001/1) 30.37%
                            File name:1El22bCuSq.html
                            File size:10'557 bytes
                            MD5:d208d81ab739dc43291c2076a8c01e62
                            SHA1:36074c3c2f409c773e42f962e7ce446783a29d5f
                            SHA256:7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318
                            SHA512:c7f9fed27c6b9d5de8d64d67fca440f5210ab76a27784987a3283e73d2a515b383cad68dad2656334d7539f31ee0d61e50a767f440dd9aab7dccd8ee47edca9e
                            SSDEEP:192:4LgkJjnZJ0hQ1y3XIEgG+w3vl+/o8CMHNaPUpTrmmitxSv/kWm/T:4yQw3D+igD5p2AHkWM
                            TLSH:212242927AAD48DF4005E15BE9147E497EEB40BE7BB7D71232B8387E6ED0420863831C
                            File Content Preview:<!DOCTYPE html>.<html lang="uk" data-bs-theme="light">.<head>.<STYLE TYPE="text/css">.@page SectionA {. margin-left: 20 mm;. margin-right: 10 mm;. margin-top: 10 mm;. margin-bottom: 10 mm;. mso-paper-source: 0;.}.DIV.Section {. page: SectionA;.}.BOD
                            TimestampSource PortDest PortSource IPDest IP
                            Oct 26, 2024 13:50:30.722150087 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.725229979 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.743660927 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.743917942 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.743999004 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.746480942 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.746634960 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.751943111 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.767781973 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.767795086 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.767865896 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.770721912 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.771595955 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.771648884 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.771658897 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.771689892 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.771689892 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.774343014 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.779616117 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.852905989 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.855895996 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.874119043 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.874133110 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.874202967 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.874497890 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.874563932 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.874633074 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.877185106 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.877252102 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.882638931 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.898163080 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.900790930 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.901408911 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.901482105 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.903964996 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:30.909343958 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.983833075 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:30.987425089 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.004889965 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.004925966 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.004990101 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.008166075 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.008289099 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.014341116 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.028064013 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.031186104 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.031264067 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.114942074 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.138147116 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.138171911 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:50:31.138221979 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.188837051 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:50:31.438860893 CEST49671443192.168.2.8204.79.197.203
                            Oct 26, 2024 13:50:31.798403978 CEST4967780192.168.2.8192.229.211.108
                            Oct 26, 2024 13:50:32.392106056 CEST49673443192.168.2.823.206.229.226
                            Oct 26, 2024 13:50:32.720177889 CEST49672443192.168.2.823.206.229.226
                            Oct 26, 2024 13:50:39.891985893 CEST49676443192.168.2.852.182.143.211
                            Oct 26, 2024 13:50:41.997997046 CEST49673443192.168.2.823.206.229.226
                            Oct 26, 2024 13:50:42.383348942 CEST49672443192.168.2.823.206.229.226
                            Oct 26, 2024 13:50:42.492722988 CEST4967780192.168.2.8192.229.211.108
                            Oct 26, 2024 13:50:44.088849068 CEST4434970423.206.229.226192.168.2.8
                            Oct 26, 2024 13:50:44.088936090 CEST49704443192.168.2.823.206.229.226
                            Oct 26, 2024 13:50:45.477463007 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:45.477538109 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:45.477646112 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:45.481623888 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:45.481646061 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.167239904 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:46.167362928 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:46.167566061 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:46.168962002 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:46.169015884 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:46.339330912 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.339603901 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:46.339632988 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.340660095 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.340732098 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:46.486088037 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:46.486238003 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.616676092 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:46.616693020 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:46.725759029 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:47.014695883 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.014938116 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.018625021 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.018651962 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.019068956 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.071304083 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.160522938 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.203337908 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.568227053 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.568398952 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.568548918 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.568550110 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.568646908 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.568694115 CEST49714443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.568713903 CEST44349714184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.606678009 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.606765985 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:47.606966972 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.607121944 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:47.607146025 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.460279942 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.460366011 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:48.461904049 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:48.461946964 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.462379932 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.463510036 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:48.507350922 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.709597111 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.709662914 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:48.709723949 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:48.710666895 CEST49715443192.168.2.8184.28.90.27
                            Oct 26, 2024 13:50:48.710680008 CEST44349715184.28.90.27192.168.2.8
                            Oct 26, 2024 13:50:52.629590034 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:52.629683971 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:52.629812002 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:52.631041050 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:52.631076097 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:53.422636032 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:53.422836065 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:53.424932003 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:53.424951077 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:53.425205946 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:53.477813005 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.115187883 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.159337044 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.373883963 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.373912096 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.373919010 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.373964071 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.373976946 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374006987 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374027014 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374062061 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374080896 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374082088 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374082088 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374105930 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374732018 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374805927 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:54.374815941 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374944925 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:54.374993086 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:55.245007992 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:55.245007992 CEST49716443192.168.2.820.109.210.53
                            Oct 26, 2024 13:50:55.245079994 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:55.245112896 CEST4434971620.109.210.53192.168.2.8
                            Oct 26, 2024 13:50:56.338299990 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:56.338458061 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:50:56.338520050 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:56.712229967 CEST49713443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:50:56.712261915 CEST44349713142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:31.738358021 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:31.738471985 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:31.738553047 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:31.738934994 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:31.738969088 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.552207947 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.552298069 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.555851936 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.555875063 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.556201935 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.561455965 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.603332043 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.824877024 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.824954033 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.824999094 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.825032949 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.825093985 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.825130939 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.825155973 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.826332092 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.826384068 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.826404095 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.826421976 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.826450109 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.827025890 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.827086926 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.828186035 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.828229904 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:32.828257084 CEST49726443192.168.2.820.109.210.53
                            Oct 26, 2024 13:51:32.828273058 CEST4434972620.109.210.53192.168.2.8
                            Oct 26, 2024 13:51:45.641901016 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:45.641957998 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:45.642034054 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:45.642261982 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:45.642280102 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:46.728976965 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:46.729378939 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:46.729413986 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:46.729796886 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:46.730144978 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:46.730222940 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:46.774600029 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:56.733558893 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:56.733633995 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:51:56.733926058 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:57.927402973 CEST49728443192.168.2.8142.250.186.164
                            Oct 26, 2024 13:51:57.927460909 CEST44349728142.250.186.164192.168.2.8
                            Oct 26, 2024 13:52:01.134293079 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:52:01.135062933 CEST4434970313.107.246.45192.168.2.8
                            Oct 26, 2024 13:52:01.135118008 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:52:01.135211945 CEST49703443192.168.2.813.107.246.45
                            Oct 26, 2024 13:52:01.140522003 CEST4434970313.107.246.45192.168.2.8
                            TimestampSource PortDest PortSource IPDest IP
                            Oct 26, 2024 13:50:40.887902975 CEST53526541.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:40.888464928 CEST53573071.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:42.350502968 CEST53628241.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:45.458894968 CEST6034453192.168.2.81.1.1.1
                            Oct 26, 2024 13:50:45.459290981 CEST5580753192.168.2.81.1.1.1
                            Oct 26, 2024 13:50:45.466686964 CEST53603441.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:45.466967106 CEST53558071.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:53.487464905 CEST53546851.1.1.1192.168.2.8
                            Oct 26, 2024 13:50:59.428646088 CEST53523621.1.1.1192.168.2.8
                            Oct 26, 2024 13:51:18.132899046 CEST53548621.1.1.1192.168.2.8
                            Oct 26, 2024 13:51:20.606221914 CEST138138192.168.2.8192.168.2.255
                            Oct 26, 2024 13:51:40.738132000 CEST53500761.1.1.1192.168.2.8
                            Oct 26, 2024 13:51:41.033348083 CEST53621911.1.1.1192.168.2.8
                            Oct 26, 2024 13:52:09.902304888 CEST53548021.1.1.1192.168.2.8
                            Oct 26, 2024 13:52:54.310283899 CEST53602751.1.1.1192.168.2.8
                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                            Oct 26, 2024 13:50:45.458894968 CEST192.168.2.81.1.1.10x518eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                            Oct 26, 2024 13:50:45.459290981 CEST192.168.2.81.1.1.10x607Standard query (0)www.google.com65IN (0x0001)false
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Oct 26, 2024 13:50:45.466686964 CEST1.1.1.1192.168.2.80x518eNo error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                            Oct 26, 2024 13:50:45.466967106 CEST1.1.1.1192.168.2.80x607No error (0)www.google.com65IN (0x0001)false
                            • fs.microsoft.com
                            • slscr.update.microsoft.com
                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                            0192.168.2.849714184.28.90.27443
                            TimestampBytes transferredDirectionData
                            2024-10-26 11:50:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                            Connection: Keep-Alive
                            Accept: */*
                            Accept-Encoding: identity
                            User-Agent: Microsoft BITS/7.8
                            Host: fs.microsoft.com
                            2024-10-26 11:50:47 UTC467INHTTP/1.1 200 OK
                            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                            Content-Type: application/octet-stream
                            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                            Server: ECAcc (lpl/EF70)
                            X-CID: 11
                            X-Ms-ApiVersion: Distribute 1.2
                            X-Ms-Region: prod-weu-z1
                            Cache-Control: public, max-age=104055
                            Date: Sat, 26 Oct 2024 11:50:47 GMT
                            Connection: close
                            X-CID: 2


                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                            1192.168.2.849715184.28.90.27443
                            TimestampBytes transferredDirectionData
                            2024-10-26 11:50:48 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                            Connection: Keep-Alive
                            Accept: */*
                            Accept-Encoding: identity
                            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                            Range: bytes=0-2147483646
                            User-Agent: Microsoft BITS/7.8
                            Host: fs.microsoft.com
                            2024-10-26 11:50:48 UTC515INHTTP/1.1 200 OK
                            ApiVersion: Distribute 1.1
                            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                            Content-Type: application/octet-stream
                            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                            Server: ECAcc (lpl/EF06)
                            X-CID: 11
                            X-Ms-ApiVersion: Distribute 1.2
                            X-Ms-Region: prod-weu-z1
                            Cache-Control: public, max-age=104054
                            Date: Sat, 26 Oct 2024 11:50:48 GMT
                            Content-Length: 55
                            Connection: close
                            X-CID: 2
                            2024-10-26 11:50:48 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                            2192.168.2.84971620.109.210.53443
                            TimestampBytes transferredDirectionData
                            2024-10-26 11:50:54 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wZMFbbHUo+x8dtS&MD=YEGWvUo5 HTTP/1.1
                            Connection: Keep-Alive
                            Accept: */*
                            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                            Host: slscr.update.microsoft.com
                            2024-10-26 11:50:54 UTC560INHTTP/1.1 200 OK
                            Cache-Control: no-cache
                            Pragma: no-cache
                            Content-Type: application/octet-stream
                            Expires: -1
                            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                            ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                            MS-CorrelationId: b54f0cf7-de97-420f-b95a-f44b962c9c23
                            MS-RequestId: cf5a4df9-c237-427c-82ae-d898273d562b
                            MS-CV: fRJHkGVcCU+Hf4Ur.0
                            X-Microsoft-SLSClientCache: 2880
                            Content-Disposition: attachment; filename=environment.cab
                            X-Content-Type-Options: nosniff
                            Date: Sat, 26 Oct 2024 11:50:53 GMT
                            Connection: close
                            Content-Length: 24490
                            2024-10-26 11:50:54 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                            Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                            2024-10-26 11:50:54 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                            Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                            3192.168.2.84972620.109.210.53443
                            TimestampBytes transferredDirectionData
                            2024-10-26 11:51:32 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=wZMFbbHUo+x8dtS&MD=YEGWvUo5 HTTP/1.1
                            Connection: Keep-Alive
                            Accept: */*
                            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                            Host: slscr.update.microsoft.com
                            2024-10-26 11:51:32 UTC560INHTTP/1.1 200 OK
                            Cache-Control: no-cache
                            Pragma: no-cache
                            Content-Type: application/octet-stream
                            Expires: -1
                            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                            ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                            MS-CorrelationId: 741c7f33-ee8e-4217-a104-bf2991a6866b
                            MS-RequestId: 3306d6f4-2716-4582-bcf5-1200ae58da2e
                            MS-CV: +vinW4SAqkyuF0Ds.0
                            X-Microsoft-SLSClientCache: 1440
                            Content-Disposition: attachment; filename=environment.cab
                            X-Content-Type-Options: nosniff
                            Date: Sat, 26 Oct 2024 11:51:32 GMT
                            Connection: close
                            Content-Length: 30005
                            2024-10-26 11:51:32 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                            Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                            2024-10-26 11:51:32 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                            Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                            Click to jump to process

                            Click to jump to process

                            Click to jump to process

                            Target ID:0
                            Start time:07:50:36
                            Start date:26/10/2024
                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\1El22bCuSq.html"
                            Imagebase:0x7ff678760000
                            File size:3'242'272 bytes
                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:false

                            Target ID:2
                            Start time:07:50:39
                            Start date:26/10/2024
                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1872,i,8697468142556874598,11642264719129557555,262144 /prefetch:8
                            Imagebase:0x7ff678760000
                            File size:3'242'272 bytes
                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:false

                            No disassembly