Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D

Overview

General Information

Sample URL:https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D
Analysis ID:1566424
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1704 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1980,i,5088498168306710667,14428680290771934357,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6576 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=7yGPpgGB35nzk6T&MD=LCcU9Gg9 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: point-mutuel.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1980,i,5088498168306710667,14428680290771934357,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1980,i,5088498168306710667,14428680290771934357,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.21.36
truefalse
    high
    point-mutuel.com
    94.217.52.151
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      94.217.52.151
      point-mutuel.comGermany
      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
      172.217.21.36
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1566424
      Start date and time:2024-12-02 07:38:51 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 23s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:UNKNOWN
      Classification:unknown0.win@18/0@4/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 216.58.208.227, 64.233.165.84, 172.217.17.46, 34.104.35.123, 199.232.210.172, 192.229.221.95, 172.217.21.35, 142.250.181.99
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Dec 2, 2024 07:39:49.111710072 CET49675443192.168.2.4173.222.162.32
      Dec 2, 2024 07:39:55.297368050 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:55.297429085 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:55.297578096 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:55.297810078 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:55.297827005 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:55.996330976 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:55.996386051 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:55.996462107 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:55.998547077 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:55.998580933 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.087075949 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:57.087354898 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:57.087395906 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:57.088509083 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:57.088579893 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:57.089754105 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:57.089827061 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:57.144197941 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:57.144212961 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:39:57.190745115 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:39:57.425971031 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.426044941 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.430648088 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.430656910 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.430917978 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.469160080 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.511343956 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.535140991 CET49740443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535191059 CET4434974094.217.52.151192.168.2.4
      Dec 2, 2024 07:39:57.535342932 CET49740443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535590887 CET49741443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535626888 CET4434974194.217.52.151192.168.2.4
      Dec 2, 2024 07:39:57.535701990 CET49741443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535778999 CET49740443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535792112 CET4434974094.217.52.151192.168.2.4
      Dec 2, 2024 07:39:57.535964012 CET49741443192.168.2.494.217.52.151
      Dec 2, 2024 07:39:57.535979033 CET4434974194.217.52.151192.168.2.4
      Dec 2, 2024 07:39:57.947580099 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.947657108 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.947771072 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.952150106 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.952187061 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:57.952200890 CET49739443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:57.952207088 CET4434973923.218.208.109192.168.2.4
      Dec 2, 2024 07:39:58.190484047 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:58.190512896 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:39:58.190618992 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:58.191016912 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:58.191030979 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:39:59.694693089 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:39:59.694890022 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:59.696839094 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:59.696854115 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:39:59.697155952 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:39:59.698304892 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:39:59.743335962 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:40:00.324856997 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:40:00.324932098 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:40:00.325010061 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:40:00.325844049 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:40:00.325865984 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:40:00.325881958 CET49742443192.168.2.423.218.208.109
      Dec 2, 2024 07:40:00.325886965 CET4434974223.218.208.109192.168.2.4
      Dec 2, 2024 07:40:02.207343102 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:02.207395077 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:02.207501888 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:02.209207058 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:02.209218025 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:04.089487076 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:04.089644909 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:04.093076944 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:04.093086958 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:04.094188929 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:04.137763977 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:05.561940908 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:05.607336998 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182495117 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182519913 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182528973 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182538033 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182564974 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182620049 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:06.182655096 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.182672024 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:06.182704926 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:06.203062057 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.203149080 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:06.203180075 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:06.203223944 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:06.773335934 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:40:06.773396969 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:40:06.773464918 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:40:07.470585108 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:07.470616102 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:07.470629930 CET49743443192.168.2.44.175.87.197
      Dec 2, 2024 07:40:07.470635891 CET443497434.175.87.197192.168.2.4
      Dec 2, 2024 07:40:07.602157116 CET49738443192.168.2.4172.217.21.36
      Dec 2, 2024 07:40:07.602194071 CET44349738172.217.21.36192.168.2.4
      Dec 2, 2024 07:40:27.550713062 CET49740443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:27.550820112 CET49741443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:27.550863028 CET4434974094.217.52.151192.168.2.4
      Dec 2, 2024 07:40:27.550930977 CET4434974194.217.52.151192.168.2.4
      Dec 2, 2024 07:40:27.550937891 CET49740443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:27.550993919 CET49741443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.595417976 CET49750443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.595462084 CET4434975094.217.52.151192.168.2.4
      Dec 2, 2024 07:40:28.595525026 CET49750443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.595681906 CET49751443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.595737934 CET4434975194.217.52.151192.168.2.4
      Dec 2, 2024 07:40:28.595784903 CET49751443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.596493959 CET49751443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.596507072 CET4434975194.217.52.151192.168.2.4
      Dec 2, 2024 07:40:28.596635103 CET49750443192.168.2.494.217.52.151
      Dec 2, 2024 07:40:28.596647024 CET4434975094.217.52.151192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Dec 2, 2024 07:39:50.823453903 CET53535841.1.1.1192.168.2.4
      Dec 2, 2024 07:39:50.970561028 CET53615101.1.1.1192.168.2.4
      Dec 2, 2024 07:39:53.773526907 CET53652911.1.1.1192.168.2.4
      Dec 2, 2024 07:39:55.158288002 CET6512253192.168.2.41.1.1.1
      Dec 2, 2024 07:39:55.158288002 CET6373753192.168.2.41.1.1.1
      Dec 2, 2024 07:39:55.295964003 CET53651221.1.1.1192.168.2.4
      Dec 2, 2024 07:39:55.295980930 CET53637371.1.1.1192.168.2.4
      Dec 2, 2024 07:39:56.733076096 CET5114453192.168.2.41.1.1.1
      Dec 2, 2024 07:39:56.733340025 CET6197553192.168.2.41.1.1.1
      Dec 2, 2024 07:39:57.534137011 CET53511441.1.1.1192.168.2.4
      Dec 2, 2024 07:39:57.534430981 CET53619751.1.1.1192.168.2.4
      Dec 2, 2024 07:40:04.131732941 CET138138192.168.2.4192.168.2.255
      Dec 2, 2024 07:40:10.819905996 CET53616281.1.1.1192.168.2.4
      Dec 2, 2024 07:40:29.750895977 CET53649741.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Dec 2, 2024 07:39:55.158288002 CET192.168.2.41.1.1.10x25beStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Dec 2, 2024 07:39:55.158288002 CET192.168.2.41.1.1.10xadaStandard query (0)www.google.com65IN (0x0001)false
      Dec 2, 2024 07:39:56.733076096 CET192.168.2.41.1.1.10xdbb0Standard query (0)point-mutuel.comA (IP address)IN (0x0001)false
      Dec 2, 2024 07:39:56.733340025 CET192.168.2.41.1.1.10x638eStandard query (0)point-mutuel.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Dec 2, 2024 07:39:55.295964003 CET1.1.1.1192.168.2.40x25beNo error (0)www.google.com172.217.21.36A (IP address)IN (0x0001)false
      Dec 2, 2024 07:39:55.295980930 CET1.1.1.1192.168.2.40xadaNo error (0)www.google.com65IN (0x0001)false
      Dec 2, 2024 07:39:57.534137011 CET1.1.1.1192.168.2.40xdbb0No error (0)point-mutuel.com94.217.52.151A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • slscr.update.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44973923.218.208.109443
      TimestampBytes transferredDirectionData
      2024-12-02 06:39:57 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-12-02 06:39:57 UTC479INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Server: Kestrel
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-OSID: 2
      X-CID: 2
      X-CCC: GB
      Cache-Control: public, max-age=132403
      Date: Mon, 02 Dec 2024 06:39:57 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974223.218.208.109443
      TimestampBytes transferredDirectionData
      2024-12-02 06:39:59 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-12-02 06:40:00 UTC535INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
      Cache-Control: public, max-age=192324
      Date: Mon, 02 Dec 2024 06:40:00 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-12-02 06:40:00 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.4497434.175.87.197443
      TimestampBytes transferredDirectionData
      2024-12-02 06:40:05 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=7yGPpgGB35nzk6T&MD=LCcU9Gg9 HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
      Host: slscr.update.microsoft.com
      2024-12-02 06:40:06 UTC560INHTTP/1.1 200 OK
      Cache-Control: no-cache
      Pragma: no-cache
      Content-Type: application/octet-stream
      Expires: -1
      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
      ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
      MS-CorrelationId: 154e1e10-d038-46f2-915f-c68123ef48d1
      MS-RequestId: 5b1b75d6-83f7-4206-b553-b5630fe3d56a
      MS-CV: TWfMSVXarkCA2Q9B.0
      X-Microsoft-SLSClientCache: 2880
      Content-Disposition: attachment; filename=environment.cab
      X-Content-Type-Options: nosniff
      Date: Mon, 02 Dec 2024 06:40:04 GMT
      Connection: close
      Content-Length: 24490
      2024-12-02 06:40:06 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
      Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
      2024-12-02 06:40:06 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
      Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:39:44
      Start date:02/12/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:01:39:49
      Start date:02/12/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1980,i,5088498168306710667,14428680290771934357,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:01:39:56
      Start date:02/12/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://point-mutuel.com/onRcDoGwglrtfqNwihPaWzmqihxspiPhnlPnxcmznlPnPhPhpiyiWhwislPnvsPhnlRcjqPnnlPnvDPhihPnpiApihhxfpDrnlPnNXZvpiFvWzZvonNXdQdQ%20%5B217.75.213.239%5D"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly