Edit tour

Windows Analysis Report
https://inesrush.shop/hedghog.mp4

Overview

General Information

Sample URL:https://inesrush.shop/hedghog.mp4
Analysis ID:1606865
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Confidence:60%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6708 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 2988 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2012,i,10141850930537608241,4546139592712272976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 5368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://inesrush.shop/hedghog.mp4" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49804 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: inesrush.shop
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49804 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@20/0@19/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2012,i,10141850930537608241,4546139592712272976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://inesrush.shop/hedghog.mp4"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2012,i,10141850930537608241,4546139592712272976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1606865 URL: https://inesrush.shop/hedghog.mp4 Startdate: 04/02/2025 Architecture: WINDOWS Score: 0 14 inesrush.shop 2->14 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.6, 443, 49400, 49705 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 142.250.184.196, 443, 49743 GOOGLEUS United States 11->20 22 inesrush.shop 11->22 24 google.com 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://inesrush.shop/hedghog.mp40%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
216.58.206.46
truefalse
    high
    www.google.com
    142.250.184.196
    truefalse
      high
      inesrush.shop
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.184.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.6
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1606865
        Start date and time:2025-02-04 22:37:25 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 6s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://inesrush.shop/hedghog.mp4
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@20/0@19/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 216.58.206.46, 66.102.1.84, 142.250.184.227, 142.250.185.78, 172.217.18.14, 2.23.77.188, 199.232.214.172, 216.58.206.78, 142.250.186.142, 13.107.246.45, 184.28.90.27, 4.245.163.56
        • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://inesrush.shop/hedghog.mp4
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 67
        • 443 (HTTPS)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Feb 4, 2025 22:38:21.147195101 CET49673443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:21.147197008 CET49674443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:21.428452969 CET49672443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:22.914560080 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:22.914607048 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:22.914679050 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:22.915776968 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:22.915792942 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:23.881243944 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:23.881373882 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:23.886219978 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:23.886230946 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:23.886488914 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:23.890930891 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:23.891217947 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:23.891223907 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:23.891500950 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:23.939332962 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:24.067827940 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:24.068078041 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:24.069108963 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:24.069372892 CET49709443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:24.069390059 CET4434970940.113.110.67192.168.2.6
        Feb 4, 2025 22:38:30.756472111 CET49673443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:30.776793957 CET49674443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:31.084486961 CET49672443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:31.300614119 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:31.300671101 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:31.300846100 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:31.301387072 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:31.301399946 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.104685068 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.104764938 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.108740091 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.108747959 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.109002113 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.130920887 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.130997896 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.131004095 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.131169081 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.171334982 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.305762053 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.305850983 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.305912971 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.306287050 CET49714443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:32.306304932 CET4434971440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:32.704380989 CET44349705173.222.162.64192.168.2.6
        Feb 4, 2025 22:38:32.704492092 CET49705443192.168.2.6173.222.162.64
        Feb 4, 2025 22:38:35.264060974 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.264116049 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.264264107 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.264465094 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.264482975 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.935095072 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.935343027 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.935365915 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.936409950 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.936470032 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.937550068 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.937612057 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:35.988737106 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:35.988766909 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:36.035623074 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:44.327130079 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:44.327166080 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:44.327239037 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:44.327943087 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:44.327955961 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.126852989 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.127002954 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.134221077 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.134246111 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.134496927 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.136377096 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.136430025 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.136436939 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.136568069 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.179328918 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.306454897 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.306607008 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.306736946 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.307544947 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.307560921 CET4434980440.113.110.67192.168.2.6
        Feb 4, 2025 22:38:45.307569981 CET49804443192.168.2.640.113.110.67
        Feb 4, 2025 22:38:45.817207098 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:45.817270994 CET44349743142.250.184.196192.168.2.6
        Feb 4, 2025 22:38:45.817464113 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:47.475306034 CET49743443192.168.2.6142.250.184.196
        Feb 4, 2025 22:38:47.475328922 CET44349743142.250.184.196192.168.2.6
        TimestampSource PortDest PortSource IPDest IP
        Feb 4, 2025 22:38:31.148745060 CET53583151.1.1.1192.168.2.6
        Feb 4, 2025 22:38:31.190208912 CET53544521.1.1.1192.168.2.6
        Feb 4, 2025 22:38:32.218700886 CET53498011.1.1.1192.168.2.6
        Feb 4, 2025 22:38:35.255795002 CET5922453192.168.2.61.1.1.1
        Feb 4, 2025 22:38:35.255950928 CET5073153192.168.2.61.1.1.1
        Feb 4, 2025 22:38:35.262573004 CET53592241.1.1.1192.168.2.6
        Feb 4, 2025 22:38:35.263247967 CET53507311.1.1.1192.168.2.6
        Feb 4, 2025 22:38:37.052612066 CET6405053192.168.2.61.1.1.1
        Feb 4, 2025 22:38:37.052969933 CET5885553192.168.2.61.1.1.1
        Feb 4, 2025 22:38:37.062398911 CET53640501.1.1.1192.168.2.6
        Feb 4, 2025 22:38:37.062740088 CET53588551.1.1.1192.168.2.6
        Feb 4, 2025 22:38:37.070714951 CET5547053192.168.2.61.1.1.1
        Feb 4, 2025 22:38:37.078850031 CET53554701.1.1.1192.168.2.6
        Feb 4, 2025 22:38:37.159837961 CET5548253192.168.2.68.8.8.8
        Feb 4, 2025 22:38:37.161679029 CET5067853192.168.2.61.1.1.1
        Feb 4, 2025 22:38:37.169372082 CET53506781.1.1.1192.168.2.6
        Feb 4, 2025 22:38:37.174981117 CET53554828.8.8.8192.168.2.6
        Feb 4, 2025 22:38:38.170679092 CET6282553192.168.2.61.1.1.1
        Feb 4, 2025 22:38:38.171056032 CET6356053192.168.2.61.1.1.1
        Feb 4, 2025 22:38:38.180404902 CET53628251.1.1.1192.168.2.6
        Feb 4, 2025 22:38:38.180906057 CET53635601.1.1.1192.168.2.6
        Feb 4, 2025 22:38:38.183084965 CET5943853192.168.2.61.1.1.1
        Feb 4, 2025 22:38:38.183228016 CET5880953192.168.2.61.1.1.1
        Feb 4, 2025 22:38:38.192030907 CET53594381.1.1.1192.168.2.6
        Feb 4, 2025 22:38:38.192456961 CET53588091.1.1.1192.168.2.6
        Feb 4, 2025 22:38:43.230866909 CET5116253192.168.2.61.1.1.1
        Feb 4, 2025 22:38:43.230954885 CET5329353192.168.2.61.1.1.1
        Feb 4, 2025 22:38:43.239763021 CET53511621.1.1.1192.168.2.6
        Feb 4, 2025 22:38:43.239837885 CET53532931.1.1.1192.168.2.6
        Feb 4, 2025 22:38:43.243370056 CET6121153192.168.2.61.1.1.1
        Feb 4, 2025 22:38:43.252295971 CET53612111.1.1.1192.168.2.6
        Feb 4, 2025 22:38:49.264548063 CET53500231.1.1.1192.168.2.6
        Feb 4, 2025 22:38:51.685060978 CET6085653192.168.2.61.1.1.1
        Feb 4, 2025 22:38:51.685269117 CET5962653192.168.2.61.1.1.1
        Feb 4, 2025 22:38:51.693865061 CET53608561.1.1.1192.168.2.6
        Feb 4, 2025 22:38:51.694525957 CET53596261.1.1.1192.168.2.6
        Feb 4, 2025 22:38:51.697114944 CET4940053192.168.2.61.1.1.1
        Feb 4, 2025 22:38:51.706743002 CET53494001.1.1.1192.168.2.6
        Feb 4, 2025 22:38:51.717931986 CET5712753192.168.2.61.1.1.1
        Feb 4, 2025 22:38:51.718188047 CET5323353192.168.2.68.8.8.8
        Feb 4, 2025 22:38:51.725301027 CET53571271.1.1.1192.168.2.6
        Feb 4, 2025 22:38:51.726459026 CET53532338.8.8.8192.168.2.6
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Feb 4, 2025 22:38:35.255795002 CET192.168.2.61.1.1.10x3977Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:35.255950928 CET192.168.2.61.1.1.10xda49Standard query (0)www.google.com65IN (0x0001)false
        Feb 4, 2025 22:38:37.052612066 CET192.168.2.61.1.1.10x74f9Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.052969933 CET192.168.2.61.1.1.10xadd5Standard query (0)inesrush.shop65IN (0x0001)false
        Feb 4, 2025 22:38:37.070714951 CET192.168.2.61.1.1.10xdc44Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.159837961 CET192.168.2.68.8.8.80xc36eStandard query (0)google.comA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.161679029 CET192.168.2.61.1.1.10x78b4Standard query (0)google.comA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.170679092 CET192.168.2.61.1.1.10xfb89Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.171056032 CET192.168.2.61.1.1.10x1b8bStandard query (0)inesrush.shop65IN (0x0001)false
        Feb 4, 2025 22:38:38.183084965 CET192.168.2.61.1.1.10xcd64Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.183228016 CET192.168.2.61.1.1.10x17cStandard query (0)inesrush.shop65IN (0x0001)false
        Feb 4, 2025 22:38:43.230866909 CET192.168.2.61.1.1.10x3f34Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:43.230954885 CET192.168.2.61.1.1.10x5beeStandard query (0)inesrush.shop65IN (0x0001)false
        Feb 4, 2025 22:38:43.243370056 CET192.168.2.61.1.1.10x96aaStandard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.685060978 CET192.168.2.61.1.1.10x9ac1Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.685269117 CET192.168.2.61.1.1.10xb5c9Standard query (0)inesrush.shop65IN (0x0001)false
        Feb 4, 2025 22:38:51.697114944 CET192.168.2.61.1.1.10x16a4Standard query (0)inesrush.shopA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.717931986 CET192.168.2.61.1.1.10x8afdStandard query (0)google.comA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.718188047 CET192.168.2.68.8.8.80x2216Standard query (0)google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Feb 4, 2025 22:38:35.262573004 CET1.1.1.1192.168.2.60x3977No error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:35.263247967 CET1.1.1.1192.168.2.60xda49No error (0)www.google.com65IN (0x0001)false
        Feb 4, 2025 22:38:37.062398911 CET1.1.1.1192.168.2.60x74f9Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.062740088 CET1.1.1.1192.168.2.60xadd5Name error (3)inesrush.shopnonenone65IN (0x0001)false
        Feb 4, 2025 22:38:37.078850031 CET1.1.1.1192.168.2.60xdc44Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.169372082 CET1.1.1.1192.168.2.60x78b4No error (0)google.com216.58.206.46A (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:37.174981117 CET8.8.8.8192.168.2.60xc36eNo error (0)google.com172.217.17.110A (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.180404902 CET1.1.1.1192.168.2.60xfb89Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.180906057 CET1.1.1.1192.168.2.60x1b8bName error (3)inesrush.shopnonenone65IN (0x0001)false
        Feb 4, 2025 22:38:38.192030907 CET1.1.1.1192.168.2.60xcd64Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:38.192456961 CET1.1.1.1192.168.2.60x17cName error (3)inesrush.shopnonenone65IN (0x0001)false
        Feb 4, 2025 22:38:43.239763021 CET1.1.1.1192.168.2.60x3f34Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:43.239837885 CET1.1.1.1192.168.2.60x5beeName error (3)inesrush.shopnonenone65IN (0x0001)false
        Feb 4, 2025 22:38:43.252295971 CET1.1.1.1192.168.2.60x96aaName error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.693865061 CET1.1.1.1192.168.2.60x9ac1Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.694525957 CET1.1.1.1192.168.2.60xb5c9Name error (3)inesrush.shopnonenone65IN (0x0001)false
        Feb 4, 2025 22:38:51.706743002 CET1.1.1.1192.168.2.60x16a4Name error (3)inesrush.shopnonenoneA (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.725301027 CET1.1.1.1192.168.2.60x8afdNo error (0)google.com216.58.212.142A (IP address)IN (0x0001)false
        Feb 4, 2025 22:38:51.726459026 CET8.8.8.8192.168.2.60x2216No error (0)google.com172.217.17.110A (IP address)IN (0x0001)false
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.64970940.113.110.67443
        TimestampBytes transferredDirectionData
        2025-02-04 21:38:23 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 50 67 4b 2b 57 41 4e 48 6a 6b 75 49 75 2b 4c 51 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 65 66 63 31 62 66 37 64 32 36 37 62 61 31 32 0d 0a 0d 0a
        Data Ascii: CNT 1 CON 305MS-CV: PgK+WANHjkuIu+LQ.1Context: befc1bf7d267ba12
        2025-02-04 21:38:23 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
        2025-02-04 21:38:23 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 50 67 4b 2b 57 41 4e 48 6a 6b 75 49 75 2b 4c 51 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 65 66 63 31 62 66 37 64 32 36 37 62 61 31 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 5a 73 2f 77 5a 53 63 58 7a 77 42 67 59 48 4a 75 4a 44 43 6f 56 57 52 71 36 35 4b 7a 71 6a 6a 37 42 32 4e 6a 67 2b 63 33 67 4a 69 57 70 58 65 4e 76 43 79 78 6d 57 42 46 4d 37 56 62 55 41 48 4a 63 51 4a 61 57 75 76 6b 4e 76 71 61 70 78 6c 56 68 6e 70 49 64 61 32 71 47 2f 37 4b 48 67 55 44 67 2b 45 57 77 56 79 4f 62 78 68 31 51
        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: PgK+WANHjkuIu+LQ.2Context: befc1bf7d267ba12<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAZs/wZScXzwBgYHJuJDCoVWRq65Kzqjj7B2Njg+c3gJiWpXeNvCyxmWBFM7VbUAHJcQJaWuvkNvqapxlVhnpIda2qG/7KHgUDg+EWwVyObxh1Q
        2025-02-04 21:38:23 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 50 67 4b 2b 57 41 4e 48 6a 6b 75 49 75 2b 4c 51 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 65 66 63 31 62 66 37 64 32 36 37 62 61 31 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
        Data Ascii: BND 3 CON\WNS 0 197MS-CV: PgK+WANHjkuIu+LQ.3Context: befc1bf7d267ba12<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
        2025-02-04 21:38:24 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
        Data Ascii: 202 1 CON 58
        2025-02-04 21:38:24 UTC58INData Raw: 4d 53 2d 43 56 3a 20 32 41 67 4e 72 79 6f 56 5a 45 43 70 62 30 42 63 43 66 4e 36 51 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
        Data Ascii: MS-CV: 2AgNryoVZECpb0BcCfN6QA.0Payload parsing failed.


        Session IDSource IPSource PortDestination IPDestination Port
        1192.168.2.64971440.113.110.67443
        TimestampBytes transferredDirectionData
        2025-02-04 21:38:32 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 6f 5a 47 44 58 7a 64 4a 4c 55 61 59 35 4c 68 43 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 65 30 36 62 61 32 39 38 66 61 63 62 36 64 65 0d 0a 0d 0a
        Data Ascii: CNT 1 CON 305MS-CV: oZGDXzdJLUaY5LhC.1Context: fe06ba298facb6de
        2025-02-04 21:38:32 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
        2025-02-04 21:38:32 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 6f 5a 47 44 58 7a 64 4a 4c 55 61 59 35 4c 68 43 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 65 30 36 62 61 32 39 38 66 61 63 62 36 64 65 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 5a 73 2f 77 5a 53 63 58 7a 77 42 67 59 48 4a 75 4a 44 43 6f 56 57 52 71 36 35 4b 7a 71 6a 6a 37 42 32 4e 6a 67 2b 63 33 67 4a 69 57 70 58 65 4e 76 43 79 78 6d 57 42 46 4d 37 56 62 55 41 48 4a 63 51 4a 61 57 75 76 6b 4e 76 71 61 70 78 6c 56 68 6e 70 49 64 61 32 71 47 2f 37 4b 48 67 55 44 67 2b 45 57 77 56 79 4f 62 78 68 31 51
        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: oZGDXzdJLUaY5LhC.2Context: fe06ba298facb6de<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAZs/wZScXzwBgYHJuJDCoVWRq65Kzqjj7B2Njg+c3gJiWpXeNvCyxmWBFM7VbUAHJcQJaWuvkNvqapxlVhnpIda2qG/7KHgUDg+EWwVyObxh1Q
        2025-02-04 21:38:32 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 6f 5a 47 44 58 7a 64 4a 4c 55 61 59 35 4c 68 43 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 65 30 36 62 61 32 39 38 66 61 63 62 36 64 65 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
        Data Ascii: BND 3 CON\WNS 0 197MS-CV: oZGDXzdJLUaY5LhC.3Context: fe06ba298facb6de<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
        2025-02-04 21:38:32 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
        Data Ascii: 202 1 CON 58
        2025-02-04 21:38:32 UTC58INData Raw: 4d 53 2d 43 56 3a 20 4b 41 52 7a 71 4d 34 4f 31 6b 65 76 54 64 48 74 49 50 69 4f 65 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
        Data Ascii: MS-CV: KARzqM4O1kevTdHtIPiOeA.0Payload parsing failed.


        Session IDSource IPSource PortDestination IPDestination Port
        2192.168.2.64980440.113.110.67443
        TimestampBytes transferredDirectionData
        2025-02-04 21:38:45 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4a 42 55 54 64 68 6b 4b 55 6b 4f 54 6f 55 2f 55 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 35 33 64 66 36 62 39 36 39 62 39 61 32 34 36 0d 0a 0d 0a
        Data Ascii: CNT 1 CON 305MS-CV: JBUTdhkKUkOToU/U.1Context: e53df6b969b9a246
        2025-02-04 21:38:45 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
        2025-02-04 21:38:45 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4a 42 55 54 64 68 6b 4b 55 6b 4f 54 6f 55 2f 55 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 35 33 64 66 36 62 39 36 39 62 39 61 32 34 36 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 5a 73 2f 77 5a 53 63 58 7a 77 42 67 59 48 4a 75 4a 44 43 6f 56 57 52 71 36 35 4b 7a 71 6a 6a 37 42 32 4e 6a 67 2b 63 33 67 4a 69 57 70 58 65 4e 76 43 79 78 6d 57 42 46 4d 37 56 62 55 41 48 4a 63 51 4a 61 57 75 76 6b 4e 76 71 61 70 78 6c 56 68 6e 70 49 64 61 32 71 47 2f 37 4b 48 67 55 44 67 2b 45 57 77 56 79 4f 62 78 68 31 51
        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: JBUTdhkKUkOToU/U.2Context: e53df6b969b9a246<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAZs/wZScXzwBgYHJuJDCoVWRq65Kzqjj7B2Njg+c3gJiWpXeNvCyxmWBFM7VbUAHJcQJaWuvkNvqapxlVhnpIda2qG/7KHgUDg+EWwVyObxh1Q
        2025-02-04 21:38:45 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 4a 42 55 54 64 68 6b 4b 55 6b 4f 54 6f 55 2f 55 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 35 33 64 66 36 62 39 36 39 62 39 61 32 34 36 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
        Data Ascii: BND 3 CON\WNS 0 197MS-CV: JBUTdhkKUkOToU/U.3Context: e53df6b969b9a246<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
        2025-02-04 21:38:45 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
        Data Ascii: 202 1 CON 58
        2025-02-04 21:38:45 UTC58INData Raw: 4d 53 2d 43 56 3a 20 6e 75 4a 61 64 7a 47 66 50 45 69 46 73 2b 4c 49 37 46 45 66 2b 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
        Data Ascii: MS-CV: nuJadzGfPEiFs+LI7FEf+A.0Payload parsing failed.


        01020s020406080100

        Click to jump to process

        01020s0.0020406080100MB

        Click to jump to process

        Target ID:1
        Start time:16:38:23
        Start date:04/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff684c40000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:16:38:29
        Start date:04/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2012,i,10141850930537608241,4546139592712272976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff684c40000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:16:38:35
        Start date:04/02/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://inesrush.shop/hedghog.mp4"
        Imagebase:0x7ff684c40000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly