Edit tour

Windows Analysis Report
https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&

Overview

General Information

Sample URL:https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&
Analysis ID:1670349
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1624 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2212 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1908,i,10654103830872755967,2167236336096847200,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6860 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a& HTTP/1.1Host: cdn.discordapp.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.discordapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=Oii2A2YnydETN.vLo7d68ahMlqILoRs_IMAgs8ZRVfY-1745245265-1.0.1.1-ZUzUvIjTR_MfVoSPwLhoQlwO.ymf1TtbllX.CasxICezoYZUH1ARrEj_3cRLtwU5pP0_q0xF3CjZET1NS.WtRr0.2i6dEFEwYwzj3rxq0Rg; _cfuvid=v7jO7iJfwCHwvXRRju3P2LUwlaJzo56W8IGUuCSYx4Y-1745245265029-0.0.1.1-604800000
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: cdn.discordapp.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 552Content-Type: application/reports+jsonOrigin: https://cdn.discordapp.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 21 Apr 2025 14:21:05 GMTContent-Type: text/plain;charset=UTF-8Content-Length: 36Connection: closeSet-Cookie: __cf_bm=Oii2A2YnydETN.vLo7d68ahMlqILoRs_IMAgs8ZRVfY-1745245265-1.0.1.1-ZUzUvIjTR_MfVoSPwLhoQlwO.ymf1TtbllX.CasxICezoYZUH1ARrEj_3cRLtwU5pP0_q0xF3CjZET1NS.WtRr0.2i6dEFEwYwzj3rxq0Rg; path=/; expires=Mon, 21-Apr-25 14:51:05 GMT; domain=.discordapp.com; HttpOnly; Secure; SameSite=NoneReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodpSet-Cookie: _cfuvid=v7jO7iJfwCHwvXRRju3P2LUwlaJzo56W8IGUuCSYx4Y-1745245265029-0.0.1.1-604800000; path=/; domain=.discordapp.com; HttpOnly; Secure; SameSite=NoneServer: cloudflareCF-RAY: 933d869a5a98f7d7-LAXalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 21 Apr 2025 14:21:06 GMTContent-Type: application/xml; charset=UTF-8Content-Length: 298Connection: closex-guploader-uploadid: AAO2VwqcK9ywYqi4lryL1c5N7tkfaGqqGjw8g9mN54khE8mSvegcnMCWgoYNn7zE2rlGcrGwdV12rScexpires: Mon, 21 Apr 2025 14:21:06 GMTCache-Control: private, max-age=0alt-svc: h3=":443"; ma=86400CF-Cache-Status: MISSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BBuU6EcO%2BIvQuhtFMql85QLQFhDEuSuSqVcna0GLQY5x1HDzK2%2FS0PR1dNyRg4IrRnuKJblhscAnuO6dAgF0%2BNnxldJLxs7laOso%2FfnQe2XzsBC6iK7qcAPUKNpcAZAg6xHwJg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodpServer: cloudflareCF-RAY: 933d869d0f0f2b9e-LAX
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1908,i,10654103830872755967,2167236336096847200,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1908,i,10654103830872755967,2167236336096847200,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1670349 URL: https://cdn.discordapp.com/... Startdate: 21/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49708 unknown unknown 5->13 15 192.168.2.7 unknown unknown 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 192.178.49.164, 443, 49725, 49741 GOOGLEUS United States 10->17 19 a.nel.cloudflare.com 35.190.80.1, 443, 49728, 49730 GOOGLEUS United States 10->19 21 cdn.discordapp.com 162.159.129.233, 443, 49726, 49727 CLOUDFLARENETUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    cdn.discordapp.com
    162.159.129.233
    truefalse
      high
      www.google.com
      192.178.49.164
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&false
          high
          https://a.nel.cloudflare.com/report/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3Dfalse
            high
            https://cdn.discordapp.com/favicon.icofalse
              high
              https://a.nel.cloudflare.com/report/v4?s=%2BBuU6EcO%2BIvQuhtFMql85QLQFhDEuSuSqVcna0GLQY5x1HDzK2%2FS0PR1dNyRg4IrRnuKJblhscAnuO6dAgF0%2BNnxldJLxs7laOso%2FfnQe2XzsBC6iK7qcAPUKNpcAZAg6xHwJg%3D%3Dfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                192.178.49.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                162.159.129.233
                cdn.discordapp.comUnited States
                13335CLOUDFLARENETUSfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.7
                192.168.2.4
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1670349
                Start date and time:2025-04-21 16:20:00 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 56s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:20
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@21/4@6/5
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 192.178.49.195, 192.178.49.206, 142.251.2.84, 192.178.49.174, 72.247.234.254, 84.201.221.40, 142.250.69.3, 184.29.183.29, 4.175.87.197
                • Excluded domains from analysis (whitelisted): a-ring-fallback.msedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, update.googleapis.com, clients.l.google.com, c.pki.goog
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&amp;is=67f896b8&amp;hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&amp;
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):36
                Entropy (8bit):3.8537006129630296
                Encrypted:false
                SSDEEP:3:hGQRALjVLeJKuWJu:hCVLWqu
                MD5:A1CA4BEBCD03FAFBE2B06A46A694E29A
                SHA1:FFC88125007C23FF6711147A12F9BBA9C3D197ED
                SHA-256:C3FA59901D56CE8A95A303B22FD119CB94ABF4F43C4F6D60A81FD78B7D00FA65
                SHA-512:6FE1730BF2A6BBA058C5E1EF309A69079A6ACCA45C0DBCA4E7D79C877257AC08E460AF741459D1E335197CF4DE209F2A2997816F2A2A3868B2C8D086EF789B0E
                Malicious:false
                Reputation:low
                URL:https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&
                Preview:This content is no longer available.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):298
                Entropy (8bit):4.710444260224062
                Encrypted:false
                SSDEEP:6:TM3i0b9ZjZvKtWRbtmdsfbPAxjqm1bATlAPAxB8AWLWFQ7ERTKvn:TM3i0b9BZKtWRbtmdsfbPAxjqSkpAPAk
                MD5:3861A3795095FE81FCB8382D2B9066BD
                SHA1:2CEF2AF9A35D636C3AF48902C20891EC49A8E791
                SHA-256:B19463CB9B847BDFC7DBF8133D9702D0A0ECC4175335C4A75DB211E0196F84B3
                SHA-512:8E881D7F7A8236D36AEF500473A3DBC5A98D46C1596D33AB76E4669F858D86C6B4881C0882C37D2D32B888FCAF6280385932CA5FFC6A5143D625C71B8FC8B294
                Malicious:false
                Reputation:low
                URL:https://cdn.discordapp.com/favicon.ico
                Preview:<?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message><Details>Anonymous caller does not have storage.objects.get access to the Google Cloud Storage object. Permission 'storage.objects.get' denied on resource (or it may not exist).</Details></Error>
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 79
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Apr 21, 2025 16:20:51.874634027 CEST4968180192.168.2.42.17.190.73
                Apr 21, 2025 16:20:58.127342939 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:20:58.494657993 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:20:59.117927074 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:21:00.481949091 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:21:01.483700991 CEST4968180192.168.2.42.17.190.73
                Apr 21, 2025 16:21:02.889591932 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:21:03.408935070 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:03.408986092 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:03.409091949 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:03.409291029 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:03.409308910 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:03.728437901 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:03.728518963 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:03.729984999 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:03.729998112 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:03.730581045 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:03.780169964 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:04.454638004 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.454689980 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.454767942 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.455239058 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.455275059 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.455434084 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.455446959 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.455466986 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.455638885 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.455653906 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.760814905 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.760956049 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.762341022 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.762353897 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.762578964 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.762593031 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.762687922 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.763739109 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.763751030 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.763984919 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.764091969 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:04.804280043 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:04.812757015 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:05.105925083 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:05.106008053 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:05.106126070 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:05.286659002 CEST49727443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:05.286722898 CEST44349727162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:05.369252920 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:05.376499891 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.376549006 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:05.376673937 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.376854897 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.376880884 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:05.412277937 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:05.684446096 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:05.684837103 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.686232090 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.686242104 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:05.686499119 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:05.690017939 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:05.732279062 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.020366907 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.020467997 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.020535946 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.020809889 CEST49728443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.020828962 CEST4434972835.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.021876097 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.021914005 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.021979094 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.022156000 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.022166014 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.230868101 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:06.230930090 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:06.230976105 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:06.231910944 CEST49726443192.168.2.4162.159.129.233
                Apr 21, 2025 16:21:06.231928110 CEST44349726162.159.129.233192.168.2.4
                Apr 21, 2025 16:21:06.325172901 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.325473070 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.325490952 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.325834990 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.325839996 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.580998898 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:06.667192936 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.667267084 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.667318106 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.667619944 CEST49730443192.168.2.435.190.80.1
                Apr 21, 2025 16:21:06.667638063 CEST4434973035.190.80.1192.168.2.4
                Apr 21, 2025 16:21:06.890070915 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:07.499445915 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:07.702600002 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:21:08.702661991 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:10.497167110 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.500957966 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.501665115 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.637123108 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.638444901 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.638458967 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.638504982 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.638560057 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.639027119 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.640738010 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.641530991 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.641593933 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.643892050 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.643903971 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.643969059 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.648161888 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.779280901 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.788381100 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.791167021 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.791181087 CEST4434970852.113.196.254192.168.2.4
                Apr 21, 2025 16:21:10.791249037 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:10.791291952 CEST49708443192.168.2.452.113.196.254
                Apr 21, 2025 16:21:11.108975887 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:13.721796989 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:13.721865892 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:13.722002983 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:14.238486052 CEST49725443192.168.2.4192.178.49.164
                Apr 21, 2025 16:21:14.238521099 CEST44349725192.178.49.164192.168.2.4
                Apr 21, 2025 16:21:15.921606064 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:21:17.312293053 CEST49671443192.168.2.4204.79.197.203
                Apr 21, 2025 16:21:25.538218975 CEST49678443192.168.2.420.189.173.27
                Apr 21, 2025 16:22:03.329093933 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:03.329130888 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:03.329221964 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:03.329678059 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:03.329694033 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:03.645054102 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:03.645379066 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:03.645397902 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:05.235109091 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.235145092 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.235724926 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.235948086 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.235959053 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.537342072 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.537738085 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.537760973 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.537911892 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.537923098 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.878308058 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.878381014 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.878489017 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.878964901 CEST49742443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.878983974 CEST4434974235.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.879873991 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.879904032 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:05.879985094 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.880171061 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:05.880181074 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.181045055 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.181473970 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:06.181490898 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.181658983 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:06.181663036 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.521971941 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.522042990 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:06.522097111 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:06.522520065 CEST49744443192.168.2.435.190.80.1
                Apr 21, 2025 16:22:06.522537947 CEST4434974435.190.80.1192.168.2.4
                Apr 21, 2025 16:22:13.647790909 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:13.647854090 CEST44349741192.178.49.164192.168.2.4
                Apr 21, 2025 16:22:13.647942066 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:14.236363888 CEST49741443192.168.2.4192.178.49.164
                Apr 21, 2025 16:22:14.236381054 CEST44349741192.178.49.164192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 21, 2025 16:20:59.348558903 CEST53559111.1.1.1192.168.2.4
                Apr 21, 2025 16:20:59.404779911 CEST53639631.1.1.1192.168.2.4
                Apr 21, 2025 16:21:00.802839994 CEST53647471.1.1.1192.168.2.4
                Apr 21, 2025 16:21:03.265630960 CEST6376153192.168.2.41.1.1.1
                Apr 21, 2025 16:21:03.265786886 CEST6098953192.168.2.41.1.1.1
                Apr 21, 2025 16:21:03.406985044 CEST53609891.1.1.1192.168.2.4
                Apr 21, 2025 16:21:03.407891989 CEST53637611.1.1.1192.168.2.4
                Apr 21, 2025 16:21:04.311903954 CEST5768953192.168.2.41.1.1.1
                Apr 21, 2025 16:21:04.312102079 CEST5357353192.168.2.41.1.1.1
                Apr 21, 2025 16:21:04.452142000 CEST53576891.1.1.1192.168.2.4
                Apr 21, 2025 16:21:04.453257084 CEST53535731.1.1.1192.168.2.4
                Apr 21, 2025 16:21:05.234303951 CEST5215053192.168.2.41.1.1.1
                Apr 21, 2025 16:21:05.234539986 CEST6389753192.168.2.41.1.1.1
                Apr 21, 2025 16:21:05.374686003 CEST53521501.1.1.1192.168.2.4
                Apr 21, 2025 16:21:05.374883890 CEST53638971.1.1.1192.168.2.4
                Apr 21, 2025 16:21:17.704184055 CEST53557401.1.1.1192.168.2.4
                Apr 21, 2025 16:21:36.660566092 CEST53645821.1.1.1192.168.2.4
                Apr 21, 2025 16:21:58.628504038 CEST53510701.1.1.1192.168.2.4
                Apr 21, 2025 16:21:59.263012886 CEST53572801.1.1.1192.168.2.4
                Apr 21, 2025 16:22:02.017082930 CEST53604981.1.1.1192.168.2.4
                Apr 21, 2025 16:22:07.537215948 CEST138138192.168.2.4192.168.2.255
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 21, 2025 16:21:03.265630960 CEST192.168.2.41.1.1.10xa707Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:03.265786886 CEST192.168.2.41.1.1.10x4fe2Standard query (0)www.google.com65IN (0x0001)false
                Apr 21, 2025 16:21:04.311903954 CEST192.168.2.41.1.1.10x700cStandard query (0)cdn.discordapp.comA (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.312102079 CEST192.168.2.41.1.1.10xb80bStandard query (0)cdn.discordapp.com65IN (0x0001)false
                Apr 21, 2025 16:21:05.234303951 CEST192.168.2.41.1.1.10xf1abStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:05.234539986 CEST192.168.2.41.1.1.10x21a5Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 21, 2025 16:21:03.406985044 CEST1.1.1.1192.168.2.40x4fe2No error (0)www.google.com65IN (0x0001)false
                Apr 21, 2025 16:21:03.407891989 CEST1.1.1.1192.168.2.40xa707No error (0)www.google.com192.178.49.164A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.452142000 CEST1.1.1.1192.168.2.40x700cNo error (0)cdn.discordapp.com162.159.129.233A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.452142000 CEST1.1.1.1192.168.2.40x700cNo error (0)cdn.discordapp.com162.159.133.233A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.452142000 CEST1.1.1.1192.168.2.40x700cNo error (0)cdn.discordapp.com162.159.134.233A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.452142000 CEST1.1.1.1192.168.2.40x700cNo error (0)cdn.discordapp.com162.159.135.233A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.452142000 CEST1.1.1.1192.168.2.40x700cNo error (0)cdn.discordapp.com162.159.130.233A (IP address)IN (0x0001)false
                Apr 21, 2025 16:21:04.453257084 CEST1.1.1.1192.168.2.40xb80bNo error (0)cdn.discordapp.com65IN (0x0001)false
                Apr 21, 2025 16:21:05.374686003 CEST1.1.1.1192.168.2.40xf1abNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                • cdn.discordapp.com
                • a.nel.cloudflare.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449727162.159.129.2334432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:21:04 UTC829OUTGET /attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a& HTTP/1.1
                Host: cdn.discordapp.com
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-21 14:21:05 UTC1077INHTTP/1.1 404 Not Found
                Date: Mon, 21 Apr 2025 14:21:05 GMT
                Content-Type: text/plain;charset=UTF-8
                Content-Length: 36
                Connection: close
                Set-Cookie: __cf_bm=Oii2A2YnydETN.vLo7d68ahMlqILoRs_IMAgs8ZRVfY-1745245265-1.0.1.1-ZUzUvIjTR_MfVoSPwLhoQlwO.ymf1TtbllX.CasxICezoYZUH1ARrEj_3cRLtwU5pP0_q0xF3CjZET1NS.WtRr0.2i6dEFEwYwzj3rxq0Rg; path=/; expires=Mon, 21-Apr-25 14:51:05 GMT; domain=.discordapp.com; HttpOnly; Secure; SameSite=None
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
                Set-Cookie: _cfuvid=v7jO7iJfwCHwvXRRju3P2LUwlaJzo56W8IGUuCSYx4Y-1745245265029-0.0.1.1-604800000; path=/; domain=.discordapp.com; HttpOnly; Secure; SameSite=None
                Server: cloudflare
                CF-RAY: 933d869a5a98f7d7-LAX
                alt-svc: h3=":443"; ma=86400
                2025-04-21 14:21:05 UTC36INData Raw: 54 68 69 73 20 63 6f 6e 74 65 6e 74 20 69 73 20 6e 6f 20 6c 6f 6e 67 65 72 20 61 76 61 69 6c 61 62 6c 65 2e
                Data Ascii: This content is no longer available.


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449726162.159.129.2334432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:21:05 UTC1033OUTGET /favicon.ico HTTP/1.1
                Host: cdn.discordapp.com
                Connection: keep-alive
                sec-ch-ua-platform: "Windows"
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                Cookie: __cf_bm=Oii2A2YnydETN.vLo7d68ahMlqILoRs_IMAgs8ZRVfY-1745245265-1.0.1.1-ZUzUvIjTR_MfVoSPwLhoQlwO.ymf1TtbllX.CasxICezoYZUH1ARrEj_3cRLtwU5pP0_q0xF3CjZET1NS.WtRr0.2i6dEFEwYwzj3rxq0Rg; _cfuvid=v7jO7iJfwCHwvXRRju3P2LUwlaJzo56W8IGUuCSYx4Y-1745245265029-0.0.1.1-604800000
                2025-04-21 14:21:06 UTC839INHTTP/1.1 403 Forbidden
                Date: Mon, 21 Apr 2025 14:21:06 GMT
                Content-Type: application/xml; charset=UTF-8
                Content-Length: 298
                Connection: close
                x-guploader-uploadid: AAO2VwqcK9ywYqi4lryL1c5N7tkfaGqqGjw8g9mN54khE8mSvegcnMCWgoYNn7zE2rlGcrGwdV12rSc
                expires: Mon, 21 Apr 2025 14:21:06 GMT
                Cache-Control: private, max-age=0
                alt-svc: h3=":443"; ma=86400
                CF-Cache-Status: MISS
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BBuU6EcO%2BIvQuhtFMql85QLQFhDEuSuSqVcna0GLQY5x1HDzK2%2FS0PR1dNyRg4IrRnuKJblhscAnuO6dAgF0%2BNnxldJLxs7laOso%2FfnQe2XzsBC6iK7qcAPUKNpcAZAg6xHwJg%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
                Server: cloudflare
                CF-RAY: 933d869d0f0f2b9e-LAX
                2025-04-21 14:21:06 UTC298INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 27 31 2e 30 27 20 65 6e 63 6f 64 69 6e 67 3d 27 55 54 46 2d 38 27 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 64 65 6e 69 65 64 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 44 65 74 61 69 6c 73 3e 41 6e 6f 6e 79 6d 6f 75 73 20 63 61 6c 6c 65 72 20 64 6f 65 73 20 6e 6f 74 20 68 61 76 65 20 73 74 6f 72 61 67 65 2e 6f 62 6a 65 63 74 73 2e 67 65 74 20 61 63 63 65 73 73 20 74 6f 20 74 68 65 20 47 6f 6f 67 6c 65 20 43 6c 6f 75 64 20 53 74 6f 72 61 67 65 20 6f 62 6a 65 63 74 2e 20 50 65 72 6d 69 73 73 69 6f 6e 20 27 73 74 6f 72 61 67 65 2e 6f 62 6a 65 63 74 73 2e 67 65 74 27 20 64 65 6e 69 65 64 20 6f 6e 20 72 65 73 6f 75 72
                Data Ascii: <?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message><Details>Anonymous caller does not have storage.objects.get access to the Google Cloud Storage object. Permission 'storage.objects.get' denied on resour


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44972835.190.80.14432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:21:05 UTC545OUTOPTIONS /report/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://cdn.discordapp.com
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-21 14:21:06 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: POST, OPTIONS
                access-control-allow-origin: *
                access-control-allow-headers: content-type, content-length
                date: Mon, 21 Apr 2025 14:21:05 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44973035.190.80.14432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:21:06 UTC520OUTPOST /report/v4?s=FhcuwRDX6iUPyu8d2RatFn2kUIgLatozU7UUpIyhTtRheUGQHMA5njaGaF12wldrpy3WvOFodf2rBdoB3UipvEj1dhIc8YqPr3LGocpQPRAjKxo15ANfvdRXbHOQF9F8on1wWA%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 552
                Content-Type: application/reports+json
                Origin: https://cdn.discordapp.com
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-21 14:21:06 UTC552OUTData Raw: 5b 7b 22 61 67 65 22 3a 38 37 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 38 31 31 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 36 32 2e 31 35 39 2e 31 32 39 2e 32 33 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 64 69 73 63 6f 72 64 61 70
                Data Ascii: [{"age":87,"body":{"elapsed_time":811,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"162.159.129.233","status_code":404,"type":"http.error"},"type":"network-error","url":"https://cdn.discordap
                2025-04-21 14:21:06 UTC214INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-allow-origin: *
                vary: Origin
                date: Mon, 21 Apr 2025 14:21:06 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.44974235.190.80.14432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:22:05 UTC555OUTOPTIONS /report/v4?s=%2BBuU6EcO%2BIvQuhtFMql85QLQFhDEuSuSqVcna0GLQY5x1HDzK2%2FS0PR1dNyRg4IrRnuKJblhscAnuO6dAgF0%2BNnxldJLxs7laOso%2FfnQe2XzsBC6iK7qcAPUKNpcAZAg6xHwJg%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://cdn.discordapp.com
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-21 14:22:05 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: POST, OPTIONS
                access-control-allow-origin: *
                access-control-allow-headers: content-type, content-length
                date: Mon, 21 Apr 2025 14:22:05 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.44974435.190.80.14432212C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-21 14:22:06 UTC530OUTPOST /report/v4?s=%2BBuU6EcO%2BIvQuhtFMql85QLQFhDEuSuSqVcna0GLQY5x1HDzK2%2FS0PR1dNyRg4IrRnuKJblhscAnuO6dAgF0%2BNnxldJLxs7laOso%2FfnQe2XzsBC6iK7qcAPUKNpcAZAg6xHwJg%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 593
                Content-Type: application/reports+json
                Origin: https://cdn.discordapp.com
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-21 14:22:06 UTC593OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 39 30 30 33 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 38 36 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 64 69 73 63 6f 72 64 61 70 70 2e 63 6f 6d 2f 61 74 74 61 63 68 6d 65 6e 74 73 2f 31 33 35 39 38 32 39 30 32 30 37 33 36 33 36 30 35 37 32 2f 31 33 36 30 31 30 35 32 34 37 32 31 32 35 36 38 36 30 37 2f 52 46 51 31 31 39 30 30 31 37 35 39 34 2e 6a 73 3f 65 78 3d 36 37 66 39 65 38 33 38 26 69 73 3d 36 37 66 38 39 36 62 38 26 68 6d 3d 36 33 32 39 39 36 65 64 62 38 34 64 33 62 35 39 30 64 64 66
                Data Ascii: [{"age":59003,"body":{"elapsed_time":862,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddf
                2025-04-21 14:22:06 UTC214INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-allow-origin: *
                vary: Origin
                date: Mon, 21 Apr 2025 14:22:05 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:1
                Start time:10:20:53
                Start date:21/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:10:20:57
                Start date:21/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1908,i,10654103830872755967,2167236336096847200,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2080 /prefetch:3
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:4
                Start time:10:21:03
                Start date:21/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cdn.discordapp.com/attachments/1359829020736360572/1360105247212568607/RFQ1190017594.js?ex=67f9e838&is=67f896b8&hm=632996edb84d3b590ddffa853bf43b9c3bc0e321c37f5bc842a4c7621ae73d8a&"
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly