Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092

Overview

General Information

Sample URL:https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwN
Analysis ID:1501422
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files inside the system directory

Classification

  • System is w10x64
  • chrome.exe (PID: 1744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2260 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6524833550617799408,17615955068735069700,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6436 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • mspaint.exe (PID: 6696 cmdline: mspaint.exe "C:\Users\user\Desktop\" MD5: 986A191E95952C9E3FE6BE112FB92026)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900 HTTP/1.1Host: na01.safelinks.protection.outlook.com.url.protected-forms.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: na01.safelinks.protection.outlook.com.url.protected-forms.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: C:\Windows\SysWOW64\mspaint.exeFile created: C:\Windows\Debug\WIAJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeFile created: C:\Windows\Debug\WIA\wiatrace.logJump to behavior
Source: classification engineClassification label: clean0.win@18/6@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\a0ad94bc-da6f-47ea-b5e8-0646e3ddc0bd.tmpJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6524833550617799408,17615955068735069700,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900"
Source: unknownProcess created: C:\Windows\SysWOW64\mspaint.exe mspaint.exe "C:\Users\user\Desktop\"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6524833550617799408,17615955068735069700,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: mfc42u.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: winmm.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: uiribbon.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: efswrt.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: sti.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: wiatrace.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLLJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mspaint.exeProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
11
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Process Injection
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1501422 URL: https://na01.safelinks.prot... Startdate: 29/08/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 16 2->5         started        8 mspaint.exe 2 2->8         started        10 chrome.exe 2->10         started        dnsIp3 15 192.168.2.4, 138, 443, 49723 unknown unknown 5->15 17 239.255.255.250 unknown Reserved 5->17 12 chrome.exe 5->12         started        process4 dnsIp5 19 www.google.com 142.250.186.68, 443, 49739 GOOGLEUS United States 12->19 21 172.217.18.100, 443, 49750 GOOGLEUS United States 12->21 23 2 other IPs or domains 12->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=20925209000%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.26
truefalse
    unknown
    www.google.com
    142.250.186.68
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        landing.training.knowbe4.com
        3.209.192.238
        truefalse
          unknown
          na01.safelinks.protection.outlook.com.url.protected-forms.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.186.68
            www.google.comUnited States
            15169GOOGLEUSfalse
            3.209.192.238
            landing.training.knowbe4.comUnited States
            14618AMAZON-AESUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            172.217.18.100
            unknownUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1501422
            Start date and time:2024-08-29 22:02:14 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 55s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:10
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@18/6@6/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.250.186.174, 74.125.206.84, 34.104.35.123, 52.165.165.26, 217.20.57.26, 192.229.221.95, 20.166.126.56, 20.242.39.171, 142.250.185.131
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 1 x 1
            Category:dropped
            Size (bytes):43
            Entropy (8bit):2.7374910194847146
            Encrypted:false
            SSDEEP:3:CUnl/7yltxlHh/:/+/
            MD5:07FFF40B5DD495ACA2AC4E1C3FBC60AA
            SHA1:E8AC224BA9EE97E87670ED6F3A2F0128B7AF9FE4
            SHA-256:A065920DF8CC4016D67C3A464BE90099C9D28FFE7C9E6EE3A18F257EFC58CBD7
            SHA-512:49B8DAF1F5BA868BC8C6B224C787A75025CA36513EF8633D1D8F34E48EE0B578F466FCC104A7BED553404DDC5F9FAFF3FEF5F894B31CD57F32245E550FAD656A
            Malicious:false
            Reputation:low
            Preview:GIF89a.............!.......,...........D..;
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 1 x 1
            Category:dropped
            Size (bytes):43
            Entropy (8bit):2.7374910194847146
            Encrypted:false
            SSDEEP:3:CUnl/7yltxlHh/:/+/
            MD5:07FFF40B5DD495ACA2AC4E1C3FBC60AA
            SHA1:E8AC224BA9EE97E87670ED6F3A2F0128B7AF9FE4
            SHA-256:A065920DF8CC4016D67C3A464BE90099C9D28FFE7C9E6EE3A18F257EFC58CBD7
            SHA-512:49B8DAF1F5BA868BC8C6B224C787A75025CA36513EF8633D1D8F34E48EE0B578F466FCC104A7BED553404DDC5F9FAFF3FEF5F894B31CD57F32245E550FAD656A
            Malicious:false
            Reputation:low
            Preview:GIF89a.............!.......,...........D..;
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 1 x 1
            Category:dropped
            Size (bytes):43
            Entropy (8bit):2.7374910194847146
            Encrypted:false
            SSDEEP:3:CUnl/7yltxlHh/:/+/
            MD5:07FFF40B5DD495ACA2AC4E1C3FBC60AA
            SHA1:E8AC224BA9EE97E87670ED6F3A2F0128B7AF9FE4
            SHA-256:A065920DF8CC4016D67C3A464BE90099C9D28FFE7C9E6EE3A18F257EFC58CBD7
            SHA-512:49B8DAF1F5BA868BC8C6B224C787A75025CA36513EF8633D1D8F34E48EE0B578F466FCC104A7BED553404DDC5F9FAFF3FEF5F894B31CD57F32245E550FAD656A
            Malicious:false
            Reputation:low
            Preview:GIF89a.............!.......,...........D..;
            Process:C:\Windows\SysWOW64\mspaint.exe
            File Type:ASCII text, with CRLF, LF line terminators
            Category:dropped
            Size (bytes):1526
            Entropy (8bit):5.299753939979568
            Encrypted:false
            SSDEEP:24:0u0q8hGG1UYF02k9YXCSYF0qVMeF0kuqYeF0w3OYYF0HXd/bXE34npXd/TznDgNk:0uL6GGDSmXgSiSku8Sw3GS3RzE345RTv
            MD5:55C1592EFD7411DC088ABCB349B04A72
            SHA1:C2F2027089F8CC2AB0250D4024C099365278CFE6
            SHA-256:D5E98B09725CC0B9735C4DC283B4179648CA96C033CB5CC6124170E419A24AFA
            SHA-512:F4A560BD7440FD0C6BD53CD6C2AB3B8EC901F3D72F3A2BCEC42047374DB8744370DDE387F400852300B926673E5C8A46108A35C1AFBEB1946DCCD9C11B716F47
            Malicious:false
            Reputation:low
            Preview:..**************** Started trace for Module: [sti.dll] in Executable [mspaint.exe] ProcessID: [6696] at 2024/08/29 16:04:25:410 ****************..WIA: 6696.3396 15 0 0 [sti.dll] AsyncRPCEventTransport::OpenConnectionToServer, AsyncRPC Connection established to server..WIA: 6696.3396 15 0 0 [sti.dll] AsyncRPCEventTransport::OpenConnectionToServer, Got my context 03536A78 from server...WIA: 6696.3396 15 0 0 [sti.dll] WiaEventReceiver::Start, WiaEventReceiver Started.....WIA: 6696.6384 15 0 0 [sti.dll] AsyncRPCEventTransport::CloseNotificationChannel, Closing the async notification channel.....WIA: 6696.6384 15 0 0 [sti.dll] AsyncRPCEventTransport::OpenNotificationChannel, Opening the async notification channel.....WIA: 6696.3396 15 0 0 [sti.dll] AsyncRPCEventTransport::SendRegisterUnregisterInfo, Sent RPC Register/Unregister information...WIA: 6696.3396 15 0 0 [sti.dll] WiaEventReceiver::SendRegisterUnregisterInfo, Added new registration:..WIA: 6696.3396 15 0 0 [sti.dll] EventRegistratio
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 1 x 1
            Category:downloaded
            Size (bytes):43
            Entropy (8bit):2.7374910194847146
            Encrypted:false
            SSDEEP:3:CUnl/7yltxlHh/:/+/
            MD5:07FFF40B5DD495ACA2AC4E1C3FBC60AA
            SHA1:E8AC224BA9EE97E87670ED6F3A2F0128B7AF9FE4
            SHA-256:A065920DF8CC4016D67C3A464BE90099C9D28FFE7C9E6EE3A18F257EFC58CBD7
            SHA-512:49B8DAF1F5BA868BC8C6B224C787A75025CA36513EF8633D1D8F34E48EE0B578F466FCC104A7BED553404DDC5F9FAFF3FEF5F894B31CD57F32245E550FAD656A
            Malicious:false
            Reputation:low
            URL:https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900
            Preview:GIF89a.............!.......,...........D..;
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Aug 29, 2024 22:03:07.911108971 CEST49675443192.168.2.4173.222.162.32
            Aug 29, 2024 22:03:08.730056047 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730094910 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:08.730170012 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730396032 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730402946 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:08.730453968 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730659962 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730674982 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:08.730902910 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:08.730912924 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.422838926 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.423103094 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.423127890 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.423495054 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.423557043 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.424377918 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.424426079 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.424968004 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.425302029 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.425309896 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.425540924 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.425630093 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.425750971 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.425808907 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.425858974 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.425867081 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.426496983 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.426546097 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.426918983 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.426995039 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.475840092 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.475840092 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:09.475850105 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:03:09.522476912 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:10.675122976 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:10.675168991 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:10.675230026 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:10.675908089 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:10.675926924 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.003101110 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:11.003187895 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:11.003247976 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:11.006833076 CEST49735443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:11.006855011 CEST443497353.209.192.238192.168.2.4
            Aug 29, 2024 22:03:11.300105095 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:11.300159931 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:11.300224066 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:11.301888943 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:11.301909924 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:11.390065908 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.390352964 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:11.390384912 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.391308069 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.391379118 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:11.551531076 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:11.551744938 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.603357077 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:11.603383064 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:11.651498079 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:11.942761898 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:11.943094015 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:11.967320919 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:11.967338085 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:11.967580080 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.007364988 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.113185883 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.156508923 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.299793959 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.299866915 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.301343918 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.305118084 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.305145025 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.305159092 CEST49740443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.305165052 CEST44349740184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.359781981 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.359842062 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.361238956 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.361238956 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.361285925 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.996171951 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.996254921 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.999588013 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:12.999600887 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:12.999948978 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:13.001131058 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:13.044513941 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:13.187062025 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:13.187120914 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:13.187170029 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:13.187899113 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:13.187920094 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:13.187930107 CEST49741443192.168.2.4184.28.90.27
            Aug 29, 2024 22:03:13.187935114 CEST44349741184.28.90.27192.168.2.4
            Aug 29, 2024 22:03:21.818991899 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:21.819051027 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:21.819195986 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:23.076468945 CEST49739443192.168.2.4142.250.186.68
            Aug 29, 2024 22:03:23.076493979 CEST44349739142.250.186.68192.168.2.4
            Aug 29, 2024 22:03:54.488418102 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:03:54.488435030 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:04:04.122656107 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:04:04.122729063 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:04:04.122975111 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:04:05.072685003 CEST49736443192.168.2.43.209.192.238
            Aug 29, 2024 22:04:05.072707891 CEST443497363.209.192.238192.168.2.4
            Aug 29, 2024 22:04:11.054447889 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:11.054476023 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.054708004 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:11.054966927 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:11.054980040 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.703933954 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.704225063 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:11.704241037 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.704539061 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.704901934 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:11.704952002 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:11.756319046 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:15.413656950 CEST4972380192.168.2.4199.232.210.172
            Aug 29, 2024 22:04:15.413806915 CEST4972480192.168.2.4199.232.210.172
            Aug 29, 2024 22:04:15.419027090 CEST8049723199.232.210.172192.168.2.4
            Aug 29, 2024 22:04:15.419039011 CEST8049724199.232.210.172192.168.2.4
            Aug 29, 2024 22:04:15.419085026 CEST4972380192.168.2.4199.232.210.172
            Aug 29, 2024 22:04:15.419100046 CEST4972480192.168.2.4199.232.210.172
            Aug 29, 2024 22:04:21.606098890 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:21.606169939 CEST44349750172.217.18.100192.168.2.4
            Aug 29, 2024 22:04:21.606352091 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:23.071403027 CEST49750443192.168.2.4172.217.18.100
            Aug 29, 2024 22:04:23.071439981 CEST44349750172.217.18.100192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Aug 29, 2024 22:03:06.839595079 CEST53564151.1.1.1192.168.2.4
            Aug 29, 2024 22:03:06.870333910 CEST53565481.1.1.1192.168.2.4
            Aug 29, 2024 22:03:08.239650011 CEST53597701.1.1.1192.168.2.4
            Aug 29, 2024 22:03:08.630002975 CEST6386153192.168.2.41.1.1.1
            Aug 29, 2024 22:03:08.630143881 CEST6525253192.168.2.41.1.1.1
            Aug 29, 2024 22:03:08.726005077 CEST53638611.1.1.1192.168.2.4
            Aug 29, 2024 22:03:08.729310036 CEST53652521.1.1.1192.168.2.4
            Aug 29, 2024 22:03:10.660187960 CEST6141453192.168.2.41.1.1.1
            Aug 29, 2024 22:03:10.660536051 CEST5493053192.168.2.41.1.1.1
            Aug 29, 2024 22:03:10.667570114 CEST53549301.1.1.1192.168.2.4
            Aug 29, 2024 22:03:10.667608976 CEST53614141.1.1.1192.168.2.4
            Aug 29, 2024 22:03:25.171246052 CEST53607851.1.1.1192.168.2.4
            Aug 29, 2024 22:03:27.031492949 CEST138138192.168.2.4192.168.2.255
            Aug 29, 2024 22:03:43.920350075 CEST53550451.1.1.1192.168.2.4
            Aug 29, 2024 22:04:06.368995905 CEST53609761.1.1.1192.168.2.4
            Aug 29, 2024 22:04:06.560982943 CEST53544111.1.1.1192.168.2.4
            Aug 29, 2024 22:04:10.722100973 CEST6027853192.168.2.41.1.1.1
            Aug 29, 2024 22:04:10.722467899 CEST5483053192.168.2.41.1.1.1
            Aug 29, 2024 22:04:11.047894955 CEST53548301.1.1.1192.168.2.4
            Aug 29, 2024 22:04:11.047910929 CEST53602781.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Aug 29, 2024 22:03:08.630002975 CEST192.168.2.41.1.1.10xe67fStandard query (0)na01.safelinks.protection.outlook.com.url.protected-forms.comA (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.630143881 CEST192.168.2.41.1.1.10xeb09Standard query (0)na01.safelinks.protection.outlook.com.url.protected-forms.com65IN (0x0001)false
            Aug 29, 2024 22:03:10.660187960 CEST192.168.2.41.1.1.10x210eStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:10.660536051 CEST192.168.2.41.1.1.10x364bStandard query (0)www.google.com65IN (0x0001)false
            Aug 29, 2024 22:04:10.722100973 CEST192.168.2.41.1.1.10x459bStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Aug 29, 2024 22:04:10.722467899 CEST192.168.2.41.1.1.10xfaa8Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)na01.safelinks.protection.outlook.com.url.protected-forms.comlanding.training.knowbe4.comCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com3.209.192.238A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com3.213.1.152A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com3.215.126.49A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com34.236.53.60A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com44.207.186.138A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.726005077 CEST1.1.1.1192.168.2.40xe67fNo error (0)landing.training.knowbe4.com52.204.140.225A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:08.729310036 CEST1.1.1.1192.168.2.40xeb09No error (0)na01.safelinks.protection.outlook.com.url.protected-forms.comlanding.training.knowbe4.comCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:03:10.667570114 CEST1.1.1.1192.168.2.40x364bNo error (0)www.google.com65IN (0x0001)false
            Aug 29, 2024 22:03:10.667608976 CEST1.1.1.1192.168.2.40x210eNo error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.26A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.37A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.42A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.34A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.36A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.39A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.21A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.029716969 CEST1.1.1.1192.168.2.40x1c83No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.20A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:22.689929962 CEST1.1.1.1192.168.2.40x69f7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:03:22.689929962 CEST1.1.1.1192.168.2.40x69f7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:35.935374975 CEST1.1.1.1192.168.2.40x297cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:03:35.935374975 CEST1.1.1.1192.168.2.40x297cNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Aug 29, 2024 22:03:59.017452955 CEST1.1.1.1192.168.2.40x7ddbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:03:59.017452955 CEST1.1.1.1192.168.2.40x7ddbNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Aug 29, 2024 22:04:11.047894955 CEST1.1.1.1192.168.2.40xfaa8No error (0)www.google.com65IN (0x0001)false
            Aug 29, 2024 22:04:11.047910929 CEST1.1.1.1192.168.2.40x459bNo error (0)www.google.com172.217.18.100A (IP address)IN (0x0001)false
            Aug 29, 2024 22:04:19.468381882 CEST1.1.1.1192.168.2.40x6a1cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Aug 29, 2024 22:04:19.468381882 CEST1.1.1.1192.168.2.40x6a1cNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • na01.safelinks.protection.outlook.com.url.protected-forms.com
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.4497353.209.192.2384432260C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-08-29 20:03:09 UTC940OUTGET /Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900 HTTP/1.1
            Host: na01.safelinks.protection.outlook.com.url.protected-forms.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-08-29 20:03:10 UTC626INHTTP/1.1 200 OK
            Date: Thu, 29 Aug 2024 20:03:10 GMT
            Content-Type: image/gif
            Content-Length: 43
            Connection: close
            X-Frame-Options: SAMEORIGIN
            X-XSS-Protection: 0
            X-Content-Type-Options: nosniff
            X-Permitted-Cross-Domain-Policies: none
            Referrer-Policy: no-referrer-when-downgrade
            Content-Disposition: attachment
            Content-Transfer-Encoding: binary
            ETag: W/"a065920df8cc4016d67c3a464be90099"
            Cache-Control: max-age=0, private, must-revalidate
            Content-Security-Policy:
            X-Request-Id: 4d62c5b3-b985-407d-83c0-53de02ee628a
            X-Runtime: 1.059752
            Strict-Transport-Security: max-age=63113904; includeSubDomains; preload
            2024-08-29 20:03:10 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 f0 00 00 00 00 00 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
            Data Ascii: GIF89a!,D;


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449740184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-08-29 20:03:12 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-08-29 20:03:12 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=135221
            Date: Thu, 29 Aug 2024 20:03:12 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449741184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-08-29 20:03:12 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-08-29 20:03:13 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=135173
            Date: Thu, 29 Aug 2024 20:03:13 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-08-29 20:03:13 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to dive into process behavior distribution

            Click to jump to process

            Target ID:0
            Start time:16:03:02
            Start date:29/08/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:16:03:04
            Start date:29/08/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6524833550617799408,17615955068735069700,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:16:03:07
            Start date:29/08/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na01.safelinks.protection.outlook.com.url.protected-forms.com/Xdm4wZ0NrYU8rSjZMaU9MelRXNVo1VTZsRTJUVmwzWXliL2czQ2x0UjBqVDRVY1REWHdDYlZuY1ZxVlhSbXFteE5wK29Qd3VzbTI3dGt0U2V5L3djeFN5dGhFNm9FaXpwNjF5dWVPZWRxcENMcGQ4cHBrdnRyQT09LS1NM3hLNzlUWnpFbDhYS2JGLS1rODc1VzRKVWZ1UXpVY2lIVkdnbCtRPT0=?cid=2092520900"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:8
            Start time:16:04:24
            Start date:29/08/2024
            Path:C:\Windows\SysWOW64\mspaint.exe
            Wow64 process (32bit):true
            Commandline:mspaint.exe "C:\Users\user\Desktop\"
            Imagebase:0x7ff72bec0000
            File size:743'424 bytes
            MD5 hash:986A191E95952C9E3FE6BE112FB92026
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            No disassembly