Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://194.195.93.132

Overview

General Information

Sample URL:http://194.195.93.132
Analysis ID:1501905
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 2136 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,6162531321584950757,16845309906352622875,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://194.195.93.132" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: unknownTCP traffic detected without corresponding DNS query: 194.195.93.132
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 194.195.93.132Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 194.195.93.132Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 194.195.93.132Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1725034386789&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: classification engineClassification label: unknown1.win@18/6@2/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,6162531321584950757,16845309906352622875,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://194.195.93.132"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,6162531321584950757,16845309906352622875,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://194.195.93.1320%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://194.195.93.132/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.132
truefalse
    unknown
    fp2e7a.wpc.phicdn.net
    192.229.221.95
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://194.195.93.132/false
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      194.195.93.132
      unknownGermany
      6659NEXINTO-DEfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.186.132
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.5
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1501905
      Start date and time:2024-08-30 18:12:31 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 33s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://194.195.93.132
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:UNKNOWN
      Classification:unknown1.win@18/6@2/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.181.227, 172.217.16.142, 74.125.71.84, 34.104.35.123, 20.114.59.183, 93.184.221.240, 192.229.221.95, 13.85.23.206, 20.166.126.56
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      • VT rate limit hit for: http://194.195.93.132
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 15:13:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.9882766947287798
      Encrypted:false
      SSDEEP:48:8hdXTP3MH3idAKZdA19ehwiZUklqehhy+3:8TLMiy
      MD5:37B00E7EC09A35169003168518DBB74F
      SHA1:114DD13FD6925C94EB58B04A63B0821C4B4BEF55
      SHA-256:914CA90380464DC1AC3B44019A7B95073FA0ACB2AE4DB76A935A23716AE71E75
      SHA-512:57EAE971E89F1D4340E9F36FF20C1C752D86BCA4A660D511AAA58E0C739488A1FCB641CF562A82F04697E99BFD11A7D87074E24097521322F6A28A8BCBFA287B
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,.....j......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 15:13:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):4.003796976673792
      Encrypted:false
      SSDEEP:48:8BdXTP3MH3idAKZdA1weh/iZUkAQkqehSy+2:8zL+9Q/y
      MD5:AD2E92D72C7D32FCB0E77C7AC3B37AB6
      SHA1:D75A5108BB0ED7E0CB3A435D2098C633C2B1636D
      SHA-256:F24C9ACDB455109D9CF2805DCB7EA9698E2208882F79527CAACDB55AABF662A0
      SHA-512:1C93196CBB52D0FAAB80A6D018444A3C956D4670B393627AEB3D83069BC72D3D47EB6789C1B09A3AE113F33B6261E3B7386B2F5F745440AC1E16BEE3456741AB
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....G#......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2693
      Entropy (8bit):4.012857763155643
      Encrypted:false
      SSDEEP:48:8xgdXTP3sH3idAKZdA14tseh7sFiZUkmgqeh7sgy+BX:8xkLmnmy
      MD5:D18E5E37ACF8FDA0D908BC216F1CBBC6
      SHA1:F8B871A995293163171437CA3962F33236E3D913
      SHA-256:C94455C2CA73056628048FB69B5EC5C3E671E7885C14CF8DE31F681AD41E3C7A
      SHA-512:D03B8B9012F49D96380BF20A32E12FB6050B2CD8186B73606D887ED977AFCF190294562FB89E867B21DB9863F94F4923E6565DA80E99EA8E37352DE68A660E6F
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 15:13:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):4.0025610791242485
      Encrypted:false
      SSDEEP:48:85dXTP3MH3idAKZdA1vehDiZUkwqehuy+R:8LLloy
      MD5:A690135A9F8AF5DAEF72E5FFEB0B5B7A
      SHA1:E1A0A0DC168E8DE55CA1179AE38E8D3638416D61
      SHA-256:9678486682C228705FF24CA5418AB4AC9AB3AAF6372C310D5FC5504EE4B2E19D
      SHA-512:F688055FC825B58A112D52F4BE517B27AEC21793B927B3C385BC4D7886AE42EF8114E89FCC0342FD2745700AAE31342F31E14C3F58A5B5A94BAA011268B3F543
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....>.......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 15:13:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.991711986060742
      Encrypted:false
      SSDEEP:48:8sdXTP3MH3idAKZdA1hehBiZUk1W1qehEy+C:8YL19ky
      MD5:1D8BFA1568CAC2F6909168B9695E9023
      SHA1:635E10F5D29F679E8DB5D34EBC9E09FC68557F28
      SHA-256:D687E4457E275D054DC801DC38762DA26005984DA227CACB983DAB1F216B1FDC
      SHA-512:634DAD1834ED52843F48D434C8986BB2EFF1A5142AAC22C6AC9FD12406DB68B93AB32381476BD30C7D23EB9CD9610E29CDE7F0818E23C3FA1BB8B2C4EAB88E9A
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....D<......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 15:13:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2683
      Entropy (8bit):4.001939638873835
      Encrypted:false
      SSDEEP:48:8fdXTP3MH3idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbmy+yT+:8RLJT/TbxWOvTbmy7T
      MD5:D9448F8721F30EACE1C8F686ED3C8581
      SHA1:A04DFE08FDA893CE5AFEC4848F56F12782F0CE44
      SHA-256:FE1B6BAA6D791B38011840221E04EEEFA7E0C199792A262CFC81478637CC80A1
      SHA-512:D8B3F0A2B74E0E525F71D1665138BC7525CF365AEB7D1AFFC63519A5CD2BDD8EE1758DEDA49AC5D86E66BD3B2B5068DCBFE96ADB6C1C3B8410D95860DEEC2F56
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....}0......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............DB.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Aug 30, 2024 18:13:16.893495083 CEST49674443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:17.002886057 CEST49675443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:17.190373898 CEST49673443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:25.751473904 CEST4970980192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:25.751705885 CEST4971080192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:25.756953955 CEST8049709194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:25.757026911 CEST4970980192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:25.757504940 CEST8049710194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:25.757559061 CEST4971080192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:25.759385109 CEST4970980192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:25.764233112 CEST8049709194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:26.494548082 CEST49674443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:26.613645077 CEST49675443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:26.805486917 CEST49673443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:28.081496000 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.081537962 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.081615925 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.081876993 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.081891060 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.307955027 CEST4434970323.1.237.91192.168.2.5
      Aug 30, 2024 18:13:28.308105946 CEST49703443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:28.716417074 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.758667946 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.817444086 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.817468882 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.818644047 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.818728924 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.851037025 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.851155043 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.899538994 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:28.899565935 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:28.948333979 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:29.197755098 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:29.197798967 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:29.197925091 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:29.200958967 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:29.200974941 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:29.853483915 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:29.853579998 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:29.869194031 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:29.869211912 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:29.869446039 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:29.915872097 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.029999018 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.076504946 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.214569092 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.214745045 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.214788914 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.214982033 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.215006113 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.215018988 CEST49714443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.215029001 CEST44349714184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.258780956 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.258810997 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.259037971 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.260201931 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.260215998 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.923361063 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.923433065 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.924969912 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.924989939 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.925231934 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:30.926386118 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:30.972500086 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:31.205125093 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:31.205195904 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:31.205440044 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:31.208178043 CEST49715443192.168.2.5184.28.90.27
      Aug 30, 2024 18:13:31.208204031 CEST44349715184.28.90.27192.168.2.5
      Aug 30, 2024 18:13:38.616127014 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:38.616194010 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:38.616309881 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:39.431118965 CEST49703443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:39.431197882 CEST49703443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:39.431891918 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:39.431929111 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:39.432079077 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:39.432410955 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:39.432425976 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:39.436068058 CEST4434970323.1.237.91192.168.2.5
      Aug 30, 2024 18:13:39.436110973 CEST4434970323.1.237.91192.168.2.5
      Aug 30, 2024 18:13:39.830008984 CEST49713443192.168.2.5142.250.186.132
      Aug 30, 2024 18:13:39.830038071 CEST44349713142.250.186.132192.168.2.5
      Aug 30, 2024 18:13:40.025727034 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.025796890 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.483181000 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.483203888 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.483622074 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.483701944 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.491343975 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.491379023 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.494055986 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.494062901 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.794384956 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.794450998 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.794632912 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.794692039 CEST4434972123.1.237.91192.168.2.5
      Aug 30, 2024 18:13:40.794717073 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:40.794747114 CEST49721443192.168.2.523.1.237.91
      Aug 30, 2024 18:13:47.113442898 CEST8049710194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:47.113516092 CEST4971080192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.148394108 CEST8049709194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:47.148461103 CEST4970980192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.148690939 CEST4970980192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.149581909 CEST4971080192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.155670881 CEST4972480192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.158917904 CEST8049709194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:47.158926964 CEST8049710194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:47.160496950 CEST8049724194.195.93.132192.168.2.5
      Aug 30, 2024 18:13:47.160576105 CEST4972480192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.161082983 CEST4972480192.168.2.5194.195.93.132
      Aug 30, 2024 18:13:47.165880919 CEST8049724194.195.93.132192.168.2.5
      Aug 30, 2024 18:14:08.555165052 CEST8049724194.195.93.132192.168.2.5
      Aug 30, 2024 18:14:08.555279970 CEST4972480192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:08.557188988 CEST4972480192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:08.561975002 CEST8049724194.195.93.132192.168.2.5
      Aug 30, 2024 18:14:09.637172937 CEST4972580192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:09.642060041 CEST8049725194.195.93.132192.168.2.5
      Aug 30, 2024 18:14:09.642159939 CEST4972580192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:09.664000988 CEST4972680192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:09.665364981 CEST4972580192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:09.668817997 CEST8049726194.195.93.132192.168.2.5
      Aug 30, 2024 18:14:09.668893099 CEST4972680192.168.2.5194.195.93.132
      Aug 30, 2024 18:14:09.670149088 CEST8049725194.195.93.132192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Aug 30, 2024 18:13:23.583513975 CEST53523771.1.1.1192.168.2.5
      Aug 30, 2024 18:13:23.648385048 CEST53502991.1.1.1192.168.2.5
      Aug 30, 2024 18:13:24.709181070 CEST53633201.1.1.1192.168.2.5
      Aug 30, 2024 18:13:28.016554117 CEST5105353192.168.2.51.1.1.1
      Aug 30, 2024 18:13:28.016746998 CEST5078353192.168.2.51.1.1.1
      Aug 30, 2024 18:13:28.023319006 CEST53510531.1.1.1192.168.2.5
      Aug 30, 2024 18:13:28.023705006 CEST53507831.1.1.1192.168.2.5
      Aug 30, 2024 18:13:41.689332962 CEST53576771.1.1.1192.168.2.5
      Aug 30, 2024 18:14:00.894496918 CEST53499871.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Aug 30, 2024 18:13:28.016554117 CEST192.168.2.51.1.1.10xfc4cStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Aug 30, 2024 18:13:28.016746998 CEST192.168.2.51.1.1.10xc44bStandard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Aug 30, 2024 18:13:28.023319006 CEST1.1.1.1192.168.2.50xfc4cNo error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
      Aug 30, 2024 18:13:28.023705006 CEST1.1.1.1192.168.2.50xc44bNo error (0)www.google.com65IN (0x0001)false
      Aug 30, 2024 18:13:38.760590076 CEST1.1.1.1192.168.2.50x9bdeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Aug 30, 2024 18:13:38.760590076 CEST1.1.1.1192.168.2.50x9bdeNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Aug 30, 2024 18:13:52.838207006 CEST1.1.1.1192.168.2.50xc235No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Aug 30, 2024 18:13:52.838207006 CEST1.1.1.1192.168.2.50xc235No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Aug 30, 2024 18:14:16.078958988 CEST1.1.1.1192.168.2.50xcd62No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Aug 30, 2024 18:14:16.078958988 CEST1.1.1.1192.168.2.50xcd62No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • https:
        • www.bing.com
      • 194.195.93.132
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.549709194.195.93.132802360C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Aug 30, 2024 18:13:25.759385109 CEST429OUTGET / HTTP/1.1
      Host: 194.195.93.132
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.549724194.195.93.132802360C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Aug 30, 2024 18:13:47.161082983 CEST429OUTGET / HTTP/1.1
      Host: 194.195.93.132
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.549725194.195.93.132802360C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Aug 30, 2024 18:14:09.665364981 CEST455OUTGET / HTTP/1.1
      Host: 194.195.93.132
      Connection: keep-alive
      Cache-Control: max-age=0
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.549714184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-08-30 16:13:30 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-08-30 16:13:30 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=62603
      Date: Fri, 30 Aug 2024 16:13:30 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.549715184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-08-30 16:13:30 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-08-30 16:13:31 UTC514INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=62555
      Date: Fri, 30 Aug 2024 16:13:31 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-08-30 16:13:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Session IDSource IPSource PortDestination IPDestination Port
      2192.168.2.54972123.1.237.91443
      TimestampBytes transferredDirectionData
      2024-08-30 16:13:40 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
      Origin: https://www.bing.com
      Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
      Accept: */*
      Accept-Language: en-CH
      Content-type: text/xml
      X-Agent-DeviceId: 01000A410900D492
      X-BM-CBT: 1696428841
      X-BM-DateFormat: dd/MM/yyyy
      X-BM-DeviceDimensions: 784x984
      X-BM-DeviceDimensionsLogical: 784x984
      X-BM-DeviceScale: 100
      X-BM-DTZ: 120
      X-BM-Market: CH
      X-BM-Theme: 000000;0078d7
      X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
      X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
      X-Device-isOptin: false
      X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
      X-Device-OSSKU: 48
      X-Device-Touch: false
      X-DeviceID: 01000A410900D492
      X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
      X-MSEdge-ExternalExpType: JointCoord
      X-PositionerType: Desktop
      X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
      X-Search-CortanaAvailableCapabilities: None
      X-Search-SafeSearch: Moderate
      X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
      X-UserAgeClass: Unknown
      Accept-Encoding: gzip, deflate, br
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
      Host: www.bing.com
      Content-Length: 2484
      Connection: Keep-Alive
      Cache-Control: no-cache
      Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1725034386789&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
      2024-08-30 16:13:40 UTC1OUTData Raw: 3c
      Data Ascii: <
      2024-08-30 16:13:40 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
      Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
      2024-08-30 16:13:40 UTC476INHTTP/1.1 204 No Content
      Access-Control-Allow-Origin: *
      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
      X-MSEdge-Ref: Ref A: 7C391AE9B409476B8C1DF6317BB9389D Ref B: LAXEDGE1906 Ref C: 2024-08-30T16:13:40Z
      Date: Fri, 30 Aug 2024 16:13:40 GMT
      Connection: close
      Alt-Svc: h3=":443"; ma=93600
      X-CDN-TraceID: 0.5ced0117.1725034420.2b901715


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:12:13:18
      Start date:30/08/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:12:13:22
      Start date:30/08/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,6162531321584950757,16845309906352622875,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:12:13:24
      Start date:30/08/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://194.195.93.132"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly