Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096FzzmeY0TwKP_lLoSRO1ALDlxuPs0wb9J7P-04Nvq72vehgtQvm2ae-s4N7jdwX3cbgaNR5sm_YmOWvXX07-DrCU2CsVsnW7CNYmEvm

Overview

General Information

Sample URL:http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096Fz
Analysis ID:1522630
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6356 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1652,i,6090835143889241649,409201857259258202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096FzzmeY0TwKP_lLoSRO1ALDlxuPs0wb9J7P-04Nvq72vehgtQvm2ae-s4N7jdwX3cbgaNR5sm_YmOWvXX07-DrCU2CsVsnW7CNYmEvm62kp40rQziaMtWdO48yE3P&n=jt2iaFkee2RMzcRS0s_k1DZgKPZQqDTpNjkXDH5q7BYKpdiMVXwkcO9G-HiUGe3P3iUbTzVkOYExqUMdU7dDZw&r=HIcFJpaQDmgaBEPEgO7ak_3notrkSvxgxxz_ZDLXwjn8CR1bH1fIEvoEJrzn6ghR&s=27253a14b4e308d98803735f7d14c90706c09a034aa7045c1e169d37118534cd&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3D25394301TR8*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3D0171FB06502FE3115A63166894845D25__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c27NT9-DG$" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=W2EkAhbXgGEaSWu&MD=SvnFWOB3 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=W2EkAhbXgGEaSWu&MD=SvnFWOB3 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: classification engineClassification label: clean0.win@22/6@4/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1652,i,6090835143889241649,409201857259258202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096FzzmeY0TwKP_lLoSRO1ALDlxuPs0wb9J7P-04Nvq72vehgtQvm2ae-s4N7jdwX3cbgaNR5sm_YmOWvXX07-DrCU2CsVsnW7CNYmEvm62kp40rQziaMtWdO48yE3P&n=jt2iaFkee2RMzcRS0s_k1DZgKPZQqDTpNjkXDH5q7BYKpdiMVXwkcO9G-HiUGe3P3iUbTzVkOYExqUMdU7dDZw&r=HIcFJpaQDmgaBEPEgO7ak_3notrkSvxgxxz_ZDLXwjn8CR1bH1fIEvoEJrzn6ghR&s=27253a14b4e308d98803735f7d14c90706c09a034aa7045c1e169d37118534cd&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3D25394301TR8*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3D0171FB06502FE3115A63166894845D25__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c27NT9-DG$"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1652,i,6090835143889241649,409201857259258202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1522630 URL: http://https:/atpscan.globa... Startdate: 30/09/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 11 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.16, 137, 138, 443 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.185.132, 443, 49701, 49712 GOOGLEUS United States 10->17 19 google.com 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
google.com0%VirustotalBrowse
www.google.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.206
truefalseunknown
www.google.com
142.250.185.132
truefalseunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
239.255.255.250
unknownReserved
unknownunknownfalse
142.250.185.132
www.google.comUnited States
15169GOOGLEUSfalse
IP
192.168.2.16
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1522630
Start date and time:2024-09-30 13:54:23 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Sample URL:http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096FzzmeY0TwKP_lLoSRO1ALDlxuPs0wb9J7P-04Nvq72vehgtQvm2ae-s4N7jdwX3cbgaNR5sm_YmOWvXX07-DrCU2CsVsnW7CNYmEvm62kp40rQziaMtWdO48yE3P&n=jt2iaFkee2RMzcRS0s_k1DZgKPZQqDTpNjkXDH5q7BYKpdiMVXwkcO9G-HiUGe3P3iUbTzVkOYExqUMdU7dDZw&r=HIcFJpaQDmgaBEPEgO7ak_3notrkSvxgxxz_ZDLXwjn8CR1bH1fIEvoEJrzn6ghR&s=27253a14b4e308d98803735f7d14c90706c09a034aa7045c1e169d37118534cd&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3D25394301TR8*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3D0171FB06502FE3115A63166894845D25__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c27NT9-DG$
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:13
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:CLEAN
Classification:clean0.win@22/6@4/3
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 142.250.184.238, 173.194.76.84, 142.250.186.67, 34.104.35.123, 199.232.214.172, 172.217.16.195, 142.250.185.174
  • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
No context
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 10:54:51 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2673
Entropy (8bit):3.986195909556042
Encrypted:false
SSDEEP:48:83ddTFViHOidAKZdA1FehwiZUklqeh2y+3:8/rPZy
MD5:13F21623A1B4B30E744B3E1935754F64
SHA1:238FBCB4952774FDABB278F382FA84A07119C1F3
SHA-256:0F33D4624CB7D5BAFAC20CD36A8EDE90147AF92ED94AE730985E88D5E30D7605
SHA-512:BF2E30D60EC611CC6E91904BFFCBCCEE356AAC64D0E16DDA40D282D417C07D49C0483236434BBC19BEF0B1184C6562BDBEE85C4E720BCD6A752C2879834BA412
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,....Q.../...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 10:54:51 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2675
Entropy (8bit):4.004492472593786
Encrypted:false
SSDEEP:48:80ddTFViHOidAKZdA1seh/iZUkAQkqehJy+2:8Or59Q0y
MD5:FE938F3DEA6DBAC82156B06BEB49EEF8
SHA1:3C18DD279279106BB0058520D89E8838417D34B8
SHA-256:5348DB7C7188C8B203C52FCD61463722ABAFC7BD33B8EC70691ADA857D08A72E
SHA-512:36FA3E956163BD177D2DDCF244608F8DAEFFF6EC5F4C35E6A5A35D8EE1A53145243A22D3725954C50E7B52B9CFCF16C24C271EDD6E2A88984493B63402554F38
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,....8.../...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2689
Entropy (8bit):4.008701017092537
Encrypted:false
SSDEEP:48:86ddTFVAHOidAKZdA14meh7sFiZUkmgqeh7sny+BX:8UrXnVy
MD5:12072033F34CDF3F2AF18DB198DA83A0
SHA1:B2933256979926108487876B74346E2ED4290C39
SHA-256:516910A9E6B254646F3C24572D36ACEA249C35EC80F2D9E3C42EBC7E55A8B37A
SHA-512:D54B8C4CFFA035D528B2547B1C03A145136B231BEBBD459230A86891EE3A72D690480C9AFC59BF0371B9084654162B502E53EA49BB70DE083F5C61E670C2E6A1
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 10:54:51 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2677
Entropy (8bit):4.002972048566335
Encrypted:false
SSDEEP:48:8rddTFViHOidAKZdA1TehDiZUkwqeh9y+R:8Trqvy
MD5:C71536A5FE8B02EE877770E698E799C6
SHA1:DC598199EF70F145C8BFC064F963FB478F7B6A7D
SHA-256:DE17A446207A7F66AB09FF7F387A82C23A624FC2BAEC1083B5FDBB1BF3413102
SHA-512:3ACB4EEB50B5694694C4150CEF5A38A710DF787DFB8F7D60B871C36EE64A55D144C677630CFEA92826FE54E1982AEFEB29871370BC634110B84F649026DFC893
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......z./...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 10:54:51 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2677
Entropy (8bit):3.989423123891425
Encrypted:false
SSDEEP:48:8WddTFViHOidAKZdA1dehBiZUk1W1qehjy+C:8Qrq9Dy
MD5:B8B75E066E1135FA693BABEEC2001ADE
SHA1:0180BE839C7C4A827F2FF2F5D916ED0B092E3B13
SHA-256:56A013187F5B99082D6760AEAB36E64BE55D0A78D870ABC0B73E003E349E0E8D
SHA-512:4A7282B3B6E10427A16653B7754C285AD87BA89C1A52E2E3FA9EE42CDDC8D744900F60D5487F1F2006ECE6319058143221C22A023CBABB4473A66434D042C1B9
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,.....:../...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 10:54:51 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2679
Entropy (8bit):3.9981311077393773
Encrypted:false
SSDEEP:48:8VddTFViHOidAKZdA1duTeehOuTbbiZUk5OjqehOuTbVy+yT+:81rgTfTbxWOvTbVy7T
MD5:D0D4EE50E3F6D73D7561A452BB55B3AF
SHA1:A450BC22ED3D4FF67A6B2C4D93978A5B1B2E1229
SHA-256:4FEA214FFCC52DC4B36BDE32ED5E80D5A1D0F6BD62FEAA780069FD9F5BA80481
SHA-512:8C2205ED1819D8DE8FAFBC4BED553051FEE385660BC6EB52443D6CA5FECF234C111BE3616CDCF63497F7715A43874E77555D20F01C73BBAC69C9C456EBC6D4A5
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......p./...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.^....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.^....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.^....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.^..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.^...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........vRM......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
No static file info
TimestampSource PortDest PortSource IPDest IP
Sep 30, 2024 13:54:54.346491098 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.346554041 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:54.346642971 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.346864939 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.346898079 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:54.983871937 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:54.984189034 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.984220028 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:54.985872984 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:54.985960960 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.986943960 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:54.987063885 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:55.029654026 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:55.029681921 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:54:55.077697039 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:54:55.701154947 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:54:56.008649111 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:54:56.624322891 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:54:57.831696987 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:54:58.486166000 CEST4968980192.168.2.16192.229.211.108
Sep 30, 2024 13:55:00.235709906 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:55:01.904934883 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:01.904964924 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:01.905064106 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:01.906985044 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:01.907004118 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:01.918952942 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:01.918975115 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:01.919051886 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:01.919908047 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:01.919929028 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.558392048 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.558471918 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.563072920 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.563080072 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.563287973 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.596299887 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.596373081 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.599877119 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.599883080 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.600091934 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.608649015 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.642657042 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.655420065 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.665450096 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.707433939 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.868855953 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.868897915 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.868949890 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.869147062 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.869162083 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.869175911 CEST49708443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.869182110 CEST44349708184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.892203093 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892226934 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892235994 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892250061 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892275095 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892285109 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.892302036 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892329931 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.892364025 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.892745018 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892805099 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.892813921 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892919064 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.892966032 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.903402090 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.903429985 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.903501987 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.903917074 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:02.903927088 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:02.906579971 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.906590939 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:02.906634092 CEST49707443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:02.906640053 CEST4434970713.85.23.86192.168.2.16
Sep 30, 2024 13:55:03.541521072 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.541600943 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.542740107 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.542747021 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.542949915 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.543973923 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.591397047 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.819343090 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.819425106 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.819545031 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.820314884 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.820333958 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.820342064 CEST49709443192.168.2.16184.28.90.27
Sep 30, 2024 13:55:03.820347071 CEST44349709184.28.90.27192.168.2.16
Sep 30, 2024 13:55:03.868963957 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:04.171662092 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:04.772666931 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:05.044645071 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:55:05.364033937 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:55:05.364111900 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:55:05.364260912 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:05.748224020 CEST49701443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:05.748258114 CEST44349701142.250.185.132192.168.2.16
Sep 30, 2024 13:55:05.985657930 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:08.335104942 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:08.398685932 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:08.638758898 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:09.245685101 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:10.452744961 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:12.856700897 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:13.207806110 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:14.659686089 CEST49673443192.168.2.16204.79.197.203
Sep 30, 2024 13:55:17.670747995 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:22.807727098 CEST49678443192.168.2.1620.189.173.10
Sep 30, 2024 13:55:27.284713030 CEST4968080192.168.2.16192.229.211.108
Sep 30, 2024 13:55:39.338175058 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:39.338224888 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:39.338329077 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:39.338665962 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:39.338677883 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.019973040 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.020082951 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.021409035 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.021420956 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.021759987 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.023634911 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.067409992 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.288080931 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.288111925 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.288130999 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.288183928 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.288212061 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.288261890 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.289562941 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.289611101 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.289629936 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.289639950 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.289669991 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.289724112 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.289774895 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.291241884 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.291261911 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:40.291273117 CEST49710443192.168.2.1613.85.23.86
Sep 30, 2024 13:55:40.291277885 CEST4434971013.85.23.86192.168.2.16
Sep 30, 2024 13:55:54.401885033 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:54.401977062 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:54.402103901 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:54.402429104 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:54.402457952 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:55.043411970 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:55.043828011 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:55.043863058 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:55.044370890 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:55.044764996 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:55:55.044833899 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:55:55.088809013 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:04.951648951 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:56:04.951781988 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:56:04.951878071 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:05.746176958 CEST49712443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:05.746237993 CEST44349712142.250.185.132192.168.2.16
Sep 30, 2024 13:56:54.466051102 CEST49714443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:54.466100931 CEST44349714142.250.185.132192.168.2.16
Sep 30, 2024 13:56:54.466176987 CEST49714443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:54.466487885 CEST49714443192.168.2.16142.250.185.132
Sep 30, 2024 13:56:54.466500998 CEST44349714142.250.185.132192.168.2.16
Sep 30, 2024 13:56:55.299694061 CEST44349714142.250.185.132192.168.2.16
Sep 30, 2024 13:56:55.354926109 CEST49714443192.168.2.16142.250.185.132
TimestampSource PortDest PortSource IPDest IP
Sep 30, 2024 13:54:49.530489922 CEST53528971.1.1.1192.168.2.16
Sep 30, 2024 13:54:49.534687042 CEST53527641.1.1.1192.168.2.16
Sep 30, 2024 13:54:50.429416895 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:54:50.582496881 CEST53638111.1.1.1192.168.2.16
Sep 30, 2024 13:54:51.186779022 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:54:51.948755026 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:54:52.735919952 CEST5951753192.168.2.168.8.8.8
Sep 30, 2024 13:54:52.736335039 CEST6362253192.168.2.161.1.1.1
Sep 30, 2024 13:54:52.742906094 CEST53595178.8.8.8192.168.2.16
Sep 30, 2024 13:54:52.743251085 CEST53636221.1.1.1192.168.2.16
Sep 30, 2024 13:54:53.781111002 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:54:54.336888075 CEST5401353192.168.2.161.1.1.1
Sep 30, 2024 13:54:54.337099075 CEST5740953192.168.2.161.1.1.1
Sep 30, 2024 13:54:54.344379902 CEST53540131.1.1.1192.168.2.16
Sep 30, 2024 13:54:54.345532894 CEST53574091.1.1.1192.168.2.16
Sep 30, 2024 13:54:54.533704996 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:54:55.284742117 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:01.055316925 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:01.815730095 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:02.579725027 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:07.640180111 CEST53570511.1.1.1192.168.2.16
Sep 30, 2024 13:55:26.448030949 CEST53626161.1.1.1192.168.2.16
Sep 30, 2024 13:55:33.358444929 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:34.116810083 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:34.881947041 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:55:49.329721928 CEST53501871.1.1.1192.168.2.16
Sep 30, 2024 13:55:49.481770039 CEST53626831.1.1.1192.168.2.16
Sep 30, 2024 13:56:00.034897089 CEST138138192.168.2.16192.168.2.255
Sep 30, 2024 13:56:18.212214947 CEST53632701.1.1.1192.168.2.16
Sep 30, 2024 13:56:35.653326988 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:56:36.415051937 CEST137137192.168.2.16192.168.2.255
Sep 30, 2024 13:56:37.167012930 CEST137137192.168.2.16192.168.2.255
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Sep 30, 2024 13:54:52.735919952 CEST192.168.2.168.8.8.80x8bdeStandard query (0)google.comA (IP address)IN (0x0001)false
Sep 30, 2024 13:54:52.736335039 CEST192.168.2.161.1.1.10xeb4Standard query (0)google.comA (IP address)IN (0x0001)false
Sep 30, 2024 13:54:54.336888075 CEST192.168.2.161.1.1.10x94eStandard query (0)www.google.comA (IP address)IN (0x0001)false
Sep 30, 2024 13:54:54.337099075 CEST192.168.2.161.1.1.10x3fe4Standard query (0)www.google.com65IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Sep 30, 2024 13:54:52.742906094 CEST8.8.8.8192.168.2.160x8bdeNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
Sep 30, 2024 13:54:52.743251085 CEST1.1.1.1192.168.2.160xeb4No error (0)google.com216.58.206.46A (IP address)IN (0x0001)false
Sep 30, 2024 13:54:54.344379902 CEST1.1.1.1192.168.2.160x94eNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
Sep 30, 2024 13:54:54.345532894 CEST1.1.1.1192.168.2.160x3fe4No error (0)www.google.com65IN (0x0001)false
  • slscr.update.microsoft.com
  • fs.microsoft.com
Session IDSource IPSource PortDestination IPDestination PortPIDProcess
0192.168.2.1649708184.28.90.27443
TimestampBytes transferredDirectionData
2024-09-30 11:55:02 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.8
Host: fs.microsoft.com
2024-09-30 11:55:02 UTC466INHTTP/1.1 200 OK
Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
Content-Type: application/octet-stream
ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
Last-Modified: Tue, 16 May 2017 22:58:00 GMT
Server: ECAcc (lpl/EF67)
X-CID: 11
X-Ms-ApiVersion: Distribute 1.2
X-Ms-Region: prod-neu-z1
Cache-Control: public, max-age=17407
Date: Mon, 30 Sep 2024 11:55:02 GMT
Connection: close
X-CID: 2


Session IDSource IPSource PortDestination IPDestination PortPIDProcess
1192.168.2.164970713.85.23.86443
TimestampBytes transferredDirectionData
2024-09-30 11:55:02 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=W2EkAhbXgGEaSWu&MD=SvnFWOB3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
Host: slscr.update.microsoft.com
2024-09-30 11:55:02 UTC560INHTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: application/octet-stream
Expires: -1
Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
MS-CorrelationId: fc6fb970-6118-48e1-bf05-0d56bc111d78
MS-RequestId: 662722aa-77ef-4fb7-b950-4b8119966a93
MS-CV: vX3quaygIU2hM08Y.0
X-Microsoft-SLSClientCache: 2880
Content-Disposition: attachment; filename=environment.cab
X-Content-Type-Options: nosniff
Date: Mon, 30 Sep 2024 11:55:01 GMT
Connection: close
Content-Length: 24490
2024-09-30 11:55:02 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
2024-09-30 11:55:02 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


Session IDSource IPSource PortDestination IPDestination PortPIDProcess
2192.168.2.1649709184.28.90.27443
TimestampBytes transferredDirectionData
2024-09-30 11:55:03 UTC239OUTGET /fs/windows/config.json HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
Range: bytes=0-2147483646
User-Agent: Microsoft BITS/7.8
Host: fs.microsoft.com
2024-09-30 11:55:03 UTC514INHTTP/1.1 200 OK
ApiVersion: Distribute 1.1
Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
Content-Type: application/octet-stream
ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
Last-Modified: Tue, 16 May 2017 22:58:00 GMT
Server: ECAcc (lpl/EF06)
X-CID: 11
X-Ms-ApiVersion: Distribute 1.2
X-Ms-Region: prod-weu-z1
Cache-Control: public, max-age=25923
Date: Mon, 30 Sep 2024 11:55:03 GMT
Content-Length: 55
Connection: close
X-CID: 2
2024-09-30 11:55:03 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


Session IDSource IPSource PortDestination IPDestination PortPIDProcess
3192.168.2.164971013.85.23.86443
TimestampBytes transferredDirectionData
2024-09-30 11:55:40 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=W2EkAhbXgGEaSWu&MD=SvnFWOB3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
Host: slscr.update.microsoft.com
2024-09-30 11:55:40 UTC560INHTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: application/octet-stream
Expires: -1
Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
MS-CorrelationId: 7a85ee19-5edc-49a8-b3be-c43b1fe231a0
MS-RequestId: 638a2d13-757f-4766-aaba-caa0d0f3eeda
MS-CV: lFEljvJo0UKC1AfE.0
X-Microsoft-SLSClientCache: 1440
Content-Disposition: attachment; filename=environment.cab
X-Content-Type-Options: nosniff
Date: Mon, 30 Sep 2024 11:55:40 GMT
Connection: close
Content-Length: 30005
2024-09-30 11:55:40 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
2024-09-30 11:55:40 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:07:54:48
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Imagebase:0x7ff7f9810000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:1
Start time:07:54:48
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1652,i,6090835143889241649,409201857259258202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Imagebase:0x7ff7f9810000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:07:54:49
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=HxUeIGqTQEqvwrU8p1N89GE3yJlZecpNcGjfW6U6YzYSjU_9OiLEcgg647uzUCOz&f=lCjmWZaU_lXGo-uD-VMCm8CTm9juwffvjLZZjV_sHlLrHh6gMvhc-HPIU6ctVgjB&i=&k=raoI&m=z096FzzmeY0TwKP_lLoSRO1ALDlxuPs0wb9J7P-04Nvq72vehgtQvm2ae-s4N7jdwX3cbgaNR5sm_YmOWvXX07-DrCU2CsVsnW7CNYmEvm62kp40rQziaMtWdO48yE3P&n=jt2iaFkee2RMzcRS0s_k1DZgKPZQqDTpNjkXDH5q7BYKpdiMVXwkcO9G-HiUGe3P3iUbTzVkOYExqUMdU7dDZw&r=HIcFJpaQDmgaBEPEgO7ak_3notrkSvxgxxz_ZDLXwjn8CR1bH1fIEvoEJrzn6ghR&s=27253a14b4e308d98803735f7d14c90706c09a034aa7045c1e169d37118534cd&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3D25394301TR8*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3D0171FB06502FE3115A63166894845D25__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c27NT9-DG$"
Imagebase:0x7ff7f9810000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly