Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVK

Overview

General Information

Sample URL:http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt
Analysis ID:1522642
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6936 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6296 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2008,i,17072862143821464706,10439542806910227767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6024 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVKfNDkV8Z7LfIWxRCCZdooZC&n=ZEhYBDFv208HJKEkNw5PqFObkm08aq7YeFB_fsGRbHtm2gx4mSx3JSwYkGZ1WU18bxwJPkfxXGKYv_KHdz1U8g&r=jfqeskceaKp8lH_i6JGe3T3xyBa6G7cbOCXOc4EPK3XMqLBHJqWBZEP0B9-qih8i&s=7226c2d05f1feec1a62ae2af2728e02cdefac54ea37a3a7665785b4a5864d360&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3DB175D31C2AE80D9A572ED101DA29F438*26file_type*3Dzip__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c26FxoQqF$%3E" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • rundll32.exe (PID: 7876 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • WINWORD.EXE (PID: 8004 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Downloads\BJZFPPWAPT.docx" /o "" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
  • Music.UI.exe (PID: 6448 cmdline: "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca MD5: F963F75C0AD152437E10D656A00793A3)
  • cleanup
No configs have been found
No yara matches
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, ProcessId: 8004, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.23:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.16:49722 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=WWfY4y+vlesLmSE&MD=E3oZYt79 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=WWfY4y+vlesLmSE&MD=E3oZYt79 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: settings-ssl.xboxlive.com
Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 4762Host: login.live.com
Source: Music.UI.exe, 00000013.00000002.2205521947.000001DF6B2A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microsoft.co
Source: Music.UI.exe, 00000013.00000002.2205521947.000001DF6B2A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.microsofi/crl/products/MicCerTruLisPCA_2009-04-02.crl
Source: Music.UI.exe, 00000013.00000002.2203205444.000001DF69F65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
Source: Music.UI.exe, 00000013.00000002.2205377542.000001DF6B261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOS
Source: Music.UI.exe, 00000013.00000002.2200317493.000001DF691A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: Music.UI.exe, 00000013.00000002.2200317493.000001DF691A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
Source: Music.UI.exe, 00000013.00000002.2202171408.000001DF69E00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local
Source: Music.UI.exe, 00000013.00000002.2202171408.000001DF69E00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
Source: Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net
Source: Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/tch
Source: Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.netCDC98
Source: Music.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpg
Source: Music.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpg
Source: Music.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com
Source: Music.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/
Source: Music.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xml
Source: Music.UI.exe, 00000013.00000002.2198770639.000001DF68CC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wns.windows.com/
Source: Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
Source: Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/OLE6543578F09ED7815F14EC5F7D14B
Source: Music.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.comngpng1003
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.23:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: classification engineClassification label: clean2.win@32/34@7/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{66DD95CB-B5E1-48D5-B55B-305EFDD54DF6} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2008,i,17072862143821464706,10439542806910227767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVKfNDkV8Z7LfIWxRCCZdooZC&n=ZEhYBDFv208HJKEkNw5PqFObkm08aq7YeFB_fsGRbHtm2gx4mSx3JSwYkGZ1WU18bxwJPkfxXGKYv_KHdz1U8g&r=jfqeskceaKp8lH_i6JGe3T3xyBa6G7cbOCXOc4EPK3XMqLBHJqWBZEP0B9-qih8i&s=7226c2d05f1feec1a62ae2af2728e02cdefac54ea37a3a7665785b4a5864d360&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3DB175D31C2AE80D9A572ED101DA29F438*26file_type*3Dzip__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c26FxoQqF$%3E"
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Downloads\BJZFPPWAPT.docx" /o ""
Source: unknownProcess created: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2008,i,17072862143821464706,10439542806910227767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sharedui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: concrt140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: esent.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.lockscreen.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wincorlib.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: lockappbroker.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.phone.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.mediaplayer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfplat.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rtworkq.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.mediacontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mmdevapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devobj.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmediaengine.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: audioses.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.devices.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.proxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: comppkgsup.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.web.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wpnapps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: photometadatahandler.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.devices.enumeration.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devdispitemprovider.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ddores.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: defaultdevicemanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wuceffects.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.backgroundtransfer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: systemeventsbrokerclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: biwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vaultcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: microsoftaccountwamextension.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: appcontracts.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: usermgrproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cdprt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cdp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmp4srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msamrnbsource.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfasfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfds.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msflacdecoder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: avrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmpeg2srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmkvsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfnetsrc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfnetcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gnsdk_fp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ninput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Templates.LNK.13.drLNK file: ..\..\Templates
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OfficeJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 904Thread sleep time: -3628800000s >= -30000sJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 904Thread sleep time: -86400000s >= -30000sJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile opened: PhysicalDrive0Jump to behavior
Source: Music.UI.exe, 00000013.00000003.2057200474.000001DF696F6000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00001.jrs VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.jfm VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\tmp.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\SRPData.xml VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\DiagOutputDir VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\DiagOutputDir\CriticalError_playbackTrace_1730549737.txt VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\DiagOutputDir\CriticalError_playbackTrace_1737029738.txt VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\backstack.json VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
2
Virtualization/Sandbox Evasion
LSASS Memory2
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Process Injection
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Rundll32
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture4
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets22
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1522642 URL: http://https:/atpscan.globa... Startdate: 30/09/2024 Architecture: WINDOWS Score: 2 18 settings-ssl.xboxlive.com 2->18 6 chrome.exe 9 2->6         started        9 WINWORD.EXE 81 94 2->9         started        11 Music.UI.exe 64 46 2->11         started        13 2 other processes 2->13 process3 dnsIp4 20 192.168.2.16, 137, 138, 443 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 15 chrome.exe 6->15         started        process5 dnsIp6 24 www.google.com 142.250.185.132, 443, 49711 GOOGLEUS United States 15->24 26 google.com 15->26

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://login.windows.local0%URL Reputationsafe
https://android.notify.windows.com/iOS0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.185.110
truefalse
    unknown
    www.google.com
    142.250.185.132
    truefalse
      unknown
      settings-ssl.xboxlive.com
      unknown
      unknownfalse
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        https://login.windows.localMusic.UI.exe, 00000013.00000002.2202171408.000001DF69E00000.00000004.00000020.00020000.00000000.sdmpfalse
        • URL Reputation: safe
        unknown
        https://login.windows.netMusic.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpfalse
          unknown
          https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xmlMusic.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpfalse
            unknown
            https://settings-ssl.xboxlive.comMusic.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              http://www.microsofi/crl/products/MicCerTruLisPCA_2009-04-02.crlMusic.UI.exe, 00000013.00000002.2205521947.000001DF6B2A4000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                http://crl.microsoft.coMusic.UI.exe, 00000013.00000002.2205521947.000001DF6B2A4000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  https://xsts.auth.xboxlive.com/OLE6543578F09ED7815F14EC5F7D14BMusic.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    https://android.notify.windows.com/iOSMusic.UI.exe, 00000013.00000002.2205377542.000001DF6B261000.00000004.00000020.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    https://login.windows.net/tchMusic.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      https://login.windows.netCDC98Music.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        https://xsts.auth.xboxlive.comMusic.UI.exe, 00000013.00000002.2205090302.000001DF6B200000.00000004.00000020.00020000.00000000.sdmpfalse
                          unknown
                          https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppMusic.UI.exe, 00000013.00000002.2203205444.000001DF69F65000.00000004.00000020.00020000.00000000.sdmpfalse
                            unknown
                            https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpgMusic.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpfalse
                              unknown
                              https://settings-ssl.xboxlive.com/Music.UI.exe, 00000013.00000003.2057151459.000001DF69191000.00000004.00000020.00020000.00000000.sdmpfalse
                                unknown
                                https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpgMusic.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpfalse
                                  unknown
                                  https://wns.windows.com/Music.UI.exe, 00000013.00000002.2198770639.000001DF68CC3000.00000004.00000020.00020000.00000000.sdmpfalse
                                    unknown
                                    https://login.windows.local/Music.UI.exe, 00000013.00000002.2202171408.000001DF69E00000.00000004.00000020.00020000.00000000.sdmpfalse
                                      unknown
                                      https://xsts.auth.xboxlive.comngpng1003Music.UI.exe, 00000013.00000002.2200794127.000001DF69649000.00000004.00000020.00020000.00000000.sdmpfalse
                                        unknown
                                        • No. of IPs < 25%
                                        • 25% < No. of IPs < 50%
                                        • 50% < No. of IPs < 75%
                                        • 75% < No. of IPs
                                        IPDomainCountryFlagASNASN NameMalicious
                                        142.250.185.132
                                        www.google.comUnited States
                                        15169GOOGLEUSfalse
                                        239.255.255.250
                                        unknownReserved
                                        unknownunknownfalse
                                        IP
                                        192.168.2.16
                                        Joe Sandbox version:41.0.0 Charoite
                                        Analysis ID:1522642
                                        Start date and time:2024-09-30 14:13:45 +02:00
                                        Joe Sandbox product:CloudBasic
                                        Overall analysis duration:0h 4m 1s
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                        Sample URL:http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVKfNDkV8Z7LfIWxRCCZdooZC&n=ZEhYBDFv208HJKEkNw5PqFObkm08aq7YeFB_fsGRbHtm2gx4mSx3JSwYkGZ1WU18bxwJPkfxXGKYv_KHdz1U8g&r=jfqeskceaKp8lH_i6JGe3T3xyBa6G7cbOCXOc4EPK3XMqLBHJqWBZEP0B9-qih8i&s=7226c2d05f1feec1a62ae2af2728e02cdefac54ea37a3a7665785b4a5864d360&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3DB175D31C2AE80D9A572ED101DA29F438*26file_type*3Dzip__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c26FxoQqF$%3E
                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                        Number of analysed new started processes analysed:26
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:0
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • EGA enabled
                                        • AMSI enabled
                                        Analysis Mode:default
                                        Analysis stop reason:Timeout
                                        Detection:CLEAN
                                        Classification:clean2.win@32/34@7/3
                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe, ApplicationFrameHost.exe
                                        • Excluded IPs from analysis (whitelisted): 142.250.184.227, 66.102.1.84, 142.250.186.78, 34.104.35.123, 52.109.89.18, 52.113.194.132, 142.250.186.35, 20.189.173.2, 88.221.168.8, 172.217.16.206
                                        • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, weu-azsc-config.officeapps.live.com, ecs-office.s-0005.s-msedge.net, clients2.google.com, update.googleapis.com, officeclient.microsoft.com, settings-ssl.xboxlive.com.edgekey.net, clients1.google.com, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, accounts.google.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, s-0005-office.config.skype.com, e87.dspb.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, edgedl.me.gvt1.com, s-0005.s-msedge.net, config.officeapps.live.com, onedscolprdwus01.westus.cloudapp.azure.com, clients.l.google.com, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.net
                                        • Not all processes where analyzed, report is missing behavior information
                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                        • Report size getting too big, too many NtEnumerateKey calls found.
                                        • Report size getting too big, too many NtOpenKey calls found.
                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                        • VT rate limit hit for: http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVKfNDkV8Z7LfIWxRCCZdooZC&n=ZEhYBDFv208HJKEkNw5PqFObkm08aq7YeFB_fsGRbHtm2gx4mSx3JSwYkGZ1WU18bxwJPkfxXGKYv_KHdz1U8g&r=jfqeskceaKp8lH_i6JGe3T3xyBa6G7cbOCXOc4EPK3XMqLBHJqWBZEP0B9-qih8i&s=7226c2d05f1feec1a62ae2af2728e02cdefac54ea37a3a7665785b4a5864d360&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3DB175D31C2AE80D9A572ED101DA29F438*26file_type*3Dzip__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGX
                                        TimeTypeDescription
                                        08:15:37API Interceptor149x Sleep call for process: Music.UI.exe modified
                                        No context
                                        No context
                                        No context
                                        No context
                                        No context
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):261
                                        Entropy (8bit):5.800418414702846
                                        Encrypted:false
                                        SSDEEP:6:5jElnhoX9CAkoeYvS6UZstDxxMDcyu47KlnhdmX9I+lBX:5jCG66yQKDKuOaR
                                        MD5:1DD837B10EFC1FECE1D0EAC023F8F0D3
                                        SHA1:30E8A81A3DAAB592C4CBC35ABD4518A1D1DEE311
                                        SHA-256:2E27D36BDE3D261E6FFCA5E4957AB340459926BA2F15CC58982B677C2C560CC4
                                        SHA-512:ACCF4EF7C3A918D54515ED3E84D8585EA11B72651A73D2D9F1BA907D96EDB37C58CD47F25EAAB873F62657B41033323185941D0D8009A1056626D964CA9316C9
                                        Malicious:false
                                        Reputation:low
                                        Preview:PK..........!.I...y...........META-INF/manifest.xmlT.K..@....w.z.o'M&...z.f....kIODo......^7<...:{1D:l....r.5..4n.....L...T.._..*(......%..#-3..3..sKl7E..TE...?.........PK..-.........!.I...y.........................META-INF/manifest.xmlPK..........C.........
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):2659
                                        Entropy (8bit):4.926959150875136
                                        Encrypted:false
                                        SSDEEP:48:cK88z2Dxfo++T4Vu5Hj2oJ//QBfM9ifr9jf2dBfUyrAf0dPfUytCfN4wc/+:n88z2DxueBQipjQB8BWP8pc+
                                        MD5:69415BBB2113097CE28402C78AAB8A1D
                                        SHA1:3CC52AA27D635F22434CFEAD93C27D3B5287BF2E
                                        SHA-256:95458051B4940AA84E142A19F4F775901CBFADC6BDEC409FC7C9DAC854FC8910
                                        SHA-512:03C62FF862F73046C45D6495D6E5E821ACBD228A230E6761DEE9E8A4E48F157CE3566E6E06FE8CACA73D4736B6AC78A4914855CDE4037574D8DBF86B2B2A0B54
                                        Malicious:false
                                        Reputation:low
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<clientConfiguration xmlns="http://schemas.microsoft.com/XblWinClient/2012/03" version="1">.. <targetedClient>XblWinClient</targetedClient > .. <rights>Copyright (c) Microsoft Corporation. All rights reserved.</rights> .... <configuration name="Features">.. <property name="EditorialPlaylistsEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="ExploreWithGenreDetailsEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="GenreRadioEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="MusicPassUpsell" type="string" value="" />.. <property name="MusicPassUpsellForCollectionPDP" type="string" value="" />.. <property name="MusicPassUpsellInMixtapes" type="string" value="" />.. <property name="MusicPassInAppPurchase" type="string" value="" />.. <property name="MusicSubscription" type="stri
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:Extensible storage engine DataBase, version 0x620, checksum 0xd98a66a6, page size 8192, DirtyShutdown, Windows version 10.0
                                        Category:dropped
                                        Size (bytes):3670016
                                        Entropy (8bit):0.2235486988980375
                                        Encrypted:false
                                        SSDEEP:1536:FSh2B+KY8kW/nbFgTC0/k63bBu7fhWx7zSh2YKY8kG4yDFqf47VgTC0/k63bBu7a:F6PL4a6fL4
                                        MD5:9C185F7CDD3AAB518AB3B2EBF0704130
                                        SHA1:8AA972823A984661F191FF47FB3B426771740ABE
                                        SHA-256:C60B1AF02DCABDAC218CEB9E51FB021D70CC936367E9B424629AA29EDDE4E185
                                        SHA-512:DA5B6F8E9AC6E3F8463E3FDE293D570AE4F3E98A90B632EAC9C82323EA70D8B2E545E843A68B8B02D2D77922B52E9D21D2A207353A7B5D2A5247F3FFE6A4AF71
                                        Malicious:false
                                        Reputation:low
                                        Preview:.f.... .......-.......m[.%....|......................................%....|..h...........................v*..%....|..........................................................................................................eJ........... ...................................................................................................... .......%....|..............................................................................................................................................................................................%....|7.................................@,.V%....|79...................C%....|..........................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16384
                                        Entropy (8bit):0.08364368713463725
                                        Encrypted:false
                                        SSDEEP:3:oXhZSPpo///tlIqS2ZTR0q5pmv2ZollynXv1lnls4/Mk/B/Qs9aclQ1:oXhZSPpo//1yqzYq7Y2CEX9/Ic
                                        MD5:B366013111346A597CAB7489FB0A1338
                                        SHA1:0F90F1CBD80A6FEBC5D9CF9FC195700FAD8054D4
                                        SHA-256:2465BA56B344845DA80DA9C1FA61839A5A2103DDBEBD35FEB394ED0F38912627
                                        SHA-512:66E666C557457E824EB88DED1922E5D60380953DCA965B5A5048EFD97632FAB7EE857464C8D70DDA258162B18F4AD0F6C15562FA3CF9DF84EC8FC81D6965AE40
                                        Malicious:false
                                        Reputation:low
                                        Preview:.......................................%....|..%....|..................%....|............Q.%....|.d...................C%....|..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):0.6157412833820387
                                        Encrypted:false
                                        SSDEEP:12:gISYwUIPxJ1qwUIPxJ1GQelRkISYwUIPxJ1qwUIPxJ1GQelR:gIVwUCx/qwUCx/GKIVwUCx/qwUCx/G
                                        MD5:44CD1D3C650BA0B409F6CA027766DC2D
                                        SHA1:42C7B3C5CC0058377426B3ACEB7D529C88986124
                                        SHA-256:BB7FC8D51461E46EE0E2DA2FC2D92B3718E676A89ED90B3EE206F2382AA9B7B3
                                        SHA-512:0FF2AB6FE6A8F4D5A302125A00C3134B8FD825AA80E5190E20DFCB2A34ECB7EEAE6B0663EC0A42463C8D48F2E8A9EF2928854832C9677D94F6AFF22A7C1A416B
                                        Malicious:false
                                        Reputation:low
                                        Preview:....................v*..%....|..................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\.................................................................................................................................................................0u..,.....................5w.................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2097152
                                        Entropy (8bit):0.7406028539704794
                                        Encrypted:false
                                        SSDEEP:1536:rLm1R1ddEBmHlZDulZu2Ea+ciyyzW0qxWtBiNwIwfO4sV6GK1Z08AZ5yeh0G32fQ:rLm1RfD7HOlTpnkYatqrb6v
                                        MD5:CF62E0ABBD71F025DDFC27BEE8E14841
                                        SHA1:A43D04DB880B9B1CD66E2B7025F470FE31EE80AB
                                        SHA-256:6FE7AA1B7B257F4E14C2190F9B8E5539E18AFDFF9120EF87C6F975A0364ABE52
                                        SHA-512:B6E1785676E93C37F9ACCA3A462763B8A694F444800F68F6AC84AD07662B5916F763DB653F7CB542FA82305705698F08F909DCCC98A624F6391A5CEB957F62AF
                                        Malicious:false
                                        Reputation:low
                                        Preview:.<j............ %....|......................v*..%....|..................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\.................................................................................................................................................................0u..,.....................5w.......................................#.................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2097152
                                        Entropy (8bit):0.0
                                        Encrypted:false
                                        SSDEEP:3::
                                        MD5:B2D1236C286A3C0704224FE4105ECA49
                                        SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                        SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                        SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                        Malicious:false
                                        Reputation:low
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2097152
                                        Entropy (8bit):0.0
                                        Encrypted:false
                                        SSDEEP:3::
                                        MD5:B2D1236C286A3C0704224FE4105ECA49
                                        SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                        SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                        SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                        Malicious:false
                                        Reputation:low
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2097152
                                        Entropy (8bit):0.0
                                        Encrypted:false
                                        SSDEEP:3::
                                        MD5:B2D1236C286A3C0704224FE4105ECA49
                                        SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                        SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                        SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                        Malicious:false
                                        Reputation:low
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:Extensible storage engine DataBase, version 0x620, checksum 0xaaa0cf96, page size 8192, JustCreated, Windows version 0.0
                                        Category:dropped
                                        Size (bytes):262144
                                        Entropy (8bit):0.14198421063674543
                                        Encrypted:false
                                        SSDEEP:768:M2gAhY+VxEyVjqaytqxUSYQHDmit8UPcim:zhY+VxEyVjqaytqxUSYQHDmit8UPcim
                                        MD5:C4FAA3514DC7C3F3514F7569D3A86171
                                        SHA1:174533926270C4649645E756E178841CEA537104
                                        SHA-256:3C9D7C442FB278D9FA46AFBC718FA8EC48466A8BFA12CDE710162D346EA17380
                                        SHA-512:DDE864DF95949CEC554358874DBFCE30CACB3258C1179D8D8E2483D1E6C82C532324034F09A8A9A8C0E3CF6CACE2C86D8A9D8128549A65F613E64FCE29203F34
                                        Malicious:false
                                        Reputation:low
                                        Preview:...... .......@.......;...%....|........................................................................................................................................................................................................... ...................................................................................................... ....................................................................................................................................................................................................................................................?a.%....|.5....................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):36990
                                        Entropy (8bit):5.310642927763068
                                        Encrypted:false
                                        SSDEEP:768:RO1Fjqoq8q7tRG8j2BZZWaTUNat7ICAPAmDcw:RmFjzq7tRGq2BZZWaTUNat7ICAPvf
                                        MD5:44D557430A6C9F2FD5FBA9268CE992AF
                                        SHA1:64C1B17AEA09ED7CE612BEBFEA06FB2D2E7C1572
                                        SHA-256:76D3A2B042216A1D39D719AE9D447C4A0DE3667641D4D6F936974FCDAEB2BF7F
                                        SHA-512:E8BE7E45F57C97FFA7B595786D7695C3F447714ABFEC31586B55502D6EDB9D614F8509866D77EE57F23036B88CED5682292D5D75166B078CB6DB2AA907BA6470
                                        Malicious:false
                                        Reputation:low
                                        Preview:1.10/04/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.3.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .4.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.5.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataProtectionApplied created.6.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.7.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.8.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackListManager::MediaPlaybackListManager.9.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackLi
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):36990
                                        Entropy (8bit):5.310642927763068
                                        Encrypted:false
                                        SSDEEP:768:RO1Fjqoq8q7tRG8j2BZZWaTUNat7ICAPAmDcw:RmFjzq7tRGq2BZZWaTUNat7ICAPvf
                                        MD5:44D557430A6C9F2FD5FBA9268CE992AF
                                        SHA1:64C1B17AEA09ED7CE612BEBFEA06FB2D2E7C1572
                                        SHA-256:76D3A2B042216A1D39D719AE9D447C4A0DE3667641D4D6F936974FCDAEB2BF7F
                                        SHA-512:E8BE7E45F57C97FFA7B595786D7695C3F447714ABFEC31586B55502D6EDB9D614F8509866D77EE57F23036B88CED5682292D5D75166B078CB6DB2AA907BA6470
                                        Malicious:false
                                        Reputation:low
                                        Preview:1.10/04/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.3.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .4.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.5.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataProtectionApplied created.6.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.7.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.8.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackListManager::MediaPlaybackListManager.9.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackLi
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):60144
                                        Entropy (8bit):5.3082269927450145
                                        Encrypted:false
                                        SSDEEP:1536:RmFjzq7tRGq2BZZWaTUNat7ICAPv8VC+xCrSJyvxp/rG5Svu8G0T9VcvSNvy12v5:wgtRG18nmCGI1
                                        MD5:147C77538755794084FD611F33A16A2C
                                        SHA1:475118E7ED8CE7D344B349D47A2C558D061220BD
                                        SHA-256:80551693B8CF577F77118BBBF418D14F7D9053D49ED45E80D6EBF09D4AB8FC41
                                        SHA-512:5CD2C73B79EE0EDE840FECACD9A8005B18B9AEA8405A96AEF1104D36D1B9EE2BBFE1C9DDE1D2CFD531225DA787BBF118888CE55117C8D91EC13F21E9B611AD86
                                        Malicious:false
                                        Reputation:low
                                        Preview:1.10/04/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.3.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .4.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.5.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataProtectionApplied created.6.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.7.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.8.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackListManager::MediaPlaybackListManager.9.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackLi
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):60144
                                        Entropy (8bit):5.3082269927450145
                                        Encrypted:false
                                        SSDEEP:1536:RmFjzq7tRGq2BZZWaTUNat7ICAPv8VC+xCrSJyvxp/rG5Svu8G0T9VcvSNvy12v5:wgtRG18nmCGI1
                                        MD5:147C77538755794084FD611F33A16A2C
                                        SHA1:475118E7ED8CE7D344B349D47A2C558D061220BD
                                        SHA-256:80551693B8CF577F77118BBBF418D14F7D9053D49ED45E80D6EBF09D4AB8FC41
                                        SHA-512:5CD2C73B79EE0EDE840FECACD9A8005B18B9AEA8405A96AEF1104D36D1B9EE2BBFE1C9DDE1D2CFD531225DA787BBF118888CE55117C8D91EC13F21E9B611AD86
                                        Malicious:false
                                        Reputation:low
                                        Preview:1.10/04/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.3.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .4.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.5.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataProtectionApplied created.6.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.7.10/08/24 09:46:24.7392.MS::Entertainment::Music::Playback::MusicNowPlayingQueue::MusicNowPlayingQueue.8.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackListManager::MediaPlaybackListManager.9.10/10/24 09:46:24.7392.MS::Entertainment::Music::Playback::MediaPlaybackLi
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text, with no line terminators
                                        Category:dropped
                                        Size (bytes):216
                                        Entropy (8bit):4.834888460738219
                                        Encrypted:false
                                        SSDEEP:3:uncHUTIqUHek8KIfFhKP4SfHUyLGewqfv/tRo+RrRD+EGmNrOVgNnb:e28IqUHeksNhy5mOfcbEGmNrDnb
                                        MD5:345F35857C1F69EFF87A954907513002
                                        SHA1:705F00BD8E3A55E9EB1567EAE6C0F7BB4B33AC59
                                        SHA-256:F42031D93A58CE45FDE1DC1CF5E17A9BC12F8A752F57E54D7E0AF0D476CEF773
                                        SHA-512:2D2A398B8F050BC568613CF80420A36C0363D82EE1E3E1F8A19BA59B2EAC1BC6C92E6D8AB7A5B09CB7DAE8FDE766AF78B803C3C5AACF4859CE8B181DDAB4B6CD
                                        Malicious:false
                                        Reputation:low
                                        Preview:<SRPData version="1" sessionId="1"><Outcomes></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="15" monthOfLastLaunch="11" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:ASCII text, with no line terminators
                                        Category:dropped
                                        Size (bytes):216
                                        Entropy (8bit):4.834888460738219
                                        Encrypted:false
                                        SSDEEP:3:uncHUTIqUHek8KIfFhKP4SfHUyLGewqfv/tRo+RrRD+EGmNrOVgNnb:e28IqUHeksNhy5mOfcbEGmNrDnb
                                        MD5:345F35857C1F69EFF87A954907513002
                                        SHA1:705F00BD8E3A55E9EB1567EAE6C0F7BB4B33AC59
                                        SHA-256:F42031D93A58CE45FDE1DC1CF5E17A9BC12F8A752F57E54D7E0AF0D476CEF773
                                        SHA-512:2D2A398B8F050BC568613CF80420A36C0363D82EE1E3E1F8A19BA59B2EAC1BC6C92E6D8AB7A5B09CB7DAE8FDE766AF78B803C3C5AACF4859CE8B181DDAB4B6CD
                                        Malicious:false
                                        Reputation:low
                                        Preview:<SRPData version="1" sessionId="1"><Outcomes></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="15" monthOfLastLaunch="11" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:JSON data
                                        Category:dropped
                                        Size (bytes):217
                                        Entropy (8bit):4.93980567695655
                                        Encrypted:false
                                        SSDEEP:6:YWLSrcTHF8+2FHyLkDHMJLb6D3PTK5cXI+HyLkDDETf3Qn:YWLSITHF8+2FSLkb2bg/AMSLkfm3Q
                                        MD5:2CDC41F725F04CEC33727CDC6481C94A
                                        SHA1:C6AC9CEB979BD3C2712C9CC5E0F033EDFA185B9D
                                        SHA-256:A58244DA4102BFB2D35130F816B81480722F622168FA8626770E00B558171057
                                        SHA-512:BAD5E48077D30A1AAB51F17239F17AB7EB21DD1B94DF2E2BD8C9926EA0F529CCC1FD346AAD6A6896629731F2AFCDBF80BBB68C6B39D24B7492CB3F3B625E0A44
                                        Malicious:false
                                        Reputation:low
                                        Preview:{"version":"10.19071.19011.0","backstack":[{"type":"MS.Entertainment.Music.AlbumsPage","transition":1,"link":"mswindowsmusic://navigatetolibrary/?pageviewtype=MS.Entertainment.Music.AlbumsPage&scrollpositioninfo=0"}]}
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:JSON data
                                        Category:dropped
                                        Size (bytes):217
                                        Entropy (8bit):4.93980567695655
                                        Encrypted:false
                                        SSDEEP:6:YWLSrcTHF8+2FHyLkDHMJLb6D3PTK5cXI+HyLkDDETf3Qn:YWLSITHF8+2FSLkb2bg/AMSLkfm3Q
                                        MD5:2CDC41F725F04CEC33727CDC6481C94A
                                        SHA1:C6AC9CEB979BD3C2712C9CC5E0F033EDFA185B9D
                                        SHA-256:A58244DA4102BFB2D35130F816B81480722F622168FA8626770E00B558171057
                                        SHA-512:BAD5E48077D30A1AAB51F17239F17AB7EB21DD1B94DF2E2BD8C9926EA0F529CCC1FD346AAD6A6896629731F2AFCDBF80BBB68C6B39D24B7492CB3F3B625E0A44
                                        Malicious:false
                                        Reputation:low
                                        Preview:{"version":"10.19071.19011.0","backstack":[{"type":"MS.Entertainment.Music.AlbumsPage","transition":1,"link":"mswindowsmusic://navigatetolibrary/?pageviewtype=MS.Entertainment.Music.AlbumsPage&scrollpositioninfo=0"}]}
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:MS Windows registry file, NT/2000 or above
                                        Category:dropped
                                        Size (bytes):16384
                                        Entropy (8bit):2.702524714848899
                                        Encrypted:false
                                        SSDEEP:96:eJbcGq6bDoimV6+5fH9lFBNrHbPLRKskVEhzZYiYq8fi6IeyKHYmrEE9gWoco1L8:ObcG3oimV6wbPLeKCGK4/V1crm
                                        MD5:D3A15F6A274889097017904FBF411CE1
                                        SHA1:916C3C548F05CD4DDB8FFA7D728E206AA58E2F65
                                        SHA-256:515BF33A72A068C7B51CD976E3108FA26B55E5E29EAA02A65B483DE7F90452AC
                                        SHA-512:34FC42839AB245774CC8F8180ED7B71C684F40555AFF288E6AF731B1D8334316CE68EDFE72D6817E0503D59ABBA644E01DFC549702C68C2309BD90C13991834C
                                        Malicious:false
                                        Reputation:low
                                        Preview:regf........b.Q.7.................. .... ......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtmfT/u2...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        File Type:MS Windows registry file, NT/2000 or above
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.4188568537914485
                                        Encrypted:false
                                        SSDEEP:96:YJ/cGq6bDoimV6+5fH9lFBNrHbPLRKskVEhzZYiYq8fi6IeyKHYmrEE9gWoco1L8:8/cG3oimV6wbPLeKCGK4/V1crm
                                        MD5:493647A5794CE1E507BBD92073C6B115
                                        SHA1:D65CA92024FAAA5CD327B0243348F1E3C5CE411E
                                        SHA-256:3F4AF3C819EA78ECCDC68DC0960EAC45940E867C4A025248DEE38872A7C0243D
                                        SHA-512:DB3633FF4B05A69EE6F6C015663396352C899C6564E43AD275F8A200BBFBFB6ADF1C37759592E53ECE40402D6F1ACE85F55323F8C040CB17D6A984806AF9537B
                                        Malicious:false
                                        Reputation:low
                                        Preview:regf........b.Q.7.................. .... ......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtmfT/u2...................................................................................................................................................................................................................................................................................................................................................HvLE............. ..........$psx...@.1....... ..hbin................b.Q.7..........nk,.T...7...... ...........................x...............................Test....p...sk..h...h.......t.......H...X.............4.........?.......................?....................... ... ...............YQ..fr]%dc;.............nk .sH.|2...................................h...............................Configuration...p...sk..x...x.......t.......H...X.............4.........?.......................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:ASCII text, with very long lines (4629), with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):16729
                                        Entropy (8bit):5.477785344518527
                                        Encrypted:false
                                        SSDEEP:384:ITTSNLKXat0CBGxozsTBjlwiKmuCBYbrwXx6rsYyC:ITTSxKXat0CBGxesjeiKm5abrwB6rB
                                        MD5:7546A3C13805D569488CD10D68D9CE7C
                                        SHA1:A24113CC7F4A1AA34CCBF73525C1C6DE4667FBE8
                                        SHA-256:ACFB139340C7F7BC8315F9AA316C3C8957512759E06E26881FB5FEAF366C3E9F
                                        SHA-512:54ECE8928C4F3344F607EF617A5E258859D391A1AF31165100206A00F32EE85765DD9E9C25FC78604BBE396CBB53C7E16BBECB597EA6EC87099595BBB82C000A
                                        Malicious:false
                                        Reputation:low
                                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..09/30/2024 12:15:12.089.WINWORD (0x1F44).0x1F78.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":22,"Time":"2024-09-30T12:15:12.089Z","Contract":"Office.System.Activity","Activity.CV":"y5XdZuG11Ui1WzBe/dVN9g.7.1","Activity.Duration":167,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...09/30/2024 12:15:12.089.WINWORD (0x1F44).0x1F78.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":23,"Time":"2024-09-30T12:15:12.089Z","Contract":"Office.System.Activity","Activity.CV":"y5XdZuG11Ui1WzBe/dVN9g.7","Activity.Duration":489,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.FailureDi
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):30
                                        Entropy (8bit):1.172253928364927
                                        Encrypted:false
                                        SSDEEP:3:zTzX:
                                        MD5:3D79DABFD4E44D9BC83CD1697A2ACA1F
                                        SHA1:C2FF2C33BA6C2EAC9A4993C8D4F875C99F446DBA
                                        SHA-256:7B72054303EE5950634317F812B59C20292CF8ECEAE1600CC092C9A0BACD02BD
                                        SHA-512:C7D3674D58021DE822161EC9E6F1E438940644AF97174DFC7E0A4B70326369BC5EFFAB1020FEAB58032DE87F67FB07A914EEE4934DF69E10CF7A2CAE46A55A3F
                                        Malicious:false
                                        Reputation:low
                                        Preview:..............................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Mon Sep 30 11:15:11 2024, mtime=Mon Sep 30 11:15:33 2024, atime=Mon Sep 30 11:15:33 2024, length=0, window=hide
                                        Category:dropped
                                        Size (bytes):1161
                                        Entropy (8bit):4.612587119745253
                                        Encrypted:false
                                        SSDEEP:24:8l9OKt3wZ9VSAlk9JZrQAouTQJ1yWBWgqygm:8lqZlkH9ouTQ2yg
                                        MD5:15A5120ACE249FCA88BEAD3848F0E911
                                        SHA1:683C11C51FE17687D233A0D00DFB82F5C7FF17E1
                                        SHA-256:203BE3B59AB5EEB8CEFD046101F1647491E2948C77C6D3C7498FC3B8450C7690
                                        SHA-512:B7FDB473C3012B6F6E72FCAABFFFB225A88519FB8890B033670BBE1C0B7B2E076C6B86E4497D7169F5E360341061C4304F5A28B313211AF93010A4BC761A567E
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.........j.f2......r2...@p.r2...........................Y....P.O. .:i.....+00.../C:\...................x.1.....FW,I..Users.d......OwH>Y.a....................:.........U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....N.1.....>Y.a..user..:......FW.H>Y.a..............................c.a.l.i.....V.1.....FW.H..AppData.@......FW.H>Y.a..............................A.p.p.D.a.t.a.....V.1.....>Y.a..Roaming.@......FW.H>Y.a..........................R...R.o.a.m.i.n.g.....\.1.....>Y.a..MICROS~1..D......FW.H>Y.a...........................m..M.i.c.r.o.s.o.f.t.....\.1.....>Y.a..TEMPLA~1..D......>Y.a>Y.a..............................T.e.m.p.l.a.t.e.s.......`...............-......._............F.......C:\Users\user\AppData\Roaming\Microsoft\Templates........\.....\.T.e.m.p.l.a.t.e.s...........................>.e.L.:..er.=....`.......X.......928100...........hT..CrF.f4... ..{.%.........%..hT..CrF.f4... ..{.%.........%.............1SPS.XF.L8C....&.m.q............/...S.-.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):28
                                        Entropy (8bit):4.351823225551765
                                        Encrypted:false
                                        SSDEEP:3:bDuMJlv:bCy
                                        MD5:4E30A3397E81DD38A188E78FC94E5A77
                                        SHA1:95E2EFA493065E02C7370BEFBE5A4BC1340CF5EF
                                        SHA-256:DDD0B5A9B8BD9275DDD6BD1D9D033C56734A5BB184B4371E50C2200B903397CB
                                        SHA-512:6D9BA51003C7C056E2628F8C435029C8A62E4A7E9A40B59C952AF160B91449AA4B9E5E4084A275E1825C6BE0CD1C8EE22709BEB1C13839BE8B29C63B2509DF53
                                        Malicious:false
                                        Reputation:low
                                        Preview:[folders]..Templates.LNK=0..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):19343
                                        Entropy (8bit):7.470539409831921
                                        Encrypted:false
                                        SSDEEP:384:Jrt+BNxt/ZtNNU/EVy9HnacaH7dMtri24sjPWfWS9mUKm0:VAxllN8Hha6+fR0
                                        MD5:B13A2446B31E9B87B1DF50BD093D619B
                                        SHA1:52B0D872E237ED87065F20B5AE93431BA03EC025
                                        SHA-256:EA2827AA80B0888AE8EBFA6A36FF9E79C75655FB7FBAC108D94AA32F6C5E1958
                                        SHA-512:1F55EE8D2DD99169DA42344B8C3728D2E66D4C808FBD61DDDFA9C868DA44125CBA7B9453C3FB53BA5C30D7BC6BEB4921F28C0D54D6173B46239BF36D42FAE826
                                        Malicious:false
                                        Reputation:low
                                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):162
                                        Entropy (8bit):3.4562602419578363
                                        Encrypted:false
                                        SSDEEP:3:8lZlYl7RjIAial/hBU5/piYvZ5g:0ZizGu/hBUaYvZa
                                        MD5:4EB24CE763AF76BF4A53BFBFDCED6DC7
                                        SHA1:9C4A795D86AD893358C4D74BACF2CA36C8A18326
                                        SHA-256:E385FCFD43D7D57EBC271902F3D08B57E55306967C0D6A0C34099C1CFE69C3E8
                                        SHA-512:42B2EDB3BF59D648360F89FF423D1AE63F888438266F4533E63D371BA6CD6E48A0575BF9E64B5F950616457C13E515C11C24181498CA30339A3C631D5DB11D94
                                        Malicious:false
                                        Reputation:low
                                        Preview:.user...................................................c.a.l.i................ ..`...T5..Xz.kM.........9j..... ..`...XF......`.R.`.R.M...........`.R.. ...5..XF..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):19343
                                        Entropy (8bit):7.470539409831921
                                        Encrypted:false
                                        SSDEEP:384:Jrt+BNxt/ZtNNU/EVy9HnacaH7dMtri24sjPWfWS9mUKm0:VAxllN8Hha6+fR0
                                        MD5:B13A2446B31E9B87B1DF50BD093D619B
                                        SHA1:52B0D872E237ED87065F20B5AE93431BA03EC025
                                        SHA-256:EA2827AA80B0888AE8EBFA6A36FF9E79C75655FB7FBAC108D94AA32F6C5E1958
                                        SHA-512:1F55EE8D2DD99169DA42344B8C3728D2E66D4C808FBD61DDDFA9C868DA44125CBA7B9453C3FB53BA5C30D7BC6BEB4921F28C0D54D6173B46239BF36D42FAE826
                                        Malicious:false
                                        Reputation:low
                                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 11:14:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2673
                                        Entropy (8bit):3.97943309877364
                                        Encrypted:false
                                        SSDEEP:48:8XodxT5hoHfidAKZdA1FehwiZUklqehny+3:8Wv4Uy
                                        MD5:642A3C9F51F4778B0F3037443D2ED13D
                                        SHA1:908A066E03653C8E5E8E3A0A0BC405E1A502B6D9
                                        SHA-256:E8EC164046A845E42C97BE2C67B08D21EAF95B437AB62FC46D58971A0D8E8EAA
                                        SHA-512:96BC8483E76E0A976567DB5B4337EAE9F730A0F2A4F261B83E095D00208F72B4FE32871F007DC25DF7526C27FED24EAC9DCBAD645F541EE1CBD11636ECFDAC87
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,.......E2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.a...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 11:14:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2675
                                        Entropy (8bit):3.996249532457966
                                        Encrypted:false
                                        SSDEEP:48:8AqdxT5hoHfidAKZdA1seh/iZUkAQkqehEy+2:8AEvO9QZy
                                        MD5:655C3400CAE091CB8BA3E9DF6664ECEE
                                        SHA1:478387143C41C8116368C3073CFB0021E680A621
                                        SHA-256:76BD1D50B2B399538E3BDA86F67D880D6D37CE361CAC5BBE905322009A6F134E
                                        SHA-512:6760809BFDBF2042FA555959E3477D197DFF56E2FE9BDC7697146235DB20D1F9F5F8682D6004A6EE3FC5D796531CD71C83B9BCB1379D157C0F4F2C2F5F57A149
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,.....V.E2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.a...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2689
                                        Entropy (8bit):4.0058155869463095
                                        Encrypted:false
                                        SSDEEP:48:8ydxT5hAHfidAKZdA14meh7sFiZUkmgqeh7smy+BX:8Mvyn4y
                                        MD5:9C4DF35506B42069E67CD04B5141CF7A
                                        SHA1:509EC6F84F386B0A2F09C69206F61E12D7B31899
                                        SHA-256:C96E68EFBD2D810A378DD58D1873CEB4745EBEE4D51BC2860F0C1FCC12531C9D
                                        SHA-512:34F620322B48E0482B5AAD30A54BEEFB67F3CFDDDDFE0B59A8E99684D490628A461543EB26099ECB017C4C433CDBE2549BA8A7970B0243D33A782A53710EB586
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 11:14:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2677
                                        Entropy (8bit):3.993422765819331
                                        Encrypted:false
                                        SSDEEP:48:8UdxT5hoHfidAKZdA1TehDiZUkwqehgy+R:8avluy
                                        MD5:277F330C98DB1C59617F41073069C006
                                        SHA1:8762FE7AA7940D916446CA6DCA2DAB8C96ABA1F6
                                        SHA-256:1D43CE593C4FC984EAF1880B2D482A1AAD2EDAA7721075844E91C7A3D61FDA2E
                                        SHA-512:52A926BD04D373EF92A2A3A29F45C96F3826A3086A8A29B4F10EBC49F9D624A3EA18C55BDD666FD51898267D84E5277FA123A9E748BECC5A272F4558439FA10A
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,......E2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.a...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 11:14:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2677
                                        Entropy (8bit):3.9842601334902836
                                        Encrypted:false
                                        SSDEEP:48:8EdxT5hoHfidAKZdA1dehBiZUk1W1qeh6y+C:8KvV9ay
                                        MD5:814D5845908E17FC253DD1465D9A11A1
                                        SHA1:1A07303A1674289758EB9E3B46EE5FCE06AF0924
                                        SHA-256:A17DF8B30FCDC0B5A3C679C0FE1B0EED817694170D1EDEC2AD74B98C67CB14F4
                                        SHA-512:95E1AF75E3374BFAFC8A95C0D56EC22BA3917955F6E2DBDFC47356744B5C064FD21129683A954E4475C48C56D06F85F2B2A4208E4BA77D91B945CA780BD273E6
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,.......E2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.a...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 11:14:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                        Category:dropped
                                        Size (bytes):2679
                                        Entropy (8bit):3.9890664099682223
                                        Encrypted:false
                                        SSDEEP:48:8ZdxT5hoHfidAKZdA1duTeehOuTbbiZUk5OjqehOuTb4y+yT+:8FvdTfTbxWOvTb4y7T
                                        MD5:5BE4C0E38F7FF37E7B8AED7CB1CA6261
                                        SHA1:F2509D48DCC169A8CED6FA6D8D102209918C39F3
                                        SHA-256:4688A8672C22DD12B7E3C875DF9107C100F7495DB33A7B3F768F3B91FC48FDA5
                                        SHA-512:FB3896A4C19AE23485CA1C7074C8C7DD69352D930B4028F8FF76D0A3C55B64CC913C4301B8A41372D1BC09EF9298E66E2A9BE5E48081ED32BA2A4EFFD108042C
                                        Malicious:false
                                        Reputation:low
                                        Preview:L..................F.@.. ...$+.,....c..E2...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I>Y.a....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Y.a....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Y.a....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Y.a..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Y.a...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............I.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):162
                                        Entropy (8bit):4.050557888384673
                                        Encrypted:false
                                        SSDEEP:3:7yhRHZ9NiBWkuSzIuAroUiWCC1i:GR59wk7AIxroU7Y
                                        MD5:53B9998AE8411C13A06AC8C20C49FF5B
                                        SHA1:D5690E14D2D1446DCB63A4D0F514438AAE0A3CFD
                                        SHA-256:2E3229EA5D03BD507290BFCD1CC6C868D446489D5383D587A85C74775571992A
                                        SHA-512:2CE6FDC376BBEE419EABD21A93D685DA2C011005D01F571D01BC267C86BF19B96A255BBC10E68DC038400DF808A3984BF0E06720B6BE904509E8E751A079BA8D
                                        Malicious:false
                                        Reputation:low
                                        Preview:..........................................................SEQAWSWDOFSPSEHOQRGFTQGBAGLJEZFNAHFMRNONCLEXLHXVVIHABFJZFHOARZFARCMMABNG2........(JE....}.j.....Z...=Pj
                                        No static file info
                                        TimestampSource PortDest PortSource IPDest IP
                                        Sep 30, 2024 14:14:14.776288033 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:15.076978922 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:15.685108900 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:16.893014908 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:17.603152990 CEST4968980192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:19.306096077 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:21.233823061 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.233870029 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:21.233990908 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.235662937 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.235678911 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:21.673135996 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:21.673177004 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:21.673254967 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:21.673525095 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:21.673537016 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:21.893155098 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:21.893276930 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.897020102 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.897033930 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:21.897289991 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:21.940809011 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:21.987418890 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.168186903 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.168267965 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.168325901 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.168382883 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.168395042 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.168406010 CEST49710443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.168410063 CEST44349710184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.213023901 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.213063002 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.213144064 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.213430882 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.213442087 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.311855078 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:22.312156916 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:22.312171936 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:22.313621998 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:22.313699007 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:22.317852974 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:22.317950964 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:22.366995096 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:22.367005110 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:22.415002108 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:22.876182079 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.876276016 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.877764940 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.877775908 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.878001928 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.879079103 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:22.923402071 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:22.941519022 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:23.158472061 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:23.158540964 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:23.158601046 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:23.159403086 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:23.159403086 CEST49712443192.168.2.16184.28.90.27
                                        Sep 30, 2024 14:14:23.159424067 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:23.159434080 CEST44349712184.28.90.27192.168.2.16
                                        Sep 30, 2024 14:14:23.251039982 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:23.856033087 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:24.111053944 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:25.070018053 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:25.805737972 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:25.805831909 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:25.806025028 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:25.807043076 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:25.807080030 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.417093992 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.417181969 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.419907093 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.419940948 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.420341015 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.471036911 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.478125095 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.523410082 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677120924 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677149057 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677159071 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677228928 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677249908 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677258015 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677267075 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.677284956 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677309036 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.677330971 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.677898884 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.677954912 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.677964926 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.678085089 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.678124905 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.689455032 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.689491034 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:26.689506054 CEST49713443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:14:26.689515114 CEST4434971320.12.23.50192.168.2.16
                                        Sep 30, 2024 14:14:27.407233000 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:27.471039057 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:27.710038900 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:28.318053007 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:29.532030106 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:31.939066887 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:32.210634947 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:32.210700035 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:32.210750103 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:32.273072958 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:32.959271908 CEST49711443192.168.2.16142.250.185.132
                                        Sep 30, 2024 14:14:32.959295034 CEST44349711142.250.185.132192.168.2.16
                                        Sep 30, 2024 14:14:33.719034910 CEST49673443192.168.2.16204.79.197.203
                                        Sep 30, 2024 14:14:36.746063948 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:14:41.888081074 CEST49678443192.168.2.1620.189.173.10
                                        Sep 30, 2024 14:14:46.347085953 CEST4968080192.168.2.16192.229.211.108
                                        Sep 30, 2024 14:15:03.052614927 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.052660942 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.052738905 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.053145885 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.053158998 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.155249119 CEST4969780192.168.2.16199.232.214.172
                                        Sep 30, 2024 14:15:03.155375004 CEST4969880192.168.2.16199.232.214.172
                                        Sep 30, 2024 14:15:03.160878897 CEST8049697199.232.214.172192.168.2.16
                                        Sep 30, 2024 14:15:03.160896063 CEST8049698199.232.214.172192.168.2.16
                                        Sep 30, 2024 14:15:03.160959959 CEST4969780192.168.2.16199.232.214.172
                                        Sep 30, 2024 14:15:03.160974026 CEST4969880192.168.2.16199.232.214.172
                                        Sep 30, 2024 14:15:03.642151117 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.642235041 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.643554926 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.643568993 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.643783092 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.645276070 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.691405058 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.847913027 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.847938061 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.847953081 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848038912 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.848058939 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848124027 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.848756075 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848795891 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848809004 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.848823071 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848856926 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.848865032 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848875999 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.848900080 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.848927021 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.851367950 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.851382017 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:03.851413965 CEST49714443192.168.2.1620.12.23.50
                                        Sep 30, 2024 14:15:03.851418972 CEST4434971420.12.23.50192.168.2.16
                                        Sep 30, 2024 14:15:18.514812946 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:18.514858007 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:18.514961004 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:18.515125990 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:18.515141010 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.333396912 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.333497047 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.348155975 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.348171949 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.349200964 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.349759102 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.349790096 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.349814892 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.710890055 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.710958958 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.711038113 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.711051941 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.711101055 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.711119890 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.711242914 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.711298943 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.711448908 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.711468935 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:19.711482048 CEST49718443192.168.2.1620.190.159.23
                                        Sep 30, 2024 14:15:19.711486101 CEST4434971820.190.159.23192.168.2.16
                                        Sep 30, 2024 14:15:45.518255949 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:45.523113966 CEST53497221.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.523238897 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:45.523283005 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:45.523283005 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:45.528086901 CEST53497221.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.528096914 CEST53497221.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.975716114 CEST53497221.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.976358891 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:45.981482983 CEST53497221.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.981585979 CEST4972253192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:53.897449017 CEST4970080192.168.2.16192.229.221.95
                                        Sep 30, 2024 14:15:53.904958963 CEST8049700192.229.221.95192.168.2.16
                                        Sep 30, 2024 14:15:53.905034065 CEST4970080192.168.2.16192.229.221.95
                                        TimestampSource PortDest PortSource IPDest IP
                                        Sep 30, 2024 14:14:16.907124043 CEST53513591.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:16.964262962 CEST53546611.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:17.789419889 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:17.935148001 CEST53603271.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:18.542105913 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:19.307104111 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:20.080482960 CEST5722153192.168.2.168.8.8.8
                                        Sep 30, 2024 14:14:20.080723047 CEST6077553192.168.2.161.1.1.1
                                        Sep 30, 2024 14:14:20.087738037 CEST53607751.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:20.109453917 CEST53572218.8.8.8192.168.2.16
                                        Sep 30, 2024 14:14:21.098267078 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:21.664917946 CEST5553453192.168.2.161.1.1.1
                                        Sep 30, 2024 14:14:21.665236950 CEST5567053192.168.2.161.1.1.1
                                        Sep 30, 2024 14:14:21.672000885 CEST53556701.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:21.672106981 CEST53555341.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:21.855117083 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:22.621088028 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:28.388050079 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:29.149097919 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:29.913137913 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:32.957947969 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:33.719130993 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:34.470133066 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:14:34.811933994 CEST53523871.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:35.241168976 CEST6345453192.168.2.161.1.1.1
                                        Sep 30, 2024 14:14:35.241718054 CEST5653553192.168.2.168.8.8.8
                                        Sep 30, 2024 14:14:35.248991013 CEST53565358.8.8.8192.168.2.16
                                        Sep 30, 2024 14:14:35.249036074 CEST53634541.1.1.1192.168.2.16
                                        Sep 30, 2024 14:14:53.795331955 CEST53604451.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:05.266752005 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:15:06.024238110 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:15:06.789232969 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:15:16.320246935 CEST53564741.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:16.868083954 CEST53586891.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:19.107836008 CEST138138192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:15:41.428350925 CEST6233353192.168.2.161.1.1.1
                                        Sep 30, 2024 14:15:44.495948076 CEST53529671.1.1.1192.168.2.16
                                        Sep 30, 2024 14:15:45.517625093 CEST53548841.1.1.1192.168.2.16
                                        Sep 30, 2024 14:16:07.551388979 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:16:08.312381983 CEST137137192.168.2.16192.168.2.255
                                        Sep 30, 2024 14:16:09.077445030 CEST137137192.168.2.16192.168.2.255
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Sep 30, 2024 14:14:20.080482960 CEST192.168.2.168.8.8.80xc8edStandard query (0)google.comA (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:20.080723047 CEST192.168.2.161.1.1.10xf801Standard query (0)google.comA (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:21.664917946 CEST192.168.2.161.1.1.10xd5ddStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:21.665236950 CEST192.168.2.161.1.1.10x1194Standard query (0)www.google.com65IN (0x0001)false
                                        Sep 30, 2024 14:14:35.241168976 CEST192.168.2.161.1.1.10x4ee1Standard query (0)google.comA (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:35.241718054 CEST192.168.2.168.8.8.80xbec6Standard query (0)google.comA (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:15:41.428350925 CEST192.168.2.161.1.1.10x4699Standard query (0)settings-ssl.xboxlive.comA (IP address)IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Sep 30, 2024 14:14:20.087738037 CEST1.1.1.1192.168.2.160xf801No error (0)google.com142.250.185.110A (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:20.109453917 CEST8.8.8.8192.168.2.160xc8edNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:21.672000885 CEST1.1.1.1192.168.2.160x1194No error (0)www.google.com65IN (0x0001)false
                                        Sep 30, 2024 14:14:21.672106981 CEST1.1.1.1192.168.2.160xd5ddNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:35.248991013 CEST8.8.8.8192.168.2.160xbec6No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:14:35.249036074 CEST1.1.1.1192.168.2.160x4ee1No error (0)google.com142.250.181.238A (IP address)IN (0x0001)false
                                        Sep 30, 2024 14:15:41.437388897 CEST1.1.1.1192.168.2.160x4699No error (0)settings-ssl.xboxlive.comsettings-ssl.xboxlive.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                        • fs.microsoft.com
                                        • slscr.update.microsoft.com
                                        • login.live.com
                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        0192.168.2.1649710184.28.90.27443
                                        TimestampBytes transferredDirectionData
                                        2024-09-30 12:14:21 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                        Connection: Keep-Alive
                                        Accept: */*
                                        Accept-Encoding: identity
                                        User-Agent: Microsoft BITS/7.8
                                        Host: fs.microsoft.com
                                        2024-09-30 12:14:22 UTC466INHTTP/1.1 200 OK
                                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                        Content-Type: application/octet-stream
                                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                        Server: ECAcc (lpl/EF06)
                                        X-CID: 11
                                        X-Ms-ApiVersion: Distribute 1.2
                                        X-Ms-Region: prod-weu-z1
                                        Cache-Control: public, max-age=25958
                                        Date: Mon, 30 Sep 2024 12:14:22 GMT
                                        Connection: close
                                        X-CID: 2


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        1192.168.2.1649712184.28.90.27443
                                        TimestampBytes transferredDirectionData
                                        2024-09-30 12:14:22 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                        Connection: Keep-Alive
                                        Accept: */*
                                        Accept-Encoding: identity
                                        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                        Range: bytes=0-2147483646
                                        User-Agent: Microsoft BITS/7.8
                                        Host: fs.microsoft.com
                                        2024-09-30 12:14:23 UTC514INHTTP/1.1 200 OK
                                        ApiVersion: Distribute 1.1
                                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                        Content-Type: application/octet-stream
                                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                        Server: ECAcc (lpl/EF06)
                                        X-CID: 11
                                        X-Ms-ApiVersion: Distribute 1.2
                                        X-Ms-Region: prod-weu-z1
                                        Cache-Control: public, max-age=25948
                                        Date: Mon, 30 Sep 2024 12:14:23 GMT
                                        Content-Length: 55
                                        Connection: close
                                        X-CID: 2
                                        2024-09-30 12:14:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        2192.168.2.164971320.12.23.50443
                                        TimestampBytes transferredDirectionData
                                        2024-09-30 12:14:26 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=WWfY4y+vlesLmSE&MD=E3oZYt79 HTTP/1.1
                                        Connection: Keep-Alive
                                        Accept: */*
                                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                        Host: slscr.update.microsoft.com
                                        2024-09-30 12:14:26 UTC560INHTTP/1.1 200 OK
                                        Cache-Control: no-cache
                                        Pragma: no-cache
                                        Content-Type: application/octet-stream
                                        Expires: -1
                                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                        ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                        MS-CorrelationId: abe89b65-8627-4cd1-a4c9-bbe8dd42ad19
                                        MS-RequestId: a0be755f-b575-42d1-bae9-b9e0c4f75a1b
                                        MS-CV: qgt/0YTu8kKGmmI1.0
                                        X-Microsoft-SLSClientCache: 2880
                                        Content-Disposition: attachment; filename=environment.cab
                                        X-Content-Type-Options: nosniff
                                        Date: Mon, 30 Sep 2024 12:14:26 GMT
                                        Connection: close
                                        Content-Length: 24490
                                        2024-09-30 12:14:26 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                        Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                        2024-09-30 12:14:26 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                        Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        3192.168.2.164971420.12.23.50443
                                        TimestampBytes transferredDirectionData
                                        2024-09-30 12:15:03 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=WWfY4y+vlesLmSE&MD=E3oZYt79 HTTP/1.1
                                        Connection: Keep-Alive
                                        Accept: */*
                                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                        Host: slscr.update.microsoft.com
                                        2024-09-30 12:15:03 UTC560INHTTP/1.1 200 OK
                                        Cache-Control: no-cache
                                        Pragma: no-cache
                                        Content-Type: application/octet-stream
                                        Expires: -1
                                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                        ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                                        MS-CorrelationId: a61321be-3bac-4dfd-bcb9-dcd2b4aa52da
                                        MS-RequestId: 0d6cc72c-e31f-411c-abad-950231e120a0
                                        MS-CV: qb0SNoxlX0uT8aJa.0
                                        X-Microsoft-SLSClientCache: 1440
                                        Content-Disposition: attachment; filename=environment.cab
                                        X-Content-Type-Options: nosniff
                                        Date: Mon, 30 Sep 2024 12:15:03 GMT
                                        Connection: close
                                        Content-Length: 30005
                                        2024-09-30 12:15:03 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                                        Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                                        2024-09-30 12:15:03 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                                        Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        4192.168.2.164971820.190.159.23443
                                        TimestampBytes transferredDirectionData
                                        2024-09-30 12:15:19 UTC422OUTPOST /RST2.srf HTTP/1.0
                                        Connection: Keep-Alive
                                        Content-Type: application/soap+xml
                                        Accept: */*
                                        User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                        Content-Length: 4762
                                        Host: login.live.com
                                        2024-09-30 12:15:19 UTC4762OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                        Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                        2024-09-30 12:15:19 UTC569INHTTP/1.1 200 OK
                                        Cache-Control: no-store, no-cache
                                        Pragma: no-cache
                                        Content-Type: application/soap+xml; charset=utf-8
                                        Expires: Mon, 30 Sep 2024 12:14:19 GMT
                                        P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                        Referrer-Policy: strict-origin-when-cross-origin
                                        x-ms-route-info: C538_SN1
                                        x-ms-request-id: 5cafafbf-b093-4fb0-90ca-c512e8471ac0
                                        PPServer: PPV: 30 H: SN1PEPF0002F94B V: 0
                                        X-Content-Type-Options: nosniff
                                        Strict-Transport-Security: max-age=31536000
                                        X-XSS-Protection: 1; mode=block
                                        Date: Mon, 30 Sep 2024 12:15:18 GMT
                                        Connection: close
                                        Content-Length: 10197
                                        2024-09-30 12:15:19 UTC10197INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                        Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                        Click to jump to process

                                        Click to jump to process

                                        Click to dive into process behavior distribution

                                        Click to jump to process

                                        Target ID:0
                                        Start time:08:14:14
                                        Start date:30/09/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                                        Imagebase:0x7ff7f9810000
                                        File size:3'242'272 bytes
                                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:false

                                        Target ID:2
                                        Start time:08:14:15
                                        Start date:30/09/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2008,i,17072862143821464706,10439542806910227767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                        Imagebase:0x7ff7f9810000
                                        File size:3'242'272 bytes
                                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:false

                                        Target ID:3
                                        Start time:08:14:16
                                        Start date:30/09/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://https:/atpscan.global.hornetsecurity.com?d=r7jv6mGLSFUWnAoVoWKJDiF7kKGt3Fw5kKbn5s5sfcpNyTRbK79Zci2IH8Nl2g5X&f=qvzVe-8YAX4Dy6XefosXpr9xe6cUPxuD05v5wTHFNiMjrMs6M0fDbIikzhduev0q&i=&k=3x5s&m=iAkhIt0HvpR1Oh2_h6Q0O4Hzfyk0g3SV3EvnL7Z4VUDMO-lWq1KA94UsI2rIZoVyTUZY62kGnDiHyWJGH-7ewwHTHsNEmZuBPXaeTQvRVKfNDkV8Z7LfIWxRCCZdooZC&n=ZEhYBDFv208HJKEkNw5PqFObkm08aq7YeFB_fsGRbHtm2gx4mSx3JSwYkGZ1WU18bxwJPkfxXGKYv_KHdz1U8g&r=jfqeskceaKp8lH_i6JGe3T3xyBa6G7cbOCXOc4EPK3XMqLBHJqWBZEP0B9-qih8i&s=7226c2d05f1feec1a62ae2af2728e02cdefac54ea37a3a7665785b4a5864d360&u=https*3A*2F*2Fpitstop.powellind.com*2Fxfer*2Fbhub.cgi*3Fact*3Ddirect_download_file*26package_id*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*26file_name*3Dpowelldocmanager*2540powellind*252Ecom*255FO8FN5TMSR40O4R6VOBEQREUV86*252Ezip*26username*3Ddlarue*2540schmidt*252Delectric*252Ecom*26direct_token*3DB175D31C2AE80D9A572ED101DA29F438*26file_type*3Dzip__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!PsRMz_liT-2f!lyFBpyvRN69uTi9lGXPBKy-XSt-kz0C0JEORrqM8dMdi_IxvE9r1JFw4LyvspGoo--E3uM-bmu0c26FxoQqF$%3E"
                                        Imagebase:0x7ff7f9810000
                                        File size:3'242'272 bytes
                                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:12
                                        Start time:08:15:01
                                        Start date:30/09/2024
                                        Path:C:\Windows\System32\rundll32.exe
                                        Wow64 process (32bit):false
                                        Commandline:C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
                                        Imagebase:0x7ff7bb980000
                                        File size:71'680 bytes
                                        MD5 hash:EF3179D498793BF4234F708D3BE28633
                                        Has elevated privileges:false
                                        Has administrator privileges:false
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:13
                                        Start time:08:15:11
                                        Start date:30/09/2024
                                        Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Downloads\BJZFPPWAPT.docx" /o ""
                                        Imagebase:0x750000
                                        File size:1'620'872 bytes
                                        MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
                                        Has elevated privileges:false
                                        Has administrator privileges:false
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:19
                                        Start time:08:15:37
                                        Start date:30/09/2024
                                        Path:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
                                        Imagebase:0x7ff67bea0000
                                        File size:23'140'864 bytes
                                        MD5 hash:F963F75C0AD152437E10D656A00793A3
                                        Has elevated privileges:false
                                        Has administrator privileges:false
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        No disassembly