Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=

Overview

General Information

Sample URL:https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=
Analysis ID:1522883
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sample execution stops while process was sleeping (likely an evasion)

Classification

  • System is w10x64
  • chrome.exe (PID: 4488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5956 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2312 --field-trial-handle=2252,i,14552223768429205743,11696779005299206885,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6404 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • conhost.exe (PID: 6476 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /l/scl/AAAiUVuCI4dTxpcgYHWxCPf= HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gvc=MTMyNDc1MzI1NDQ0MDk3NTY5NzcwOTQ5MTQ3MTgwMzc0OTQzMTAw; t=ORwbf7CoyxPx4jMIdoxcmX0E; __Host-js_csrf=ORwbf7CoyxPx4jMIdoxcmX0E; __Host-ss=QLu8zKyDrg; locale=en
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.dropbox.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundStrict-Transport-Security: max-age=31536000; includeSubDomainsContent-Length: 1233Content-Type: text/htmlDate: Mon, 30 Sep 2024 17:56:18 GMTServer: envoyCache-Control: no-cache, no-storeVary: Accept-EncodingX-Dropbox-Response-Origin: remoteX-Dropbox-Request-Id: 9032f8eabee8450396ee348f4c9e4fb4Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/0@4/4
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:6476:120:WilError_03
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2312 --field-trial-handle=2252,i,14552223768429205743,11696779005299206885,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2312 --field-trial-handle=2252,i,14552223768429205743,11696779005299206885,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www-env.dropbox-dns.com
162.125.66.18
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        www.dropbox.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://www.dropbox.com/favicon.icofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            162.125.66.18
            www-env.dropbox-dns.comUnited States
            19679DROPBOXUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1522883
            Start date and time:2024-09-30 19:55:16 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 58s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/0@4/4
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 173.194.76.84, 142.250.184.238, 216.58.206.67, 34.104.35.123, 13.85.23.86, 88.221.110.91, 2.16.100.168, 192.229.221.95, 13.85.23.206, 40.69.42.241, 172.217.18.3
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Sep 30, 2024 19:56:05.299355984 CEST49675443192.168.2.4173.222.162.32
            Sep 30, 2024 19:56:14.939729929 CEST49675443192.168.2.4173.222.162.32
            Sep 30, 2024 19:56:16.894249916 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.894296885 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:16.894382000 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.894432068 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.894505978 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:16.894613981 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.894906998 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.894925117 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:16.895042896 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:16.895060062 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.551285028 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.551295996 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.551645041 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.551681995 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.551785946 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.551810026 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.552776098 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.552850962 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.552856922 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.552917957 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.555402040 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.555483103 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.555834055 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.555908918 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.555946112 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.555954933 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.595714092 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.595730066 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:17.595778942 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:17.642807007 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.096213102 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.096241951 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.096288919 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.096302986 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.096374989 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.103718042 CEST49736443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.103740931 CEST44349736162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.196182966 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:18.196232080 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:18.196301937 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:18.206588984 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:18.206605911 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:18.281115055 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.327400923 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.567564964 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.567651987 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.567707062 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.592231035 CEST49735443192.168.2.4162.125.66.18
            Sep 30, 2024 19:56:18.592294931 CEST44349735162.125.66.18192.168.2.4
            Sep 30, 2024 19:56:18.844652891 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:18.845386982 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:18.845412970 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:18.846532106 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:18.846678972 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:19.120335102 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:19.120533943 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:19.175831079 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:19.175858021 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:19.222405910 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:20.205152988 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.205193996 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:20.205252886 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.209973097 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.209991932 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:20.849370003 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:20.849456072 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.853014946 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.853025913 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:20.853275061 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:20.891402960 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:20.935405016 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.123909950 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.124037981 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.124221087 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.168643951 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.168643951 CEST49740443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.168675900 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.168684959 CEST44349740184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.287276983 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.287319899 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.287417889 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.288707972 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.288722992 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.932037115 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.932111025 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.934704065 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.934711933 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.934943914 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:21.937165976 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:21.983396053 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:22.357799053 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:22.357850075 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:22.357913017 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:22.358751059 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:22.358772039 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:22.358784914 CEST49741443192.168.2.4184.28.90.27
            Sep 30, 2024 19:56:22.358793020 CEST44349741184.28.90.27192.168.2.4
            Sep 30, 2024 19:56:28.773228884 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:28.773395061 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:28.773523092 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:29.098782063 CEST49739443192.168.2.4142.250.186.100
            Sep 30, 2024 19:56:29.098830938 CEST44349739142.250.186.100192.168.2.4
            Sep 30, 2024 19:56:29.604160070 CEST4972380192.168.2.4199.232.210.172
            Sep 30, 2024 19:56:29.609250069 CEST8049723199.232.210.172192.168.2.4
            Sep 30, 2024 19:56:29.609508991 CEST4972380192.168.2.4199.232.210.172
            Sep 30, 2024 19:57:17.629726887 CEST4972480192.168.2.4199.232.210.172
            Sep 30, 2024 19:57:17.636826038 CEST8049724199.232.210.172192.168.2.4
            Sep 30, 2024 19:57:17.636934996 CEST4972480192.168.2.4199.232.210.172
            Sep 30, 2024 19:57:18.053493023 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:18.053541899 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.053610086 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:18.054248095 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:18.054260969 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.695061922 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.695440054 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:18.695456028 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.695772886 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.696999073 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:18.697056055 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:18.746994019 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:28.597290039 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:28.597366095 CEST44349750142.250.186.100192.168.2.4
            Sep 30, 2024 19:57:28.597429037 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:29.098550081 CEST49750443192.168.2.4142.250.186.100
            Sep 30, 2024 19:57:29.098613024 CEST44349750142.250.186.100192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Sep 30, 2024 19:56:14.871464968 CEST53513581.1.1.1192.168.2.4
            Sep 30, 2024 19:56:14.873486042 CEST53499221.1.1.1192.168.2.4
            Sep 30, 2024 19:56:15.874524117 CEST53512681.1.1.1192.168.2.4
            Sep 30, 2024 19:56:16.865295887 CEST5303953192.168.2.41.1.1.1
            Sep 30, 2024 19:56:16.865463018 CEST5967753192.168.2.41.1.1.1
            Sep 30, 2024 19:56:16.872922897 CEST53530391.1.1.1192.168.2.4
            Sep 30, 2024 19:56:16.873541117 CEST53596771.1.1.1192.168.2.4
            Sep 30, 2024 19:56:18.008490086 CEST5037953192.168.2.41.1.1.1
            Sep 30, 2024 19:56:18.008634090 CEST6246753192.168.2.41.1.1.1
            Sep 30, 2024 19:56:18.099298000 CEST53624671.1.1.1192.168.2.4
            Sep 30, 2024 19:56:18.099566936 CEST53503791.1.1.1192.168.2.4
            Sep 30, 2024 19:56:29.235574961 CEST138138192.168.2.4192.168.2.255
            Sep 30, 2024 19:56:33.059169054 CEST53508231.1.1.1192.168.2.4
            Sep 30, 2024 19:56:52.025362015 CEST53620821.1.1.1192.168.2.4
            Sep 30, 2024 19:57:14.049704075 CEST53529691.1.1.1192.168.2.4
            Sep 30, 2024 19:57:14.780854940 CEST53546861.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Sep 30, 2024 19:56:16.865295887 CEST192.168.2.41.1.1.10xa2e2Standard query (0)www.dropbox.comA (IP address)IN (0x0001)false
            Sep 30, 2024 19:56:16.865463018 CEST192.168.2.41.1.1.10x4874Standard query (0)www.dropbox.com65IN (0x0001)false
            Sep 30, 2024 19:56:18.008490086 CEST192.168.2.41.1.1.10x26aeStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Sep 30, 2024 19:56:18.008634090 CEST192.168.2.41.1.1.10x3059Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Sep 30, 2024 19:56:16.872922897 CEST1.1.1.1192.168.2.40xa2e2No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:56:16.872922897 CEST1.1.1.1192.168.2.40xa2e2No error (0)www-env.dropbox-dns.com162.125.66.18A (IP address)IN (0x0001)false
            Sep 30, 2024 19:56:16.873541117 CEST1.1.1.1192.168.2.40x4874No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:56:18.099298000 CEST1.1.1.1192.168.2.40x3059No error (0)www.google.com65IN (0x0001)false
            Sep 30, 2024 19:56:18.099566936 CEST1.1.1.1192.168.2.40x26aeNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
            Sep 30, 2024 19:56:31.063087940 CEST1.1.1.1192.168.2.40xd67No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:56:31.063087940 CEST1.1.1.1192.168.2.40xd67No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Sep 30, 2024 19:56:43.341353893 CEST1.1.1.1192.168.2.40x8435No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:56:43.341353893 CEST1.1.1.1192.168.2.40x8435No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Sep 30, 2024 19:57:07.147980928 CEST1.1.1.1192.168.2.40x23fcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:57:07.147980928 CEST1.1.1.1192.168.2.40x23fcNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Sep 30, 2024 19:57:27.278657913 CEST1.1.1.1192.168.2.40x20b8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Sep 30, 2024 19:57:27.278657913 CEST1.1.1.1192.168.2.40x20b8No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • www.dropbox.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449736162.125.66.184435956C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-09-30 17:56:17 UTC688OUTGET /l/scl/AAAiUVuCI4dTxpcgYHWxCPf= HTTP/1.1
            Host: www.dropbox.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-09-30 17:56:18 UTC3369INHTTP/1.1 200 OK
            Content-Type: image/jpeg
            Content-Security-Policy: base-uri 'self' ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; connect-src https://* ws://127.0.0.1:*/ws blob: wss://dsimports.dropbox.com/ ; default-src 'none' ; font-src https://* data: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; frame-src https://* carousel: dbapi-6 [TRUNCATED]
            Content-Security-Policy: report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-QBBAl5m2sT1mtTrqcLSe' 'nonce-oi+9GpvYo6vKuH9KneCI'
            Referrer-Policy: strict-origin-when-cross-origin
            Set-Cookie: gvc=MTMyNDc1MzI1NDQ0MDk3NTY5NzcwOTQ5MTQ3MTgwMzc0OTQzMTAw; expires=Sat, 29 Sep 2029 17:56:17 GMT; HttpOnly; Path=/; SameSite=None; Secure
            Set-Cookie: t=ORwbf7CoyxPx4jMIdoxcmX0E; Domain=dropbox.com; expires=Tue, 30 Sep 2025 17:56:17 GMT; HttpOnly; Path=/; SameSite=None; Secure
            Set-Cookie: __Host-js_csrf=ORwbf7CoyxPx4jMIdoxcmX0E; expires=Tue, 30 Sep 2025 17:56:17 GMT; Path=/; SameSite=None; Secure
            Set-Cookie: __Host-ss=QLu8zKyDrg; expires=Tue, 30 Sep 2025 17:56:17 GMT; HttpOnly; Path=/; SameSite=Strict; Secure
            Set-Cookie: locale=en; Domain=dropbox.com; expires=Sat, 29 Sep 2029 17:56:17 GMT; Path=/; SameSite=None; Secure
            X-Content-Type-Options: nosniff
            X-Frame-Options: SAMEORIGIN
            X-Permitted-Cross-Domain-Policies: none
            X-Server-Response-Time: 10
            X-Xss-Protection: 1; mode=block
            Date: Mon, 30 Sep 2024 17:56:17 GMT
            Server: envoy
            Strict-Transport-Security: max-age=31536000; includeSubDomains
            Strict-Transport-Security: max-age=31536000; includeSubDomains
            Cache-Control: no-cache, no-store
            X-Dropbox-Response-Origin: far_remote
            X-Dropbox-Request-Id: f0be16d5938641fc81e50b7257215a57
            Connection: close
            Transfer-Encoding: chunked
            2024-09-30 17:56:18 UTC643INData Raw: 32 37 37 0d 0a ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff db 00 43 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff c0 00 11 08 00 01 00 01 03 01 22 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14
            Data Ascii: 277JFIFCC"}!1AQa"q


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735162.125.66.184435956C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-09-30 17:56:18 UTC784OUTGET /favicon.ico HTTP/1.1
            Host: www.dropbox.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf=
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: gvc=MTMyNDc1MzI1NDQ0MDk3NTY5NzcwOTQ5MTQ3MTgwMzc0OTQzMTAw; t=ORwbf7CoyxPx4jMIdoxcmX0E; __Host-js_csrf=ORwbf7CoyxPx4jMIdoxcmX0E; __Host-ss=QLu8zKyDrg; locale=en
            2024-09-30 17:56:18 UTC357INHTTP/1.1 404 Not Found
            Strict-Transport-Security: max-age=31536000; includeSubDomains
            Content-Length: 1233
            Content-Type: text/html
            Date: Mon, 30 Sep 2024 17:56:18 GMT
            Server: envoy
            Cache-Control: no-cache, no-store
            Vary: Accept-Encoding
            X-Dropbox-Response-Origin: remote
            X-Dropbox-Request-Id: 9032f8eabee8450396ee348f4c9e4fb4
            Connection: close
            2024-09-30 17:56:18 UTC1233INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 44 72 6f 70 62 6f 78 20 2d 20 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 66 6c 2e 64 72 6f 70 62 6f 78 73 74 61 74 69 63 2e 63 6f 6d 2f 73 74 61 74 69 63 2f 6d 65 74 61 73 65 72 76 65
            Data Ascii: <!DOCTYPE html><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Dropbox - 404</title><link href="https://cfl.dropboxstatic.com/static/metaserve


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449740184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-09-30 17:56:20 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-09-30 17:56:21 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=254969
            Date: Mon, 30 Sep 2024 17:56:21 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449741184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-09-30 17:56:21 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-09-30 17:56:22 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=254912
            Date: Mon, 30 Sep 2024 17:56:22 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-09-30 17:56:22 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:13:56:08
            Start date:30/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:13:56:12
            Start date:30/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2312 --field-trial-handle=2252,i,14552223768429205743,11696779005299206885,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:13:56:16
            Start date:30/09/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AAAiUVuCI4dTxpcgYHWxCPf="
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:6
            Start time:13:56:30
            Start date:30/09/2024
            Path:C:\Windows\System32\conhost.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Imagebase:0x7ff7699e0000
            File size:862'208 bytes
            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
            Has elevated privileges:true
            Has administrator privileges:false
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly