Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://84.116.6.21

Overview

General Information

Sample URL:http://84.116.6.21
Analysis ID:1523155
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2532,i,9202789991829421911,12762497972316314336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6336 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://84.116.6.21" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownTCP traffic detected without corresponding DNS query: 84.116.6.21
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 84.116.6.21Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/0@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2532,i,9202789991829421911,12762497972316314336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://84.116.6.21"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2532,i,9202789991829421911,12762497972316314336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://84.116.6.211%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://84.116.6.21/1%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    www.google.com
    142.250.184.228
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://84.116.6.21/falseunknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        84.116.6.21
        unknownNetherlands
        6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.184.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1523155
        Start date and time:2024-10-01 07:33:21 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 11s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://84.116.6.21
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@17/0@2/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.16.195, 216.58.206.46, 142.251.168.84, 34.104.35.123, 142.250.185.227, 142.250.185.195, 20.12.23.50, 199.232.214.172, 20.3.187.198, 192.229.221.95, 20.242.39.171, 172.217.23.99
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Oct 1, 2024 07:34:11.778295040 CEST49675443192.168.2.4173.222.162.32
        Oct 1, 2024 07:34:21.386707067 CEST49675443192.168.2.4173.222.162.32
        Oct 1, 2024 07:34:22.335367918 CEST4973580192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.335556030 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.340228081 CEST804973584.116.6.21192.168.2.4
        Oct 1, 2024 07:34:22.340255976 CEST804973684.116.6.21192.168.2.4
        Oct 1, 2024 07:34:22.340313911 CEST4973580192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.340389967 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.361196041 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.366002083 CEST804973684.116.6.21192.168.2.4
        Oct 1, 2024 07:34:22.959408998 CEST804973684.116.6.21192.168.2.4
        Oct 1, 2024 07:34:22.963769913 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.963844061 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:22.963965893 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.964248896 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:22.964267015 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:23.015404940 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:23.774439096 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:23.823504925 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.140222073 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.140261889 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:24.141503096 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:24.141566038 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.169199944 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.169527054 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:24.169620037 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.169713020 CEST49739443192.168.2.484.116.6.21
        Oct 1, 2024 07:34:24.169734955 CEST4434973984.116.6.21192.168.2.4
        Oct 1, 2024 07:34:24.496037006 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:24.496066093 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:24.496130943 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:24.497283936 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:24.497293949 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.158427954 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.158797026 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:25.158807039 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.159902096 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.159980059 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:25.183684111 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.183727980 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:25.183794022 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.185753107 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.185774088 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:25.338905096 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:25.339056015 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.387618065 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:25.387630939 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:25.433276892 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:25.826391935 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:25.826472044 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.853456020 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.853501081 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:25.853909016 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:25.903742075 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:25.979470015 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.023406029 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.274650097 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.274806023 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.274858952 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.667167902 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.667227030 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.667232990 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.667243958 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.843369007 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.843426943 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:26.843516111 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.843914032 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:26.843928099 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.505666018 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.505726099 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.590089083 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.590109110 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.590483904 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.594300032 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.639400005 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.786899090 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.786963940 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.787134886 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.788312912 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.788312912 CEST49743443192.168.2.4184.28.90.27
        Oct 1, 2024 07:34:27.788331032 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:27.788341045 CEST44349743184.28.90.27192.168.2.4
        Oct 1, 2024 07:34:35.051681995 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:35.051750898 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:35.051872969 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:36.058293104 CEST4972380192.168.2.4199.232.210.172
        Oct 1, 2024 07:34:36.063513041 CEST8049723199.232.210.172192.168.2.4
        Oct 1, 2024 07:34:36.063597918 CEST4972380192.168.2.4199.232.210.172
        Oct 1, 2024 07:34:36.748712063 CEST49741443192.168.2.4142.250.184.228
        Oct 1, 2024 07:34:36.748747110 CEST44349741142.250.184.228192.168.2.4
        Oct 1, 2024 07:34:52.868058920 CEST804973584.116.6.21192.168.2.4
        Oct 1, 2024 07:34:52.868155956 CEST4973580192.168.2.484.116.6.21
        Oct 1, 2024 07:34:52.954169989 CEST804973684.116.6.21192.168.2.4
        Oct 1, 2024 07:34:52.954245090 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:54.735560894 CEST4973580192.168.2.484.116.6.21
        Oct 1, 2024 07:34:54.735677004 CEST4973680192.168.2.484.116.6.21
        Oct 1, 2024 07:34:54.740396976 CEST804973584.116.6.21192.168.2.4
        Oct 1, 2024 07:34:54.740427971 CEST804973684.116.6.21192.168.2.4
        Oct 1, 2024 07:35:22.589493036 CEST4972480192.168.2.4199.232.210.172
        Oct 1, 2024 07:35:22.594554901 CEST8049724199.232.210.172192.168.2.4
        Oct 1, 2024 07:35:22.594611883 CEST4972480192.168.2.4199.232.210.172
        Oct 1, 2024 07:35:24.544015884 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:24.544084072 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:24.544260979 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:24.544594049 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:24.544606924 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:25.201678991 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:25.202056885 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:25.202073097 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:25.202471972 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:25.202908993 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:25.202996016 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:25.245565891 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:35.111733913 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:35.111849070 CEST44349752142.250.184.228192.168.2.4
        Oct 1, 2024 07:35:35.111895084 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:36.762720108 CEST49752443192.168.2.4142.250.184.228
        Oct 1, 2024 07:35:36.762765884 CEST44349752142.250.184.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Oct 1, 2024 07:34:20.156482935 CEST53511711.1.1.1192.168.2.4
        Oct 1, 2024 07:34:20.158565998 CEST53612081.1.1.1192.168.2.4
        Oct 1, 2024 07:34:21.273359060 CEST53546581.1.1.1192.168.2.4
        Oct 1, 2024 07:34:24.482600927 CEST5948053192.168.2.41.1.1.1
        Oct 1, 2024 07:34:24.486450911 CEST5390753192.168.2.41.1.1.1
        Oct 1, 2024 07:34:24.489603043 CEST53594801.1.1.1192.168.2.4
        Oct 1, 2024 07:34:24.492930889 CEST53539071.1.1.1192.168.2.4
        Oct 1, 2024 07:34:34.115417957 CEST138138192.168.2.4192.168.2.255
        Oct 1, 2024 07:34:38.665560961 CEST53510881.1.1.1192.168.2.4
        Oct 1, 2024 07:34:57.802597046 CEST53550341.1.1.1192.168.2.4
        Oct 1, 2024 07:35:19.961396933 CEST53596361.1.1.1192.168.2.4
        Oct 1, 2024 07:35:20.953913927 CEST53578361.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Oct 1, 2024 07:34:24.482600927 CEST192.168.2.41.1.1.10xe31Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Oct 1, 2024 07:34:24.486450911 CEST192.168.2.41.1.1.10x5f11Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Oct 1, 2024 07:34:24.489603043 CEST1.1.1.1192.168.2.40xe31No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
        Oct 1, 2024 07:34:24.492930889 CEST1.1.1.1192.168.2.40x5f11No error (0)www.google.com65IN (0x0001)false
        Oct 1, 2024 07:34:35.407416105 CEST1.1.1.1192.168.2.40xb4e9No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
        Oct 1, 2024 07:34:35.407416105 CEST1.1.1.1192.168.2.40xb4e9No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
        Oct 1, 2024 07:34:36.997956991 CEST1.1.1.1192.168.2.40x3482No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 1, 2024 07:34:36.997956991 CEST1.1.1.1192.168.2.40x3482No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Oct 1, 2024 07:34:53.786390066 CEST1.1.1.1192.168.2.40xa31aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 1, 2024 07:34:53.786390066 CEST1.1.1.1192.168.2.40xa31aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Oct 1, 2024 07:35:12.874237061 CEST1.1.1.1192.168.2.40x78a5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 1, 2024 07:35:12.874237061 CEST1.1.1.1192.168.2.40x78a5No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        Oct 1, 2024 07:35:33.207546949 CEST1.1.1.1192.168.2.40x4c80No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 1, 2024 07:35:33.207546949 CEST1.1.1.1192.168.2.40x4c80No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        • fs.microsoft.com
        • 84.116.6.21
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973684.116.6.21804544C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Oct 1, 2024 07:34:22.361196041 CEST426OUTGET / HTTP/1.1
        Host: 84.116.6.21
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Oct 1, 2024 07:34:22.959408998 CEST321INHTTP/1.1 301 Moved Permanently
        Content-Type: text/html
        Content-Length: 185
        Connection: keep-alive
        Location: https://84.116.6.21/
        Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 41 76 69 20 56 61 6e 74 61 67 65 2f 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
        Data Ascii: <html><head><title>301 Moved Permanently</title></head><body bgcolor="white"><center><h1>301 Moved Permanently</h1></center><hr><center>Avi Vantage/</center></body></html>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449742184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-10-01 05:34:25 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-10-01 05:34:26 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-neu-z1
        Cache-Control: public, max-age=213084
        Date: Tue, 01 Oct 2024 05:34:26 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449743184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-10-01 05:34:27 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-10-01 05:34:27 UTC515INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-weu-z1
        Cache-Control: public, max-age=213027
        Date: Tue, 01 Oct 2024 05:34:27 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-10-01 05:34:27 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:01:34:15
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:01:34:18
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2532,i,9202789991829421911,12762497972316314336,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:01:34:21
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://84.116.6.21"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly