Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb

Overview

General Information

Sample URL:http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb
Analysis ID:1523494
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1980,i,16119807065340329461,17326420478589508304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.5:62699 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb HTTP/1.1Host: arzr0cs.vzeuudtjkrdnxhbtt.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb HTTP/1.1Host: arzr0cs.vzeuudtjkrdnxhbtt.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: arzr0cs.vzeuudtjkrdnxhbtt.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: hjky.cbwjvddifgpouc8ju.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62705
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 62705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean1.win@20/6@22/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1980,i,16119807065340329461,17326420478589508304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1980,i,16119807065340329461,17326420478589508304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    google.com
    142.250.184.206
    truefalse
      unknown
      arzr0cs.vzeuudtjkrdnxhbtt.com
      94.156.64.140
      truefalse
        unknown
        www.google.com
        142.250.186.36
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            241.42.69.40.in-addr.arpa
            unknown
            unknownfalse
              unknown
              hjky.cbwjvddifgpouc8ju.com
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksbfalse
                  unknown
                  https://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksbfalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.186.36
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    94.156.64.140
                    arzr0cs.vzeuudtjkrdnxhbtt.comBulgaria
                    31420TERASYST-ASBGfalse
                    172.217.16.196
                    unknownUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.6
                    192.168.2.5
                    Joe Sandbox version:41.0.0 Charoite
                    Analysis ID:1523494
                    Start date and time:2024-10-01 17:22:36 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 0s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean1.win@20/6@22/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 74.125.133.84, 172.217.18.14, 142.250.184.195, 34.104.35.123, 13.85.23.86, 199.232.214.172, 192.229.221.95, 13.85.23.206, 20.242.39.171, 40.69.42.241, 4.175.87.197, 142.250.186.163
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:23:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2677
                    Entropy (8bit):3.9841923625881384
                    Encrypted:false
                    SSDEEP:48:8MdATkQCH1idAKZdA19ehwiZUklqehYgy+3:8Pv8fgy
                    MD5:ADA53548C9722786AD7DA19EEE46E722
                    SHA1:45C247120374133FB42BA8D8380BE91EF0FE9FCB
                    SHA-256:3D65D09E0533B4B1922633D705329817321489BACDC91A7144A8E56FCCC73D39
                    SHA-512:51E0D89BCBF83EC2F9813580980207A345F24696730051FDFFBC918B62B5F233B7DB1D60408BC27878B2B964402F47F61DC0C3794756489631B6F44AE8F9AD1A
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:23:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2679
                    Entropy (8bit):3.9975082934212858
                    Encrypted:false
                    SSDEEP:48:8xdATkQCH1idAKZdA1weh/iZUkAQkqehPgy+2:8svO9Qagy
                    MD5:E6DB8D96386020BBBFC7D8FA231253FD
                    SHA1:8E3E442B54D151718BCA8B00A1A608C3C011A97D
                    SHA-256:13A6496AD8BFB59624364FAA806D39D9A67F93FADA7E85475BEE3999B78D8416
                    SHA-512:0F06AC9F72CE2B6E37703599DD86700827DFD694BBAE55C47819E7615EF6DE10F3518F142EC35EA31E10CD9ED2449A0A39871F5BD93EA091FCE2DA910CBD46E0
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....'.......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2693
                    Entropy (8bit):4.008310640231874
                    Encrypted:false
                    SSDEEP:48:8xxdATkQsH1idAKZdA14tseh7sFiZUkmgqeh7sxgy+BX:8xsvknDgy
                    MD5:D775C30D38E50C3B67F4251ADD744C25
                    SHA1:0D15FB37D101BCCF7BF22886CDAC4C013C2610B0
                    SHA-256:70067252301D67AEE1A754A111EDD8AF0DDC41DE4B64EB6ED31F9D5E33A75B05
                    SHA-512:9C545E034C333D374D14F547333343FC56AA68B9B4E0127CFEED653664F06AC3E55F1CB557764F43B9E3A57D8F54A7A36282D7DD53738DA1808FE6597CFBD1E2
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:23:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.9958190954574366
                    Encrypted:false
                    SSDEEP:48:8HdATkQCH1idAKZdA1vehDiZUkwqehbgy+R:8OvVJgy
                    MD5:B08C0F2BC95ECC6A58612AE37094CF45
                    SHA1:604EEC4409CDB89E6D462077F32D2066ABA58CA5
                    SHA-256:6E84BAA9FFB100951395A8B3F90E6CE9D0FAEAF899C0C9017EF34E8AF9A72028
                    SHA-512:D8AAE407CA9A5C9426F11E538BB1E7B9A9D22CC4A062677292E30EE146E9286F17E1F314DA8204F8C80A30BC27DDC5AB09F648C2AEE5450A9E9C8941ABAAB9B8
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.....,......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:23:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.985469428735985
                    Encrypted:false
                    SSDEEP:48:8vdATkQCH1idAKZdA1hehBiZUk1W1qeh1gy+C:8WvF9Vgy
                    MD5:16FF7F5F088F50AFDE9496F4201DD837
                    SHA1:8825F12AB691DECB28F70A8BEE0AC2BAC80D2518
                    SHA-256:C0BBFD8E894EBAC90E48B30D8ACC1E13D6DE4C39547B470316912D0DE4343264
                    SHA-512:F4D4DB2AC9C7F04CDBDD39F8F9AF12B0BFDAF99D0C32DBD6C69406849E53C8745B96EFFAE6A90BBDF7FA10902FB3C2E2218F1ECD5506CD11C7609E3D2CEB9A1A
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....{.......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:23:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2683
                    Entropy (8bit):3.9944063724971746
                    Encrypted:false
                    SSDEEP:48:8mdATkQCH1idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbDgy+yT+:8tvZT/TbxWOvTbDgy7T
                    MD5:4A4344E634F6C95B33C1C64319C81DB6
                    SHA1:49CF0A81D1340F05F31DEEA3EE5EC9D580C447C8
                    SHA-256:65A576CEB036F01A07540E885115EF482B68B6BE85EB6FBE5C21CBF0EFB9699D
                    SHA-512:E0896623FBF17A676EA40FB26CC19BD829FB356FADB27354BCE05C354344F044B4B2C9D39A6CC05F62811D04338CC15EFABDD56BEC334612A3135F775A5C438D
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.....c......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IAY.z....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 1, 2024 17:23:21.883044004 CEST49674443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:21.883071899 CEST49675443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:21.992438078 CEST49673443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:31.555949926 CEST49674443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:31.649657011 CEST49675443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:31.649667978 CEST49673443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:32.972249985 CEST4970980192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:32.972723007 CEST4971080192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:32.977073908 CEST804970994.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:32.977188110 CEST4970980192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:32.977376938 CEST4970980192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:32.977510929 CEST804971094.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:32.977579117 CEST4971080192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:32.982501030 CEST804970994.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:33.272239923 CEST4434970323.1.237.91192.168.2.5
                    Oct 1, 2024 17:23:33.272365093 CEST49703443192.168.2.523.1.237.91
                    Oct 1, 2024 17:23:33.635245085 CEST804970994.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:33.674902916 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:33.674973965 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:33.675055981 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:33.675559998 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:33.675596952 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:33.678527117 CEST4970980192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.493237972 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:34.539571047 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.628314972 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.628330946 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:34.629903078 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:34.629995108 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.640358925 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.640455961 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:34.641540051 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.641557932 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:34.682678938 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:34.711599112 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:34.711641073 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:34.711864948 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:34.715406895 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:34.715425014 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:35.415601015 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:35.462114096 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:35.538727999 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:35.538737059 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:35.542782068 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:35.542870045 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:35.873945951 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:35.873956919 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:35.874133110 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:35.877211094 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:35.877221107 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.095484018 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:36.095891953 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:36.149755955 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:36.149776936 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:36.199197054 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:36.516983986 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.517097950 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.525000095 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.525017023 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.525250912 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.572838068 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.664877892 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.711410999 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.849589109 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.849838972 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.849922895 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.866282940 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.866295099 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.866377115 CEST49715443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.866381884 CEST44349715184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.914813995 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.914829969 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:36.914910078 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.915968895 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:36.915982962 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.550151110 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.550228119 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.551798105 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.551803112 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.552042961 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.553188086 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.595448017 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.598711014 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:37.598903894 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:37.599030018 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:37.599265099 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:37.599283934 CEST4434971394.156.64.140192.168.2.5
                    Oct 1, 2024 17:23:37.599298954 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:37.599363089 CEST49713443192.168.2.594.156.64.140
                    Oct 1, 2024 17:23:37.825937033 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.826001883 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.826191902 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.829420090 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.829430103 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:37.829441071 CEST49716443192.168.2.5184.28.90.27
                    Oct 1, 2024 17:23:37.829446077 CEST44349716184.28.90.27192.168.2.5
                    Oct 1, 2024 17:23:45.293879986 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:45.293952942 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:45.294058084 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:45.344306946 CEST49714443192.168.2.5142.250.186.36
                    Oct 1, 2024 17:23:45.344341040 CEST44349714142.250.186.36192.168.2.5
                    Oct 1, 2024 17:23:59.267656088 CEST6269953192.168.2.5162.159.36.2
                    Oct 1, 2024 17:23:59.272852898 CEST5362699162.159.36.2192.168.2.5
                    Oct 1, 2024 17:23:59.272922993 CEST6269953192.168.2.5162.159.36.2
                    Oct 1, 2024 17:23:59.273030043 CEST6269953192.168.2.5162.159.36.2
                    Oct 1, 2024 17:23:59.278114080 CEST5362699162.159.36.2192.168.2.5
                    Oct 1, 2024 17:23:59.726653099 CEST5362699162.159.36.2192.168.2.5
                    Oct 1, 2024 17:23:59.727309942 CEST6269953192.168.2.5162.159.36.2
                    Oct 1, 2024 17:23:59.732357025 CEST5362699162.159.36.2192.168.2.5
                    Oct 1, 2024 17:23:59.732413054 CEST6269953192.168.2.5162.159.36.2
                    Oct 1, 2024 17:24:17.983853102 CEST4971080192.168.2.594.156.64.140
                    Oct 1, 2024 17:24:17.988900900 CEST804971094.156.64.140192.168.2.5
                    Oct 1, 2024 17:24:18.642600060 CEST4970980192.168.2.594.156.64.140
                    Oct 1, 2024 17:24:18.647500038 CEST804970994.156.64.140192.168.2.5
                    Oct 1, 2024 17:24:33.308716059 CEST4971080192.168.2.594.156.64.140
                    Oct 1, 2024 17:24:33.314138889 CEST804971094.156.64.140192.168.2.5
                    Oct 1, 2024 17:24:33.314219952 CEST4971080192.168.2.594.156.64.140
                    Oct 1, 2024 17:24:34.772406101 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:34.772433043 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:34.772505999 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:34.772798061 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:34.772814989 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:35.402972937 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:35.404025078 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:35.404040098 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:35.404393911 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:35.404939890 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:35.405004025 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:35.447123051 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:46.062489986 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:46.062586069 CEST44362705172.217.16.196192.168.2.5
                    Oct 1, 2024 17:24:46.062648058 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:47.566303015 CEST62705443192.168.2.5172.217.16.196
                    Oct 1, 2024 17:24:47.566329002 CEST44362705172.217.16.196192.168.2.5
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 1, 2024 17:23:30.858999968 CEST53598431.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:31.055510044 CEST53504501.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:32.033279896 CEST53577031.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:32.922506094 CEST5086353192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:32.922758102 CEST6204753192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:32.956322908 CEST53508631.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:33.104300022 CEST53620471.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:33.638472080 CEST6470853192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:33.638636112 CEST6219953192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:33.672780991 CEST53621991.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:33.674067020 CEST53647081.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:34.701493979 CEST6061253192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:34.702425003 CEST5121353192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:34.708847046 CEST53606121.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:34.709309101 CEST53512131.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:37.748833895 CEST5407753192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:37.748981953 CEST5609353192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:37.759233952 CEST53540771.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:37.759301901 CEST53560931.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:37.761548996 CEST5161453192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:37.921277046 CEST53516141.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:38.099971056 CEST5003253192.168.2.58.8.8.8
                    Oct 1, 2024 17:23:38.106837988 CEST53500328.8.8.8192.168.2.5
                    Oct 1, 2024 17:23:38.109515905 CEST5645553192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:38.116225004 CEST53564551.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:39.114675999 CEST6120553192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:39.115123987 CEST5713853192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:39.126727104 CEST53612051.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:39.127353907 CEST53571381.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:39.169392109 CEST5108953192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:39.169827938 CEST6412053192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:39.179636955 CEST53510891.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:39.181727886 CEST53641201.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:44.209358931 CEST5494653192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:44.209696054 CEST6242253192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:44.240175009 CEST53624221.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:44.246102095 CEST53549461.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:44.247354031 CEST6377953192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:44.259516954 CEST53637791.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:49.115770102 CEST53493131.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:57.244600058 CEST5553853192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:57.254686117 CEST53555381.1.1.1192.168.2.5
                    Oct 1, 2024 17:23:59.266967058 CEST5351720162.159.36.2192.168.2.5
                    Oct 1, 2024 17:23:59.740016937 CEST5829553192.168.2.51.1.1.1
                    Oct 1, 2024 17:23:59.747116089 CEST53582951.1.1.1192.168.2.5
                    Oct 1, 2024 17:24:14.501085043 CEST6208253192.168.2.51.1.1.1
                    Oct 1, 2024 17:24:14.511868954 CEST53620821.1.1.1192.168.2.5
                    Oct 1, 2024 17:24:34.762089968 CEST5174853192.168.2.51.1.1.1
                    Oct 1, 2024 17:24:34.771321058 CEST53517481.1.1.1192.168.2.5
                    TimestampSource IPDest IPChecksumCodeType
                    Oct 1, 2024 17:23:33.104387999 CEST192.168.2.51.1.1.1c23a(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Oct 1, 2024 17:23:32.922506094 CEST192.168.2.51.1.1.10x2e13Standard query (0)arzr0cs.vzeuudtjkrdnxhbtt.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:32.922758102 CEST192.168.2.51.1.1.10x785dStandard query (0)arzr0cs.vzeuudtjkrdnxhbtt.com65IN (0x0001)false
                    Oct 1, 2024 17:23:33.638472080 CEST192.168.2.51.1.1.10x3ecdStandard query (0)arzr0cs.vzeuudtjkrdnxhbtt.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:33.638636112 CEST192.168.2.51.1.1.10x6019Standard query (0)arzr0cs.vzeuudtjkrdnxhbtt.com65IN (0x0001)false
                    Oct 1, 2024 17:23:34.701493979 CEST192.168.2.51.1.1.10xe779Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:34.702425003 CEST192.168.2.51.1.1.10xcdb4Standard query (0)www.google.com65IN (0x0001)false
                    Oct 1, 2024 17:23:37.748833895 CEST192.168.2.51.1.1.10x8621Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:37.748981953 CEST192.168.2.51.1.1.10x356Standard query (0)hjky.cbwjvddifgpouc8ju.com65IN (0x0001)false
                    Oct 1, 2024 17:23:37.761548996 CEST192.168.2.51.1.1.10x1b41Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:38.099971056 CEST192.168.2.58.8.8.80xb446Standard query (0)google.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:38.109515905 CEST192.168.2.51.1.1.10x6b72Standard query (0)google.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.114675999 CEST192.168.2.51.1.1.10x1fb1Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.115123987 CEST192.168.2.51.1.1.10x344cStandard query (0)hjky.cbwjvddifgpouc8ju.com65IN (0x0001)false
                    Oct 1, 2024 17:23:39.169392109 CEST192.168.2.51.1.1.10x55baStandard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.169827938 CEST192.168.2.51.1.1.10x3321Standard query (0)hjky.cbwjvddifgpouc8ju.com65IN (0x0001)false
                    Oct 1, 2024 17:23:44.209358931 CEST192.168.2.51.1.1.10xbf9bStandard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:44.209696054 CEST192.168.2.51.1.1.10x9af8Standard query (0)hjky.cbwjvddifgpouc8ju.com65IN (0x0001)false
                    Oct 1, 2024 17:23:44.247354031 CEST192.168.2.51.1.1.10xf373Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:57.244600058 CEST192.168.2.51.1.1.10xcd48Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:59.740016937 CEST192.168.2.51.1.1.10x32c6Standard query (0)241.42.69.40.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                    Oct 1, 2024 17:24:14.501085043 CEST192.168.2.51.1.1.10x7d33Standard query (0)hjky.cbwjvddifgpouc8ju.comA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:24:34.762089968 CEST192.168.2.51.1.1.10x98dcStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Oct 1, 2024 17:23:32.956322908 CEST1.1.1.1192.168.2.50x2e13No error (0)arzr0cs.vzeuudtjkrdnxhbtt.com94.156.64.140A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:33.674067020 CEST1.1.1.1192.168.2.50x3ecdNo error (0)arzr0cs.vzeuudtjkrdnxhbtt.com94.156.64.140A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:34.708847046 CEST1.1.1.1192.168.2.50xe779No error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:34.709309101 CEST1.1.1.1192.168.2.50xcdb4No error (0)www.google.com65IN (0x0001)false
                    Oct 1, 2024 17:23:37.759233952 CEST1.1.1.1192.168.2.50x8621Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:37.759301901 CEST1.1.1.1192.168.2.50x356Name error (3)hjky.cbwjvddifgpouc8ju.comnonenone65IN (0x0001)false
                    Oct 1, 2024 17:23:37.921277046 CEST1.1.1.1192.168.2.50x1b41Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:38.106837988 CEST8.8.8.8192.168.2.50xb446No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:38.116225004 CEST1.1.1.1192.168.2.50x6b72No error (0)google.com142.250.74.206A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.126727104 CEST1.1.1.1192.168.2.50x1fb1Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.127353907 CEST1.1.1.1192.168.2.50x344cName error (3)hjky.cbwjvddifgpouc8ju.comnonenone65IN (0x0001)false
                    Oct 1, 2024 17:23:39.179636955 CEST1.1.1.1192.168.2.50x55baName error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:39.181727886 CEST1.1.1.1192.168.2.50x3321Name error (3)hjky.cbwjvddifgpouc8ju.comnonenone65IN (0x0001)false
                    Oct 1, 2024 17:23:42.627199888 CEST1.1.1.1192.168.2.50xc5f7No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:42.627199888 CEST1.1.1.1192.168.2.50xc5f7No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:43.144521952 CEST1.1.1.1192.168.2.50xa3e6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Oct 1, 2024 17:23:43.144521952 CEST1.1.1.1192.168.2.50xa3e6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:44.240175009 CEST1.1.1.1192.168.2.50x9af8Name error (3)hjky.cbwjvddifgpouc8ju.comnonenone65IN (0x0001)false
                    Oct 1, 2024 17:23:44.246102095 CEST1.1.1.1192.168.2.50xbf9bName error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:44.259516954 CEST1.1.1.1192.168.2.50xf373Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:57.254686117 CEST1.1.1.1192.168.2.50xcd48Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:23:59.747116089 CEST1.1.1.1192.168.2.50x32c6Name error (3)241.42.69.40.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
                    Oct 1, 2024 17:24:14.511868954 CEST1.1.1.1192.168.2.50x7d33Name error (3)hjky.cbwjvddifgpouc8ju.comnonenoneA (IP address)IN (0x0001)false
                    Oct 1, 2024 17:24:34.771321058 CEST1.1.1.1192.168.2.50x98dcNo error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                    • arzr0cs.vzeuudtjkrdnxhbtt.com
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.54970994.156.64.140803504C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Oct 1, 2024 17:23:32.977376938 CEST504OUTGET /sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb HTTP/1.1
                    Host: arzr0cs.vzeuudtjkrdnxhbtt.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Oct 1, 2024 17:23:33.635245085 CEST367INHTTP/1.1 302 Found
                    Content-Type: text/html; charset=utf-8
                    Location: https://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb
                    Date: Tue, 01 Oct 2024 15:23:33 GMT
                    Content-Length: 137
                    Data Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 7a 72 30 63 73 2e 76 7a 65 75 75 64 74 6a 6b 72 64 6e 78 68 62 74 74 2e 63 6f 6d 2f 73 78 37 39 65 71 69 32 69 26 61 6d 70 3b 66 75 6e 77 3d 71 70 70 6e 62 68 79 26 61 6d 70 3b 61 6a 73 68 64 70 76 3d 6b 62 68 73 26 61 6d 70 3b 74 78 6a 76 76 3d 6b 6a 7a 71 7a 63 26 61 6d 70 3b 64 74 66 7a 6f 69 69 3d 6b 73 62 22 3e 46 6f 75 6e 64 3c 2f 61 3e 2e 0a 0a
                    Data Ascii: <a href="https://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&amp;funw=qppnbhy&amp;ajshdpv=kbhs&amp;txjvv=kjzqzc&amp;dtfzoii=ksb">Found</a>.
                    Oct 1, 2024 17:24:18.642600060 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.54971094.156.64.140803504C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Oct 1, 2024 17:24:17.983853102 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.54971394.156.64.1404433504C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-10-01 15:23:34 UTC732OUTGET /sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb HTTP/1.1
                    Host: arzr0cs.vzeuudtjkrdnxhbtt.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-10-01 15:23:37 UTC196INHTTP/1.1 301 Moved Permanently
                    Content-Type: text/html; charset=utf-8
                    Location: https://HJKY.cbWJvddifgpoUC8Ju.com
                    Date: Tue, 01 Oct 2024 15:23:37 GMT
                    Content-Length: 69
                    Connection: close
                    2024-10-01 15:23:37 UTC69INData Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 48 4a 4b 59 2e 63 62 57 4a 76 64 64 69 66 67 70 6f 55 43 38 4a 75 2e 63 6f 6d 22 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 61 3e 2e 0a 0a
                    Data Ascii: <a href="https://HJKY.cbWJvddifgpoUC8Ju.com">Moved Permanently</a>.


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.549715184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-10-01 15:23:36 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-10-01 15:23:36 UTC467INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF06)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-neu-z1
                    Cache-Control: public, max-age=177734
                    Date: Tue, 01 Oct 2024 15:23:36 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.549716184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-10-01 15:23:37 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-10-01 15:23:37 UTC515INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF06)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-weu-z1
                    Cache-Control: public, max-age=177677
                    Date: Tue, 01 Oct 2024 15:23:37 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-10-01 15:23:37 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:11:23:24
                    Start date:01/10/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:11:23:28
                    Start date:01/10/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1980,i,16119807065340329461,17326420478589508304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:11:23:31
                    Start date:01/10/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://arzr0cs.vzeuudtjkrdnxhbtt.com/sx79eqi2i&funw=qppnbhy&ajshdpv=kbhs&txjvv=kjzqzc&dtfzoii=ksb"
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly