Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://finalstepgo.com/uploads/beta9.zip

Overview

General Information

Sample URL:https://finalstepgo.com/uploads/beta9.zip
Analysis ID:1523570
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 3924 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1924,i,14654322300716869509,12622278140637358057,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://finalstepgo.com/uploads/beta9.zip" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.16:60211 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIkqHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=omMEF4aUzXBc213&MD=nXhxcus6 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: finalstepgo.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: classification engineClassification label: clean1.win@27/8@22/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1924,i,14654322300716869509,12622278140637358057,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://finalstepgo.com/uploads/beta9.zip"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1924,i,14654322300716869509,12622278140637358057,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1523570 URL: https://finalstepgo.com/upl... Startdate: 01/10/2024 Architecture: WINDOWS Score: 1 14 finalstepgo.com 2->14 6 chrome.exe 8 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.16, 443, 49701, 49707 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 172.217.16.196, 443, 49701 GOOGLEUS United States 11->20 22 google.com 11->22 24 finalstepgo.com 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.186.78
truefalse
    unknown
    www.google.com
    172.217.16.196
    truefalse
      unknown
      finalstepgo.com
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          172.217.16.196
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.16
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1523570
          Start date and time:2024-10-01 19:39:58 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 10s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsinteractivecookbook.jbs
          Sample URL:https://finalstepgo.com/uploads/beta9.zip
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:11
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean1.win@27/8@22/3
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 216.58.212.131, 142.250.74.206, 64.233.166.84, 34.104.35.123, 217.20.57.41
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: https://finalstepgo.com/uploads/beta9.zip
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 16:40:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2673
          Entropy (8bit):3.983247520027641
          Encrypted:false
          SSDEEP:48:8ddqTWyfHXZidAKZdA1FehwiZUklqehSy+3:8a7r1y
          MD5:D16DF2A7ACBB0D20C24FCE13B21002A5
          SHA1:E41E325EEF47610506D07D79CFEA375B3A338E6A
          SHA-256:9CDFDCA1B1CDCF283B0BA22E476FFA61951761BBF70897209945522D664C90E8
          SHA-512:FAE56CAA77DE86D7679DBE31E97AB544A8A39DD87F7CFD3BA062BBF128DC03FFFA330EC2302002F9E2E2636FE031B553241990A6BF1D22AA097177BBBAD7FB2E
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....7)..)...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 16:40:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2675
          Entropy (8bit):4.000645777116033
          Encrypted:false
          SSDEEP:48:8DjdqTWyfHXZidAKZdA1seh/iZUkAQkqehly+2:8Ds719Q4y
          MD5:B48329AB25B63870ECFDAAD6AE761955
          SHA1:63B2326C424CF606A0BFD433313B77CF573E3C96
          SHA-256:F8B41EDD04C86BF07FE4D15C6E564483BB0D1305F6DDCA4C17FF5510F2F9369A
          SHA-512:2B775B2C4AE242DE98FD8E27C5C29CEB43F17768EA710A77CBE2CF8937FB60C651710128174DAF2C6FA16E4C26A5C0388383FE38B2571944DCA59CE20EA4C883
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.......)...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2689
          Entropy (8bit):4.008891221504441
          Encrypted:false
          SSDEEP:48:8jdqTWyAHXZidAKZdA14meh7sFiZUkmgqeh7sry+BX:8s78npy
          MD5:1EE5F82F5195917CB7C50CFF62637BDE
          SHA1:7568EBBFD4A607DEFF1AF469F0D058F8BBB3E0AB
          SHA-256:59D9643299E1F0BE8A1D7F6C4F4B9FE98E299906FA6128CDA5F2584558F2FE97
          SHA-512:056A412321917CF18B2A33C3523F611D05982CBD5A873445A07B354F00DB287BCC7D1335BCD1EF6392382B698C39A9398FB686A2F5E304E0FCD74D27A55894F6
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 16:40:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9986710396197496
          Encrypted:false
          SSDEEP:48:8YdqTWyfHXZidAKZdA1TehDiZUkwqehRy+R:817mTy
          MD5:99163AFA4CD82CED503F6D77AF0B2E33
          SHA1:41AAED5EE8514380A8FCE78F64E9A27F929C07B5
          SHA-256:2A0EB5030A40D1BD2C5DECC3754631E75928663C4D727AE0BDA5C936998301A1
          SHA-512:0875CE96A162F943E7141F594F9B44ACDBA12180D6027A1DB693D1008689817E1F1C37EF2647031ECE9921B62736BD6D6C4C61D9BEF04DC9174CB353B0C52759
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....q..)...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 16:40:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9866391523530496
          Encrypted:false
          SSDEEP:48:8gdqTWyfHXZidAKZdA1dehBiZUk1W1qehfy+C:897G9/y
          MD5:B0A1F5ACB2E2D30D0EE18A7B403AF52A
          SHA1:D76FA17C3E8F2BBE8EA6B6A8DAAD7D435785E423
          SHA-256:B817187D6A1F0B49477CDEB3E2A6748B67761C7AEC455186A0025889F821E2DA
          SHA-512:AF138C4713F08A60247D516597E22F3827FDAE96608F14C9BD051B38270958EB8C1E7AB4600FA69E4B0FA6C7880D77BD29766A596F14D2D1E2DFB21C03D0DD6F
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,..... ..)...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 16:40:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.9973121575483694
          Encrypted:false
          SSDEEP:48:8GdqTWyfHXZidAKZdA1duTeehOuTbbiZUk5OjqehOuTbpy+yT+:8f78TfTbxWOvTbpy7T
          MD5:558C7BB26CEB22409954A2998A7D1FFA
          SHA1:4E1AB9A55A37BA4BDF6F1A6040F17D7AF86FC04E
          SHA-256:F45AAAF8F16E0CA15770A084C4B0473B4ACCAED86050D81B6982843B276A82BA
          SHA-512:495EBDD913D055160A22B70364E6887F1E98B7E395CBFEC8E3724B42878C7E193DE8939934A7730A02F346DC76197E1A020277D499460FF3F15B6A7EC246B694
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....:..)...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IAY......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VAY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VAY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VAY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VAY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............+b.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (754)
          Category:downloaded
          Size (bytes):759
          Entropy (8bit):5.10191259979367
          Encrypted:false
          SSDEEP:12:uAIlIsr7CirDaw6/BHslriFTAYsSw7sZAnIIIIIII5wuCPXIwuGHHHHHHHYZw4/4:hIW2ZrmdBHslgT9lCuABuoB7HHHHHHHJ
          MD5:D9C972AD61406B6C467A215AE964D95D
          SHA1:5F7F87E80F3A6DDF0065AECC08A328BD74C27FE5
          SHA-256:2A6BC24FD0F5ED1A742CF17B57DDF197E93D332004C733CC7F842E1E24FB83B9
          SHA-512:388704E21AB486BD67BD8D76D11BA62FE1E6ADE6EDA4DB110BF0643A738FF39E132C4937E95698918BFC7E1B6DFD8142D3BEEB45CE667EC5E74854A1C9F825B7
          Malicious:false
          Reputation:low
          URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
          Preview:)]}'.["",["college football rankings","nyt strands hints","q3 tesla deliveries","apple intelligence iphone 16","see comet a3","nyt crossword clues","football power rankings nfl","starfield shattered space dlc"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 1, 2024 19:40:31.276372910 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:31.580043077 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:32.186012983 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:32.419821978 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:32.419862032 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:32.419945955 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:32.420193911 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:32.420205116 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.062283039 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.062592030 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:33.062621117 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.063499928 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.063575029 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:33.065107107 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:33.065188885 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.109031916 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:33.109055996 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:33.157023907 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:33.390142918 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:34.044522047 CEST4968980192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:35.794048071 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:37.567011118 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:37.567045927 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:37.567138910 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:37.568564892 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:37.568579912 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.226227045 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:38.227068901 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.227170944 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.239044905 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.239065886 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.239434958 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.271411896 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:38.282145977 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.287956953 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.335401058 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.432565928 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:38.433581114 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:38.433654070 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:38.434575081 CEST49701443192.168.2.16172.217.16.196
          Oct 1, 2024 19:40:38.434593916 CEST44349701172.217.16.196192.168.2.16
          Oct 1, 2024 19:40:38.502882004 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.502939939 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.502991915 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.503082991 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.503082991 CEST49707443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.503104925 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.503113985 CEST44349707184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.540549994 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.540599108 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:38.540676117 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.540920019 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:38.540942907 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.178838968 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.178940058 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.180093050 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.180105925 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.180344105 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.181468010 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.227421045 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.448584080 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:39.455245018 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.455322981 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.455391884 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.456048965 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.456083059 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.456110954 CEST49708443192.168.2.16184.28.90.27
          Oct 1, 2024 19:40:39.456120968 CEST44349708184.28.90.27192.168.2.16
          Oct 1, 2024 19:40:39.751096964 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:40.102035999 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.102082968 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:40.102168083 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.103336096 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.103349924 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:40.357132912 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:40.597745895 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:40.896677971 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:40.896755934 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.899569035 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.899588108 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:40.899988890 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:40.947101116 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.956672907 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:40.999404907 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227652073 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227680922 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227689981 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227701902 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227741003 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.227787018 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.227804899 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.228156090 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.228156090 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.228403091 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.228481054 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.228486061 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.228622913 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.228677988 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.239914894 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.239938974 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.239948988 CEST49709443192.168.2.1620.114.59.183
          Oct 1, 2024 19:40:41.239954948 CEST4434970920.114.59.183192.168.2.16
          Oct 1, 2024 19:40:41.568069935 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:43.919219017 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:43.983102083 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:44.223118067 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:44.830151081 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:46.043128967 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:48.451117992 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:48.787215948 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:40:50.207169056 CEST49673443192.168.2.16204.79.197.203
          Oct 1, 2024 19:40:53.266207933 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:40:58.393244028 CEST49678443192.168.2.1620.189.173.10
          Oct 1, 2024 19:41:02.876240969 CEST4968080192.168.2.16192.229.211.108
          Oct 1, 2024 19:41:08.823954105 CEST6021153192.168.2.161.1.1.1
          Oct 1, 2024 19:41:08.828777075 CEST53602111.1.1.1192.168.2.16
          Oct 1, 2024 19:41:08.828938007 CEST6021153192.168.2.161.1.1.1
          Oct 1, 2024 19:41:08.828938007 CEST6021153192.168.2.161.1.1.1
          Oct 1, 2024 19:41:08.833745003 CEST53602111.1.1.1192.168.2.16
          Oct 1, 2024 19:41:09.280503035 CEST53602111.1.1.1192.168.2.16
          Oct 1, 2024 19:41:09.281416893 CEST6021153192.168.2.161.1.1.1
          Oct 1, 2024 19:41:09.290124893 CEST53602111.1.1.1192.168.2.16
          Oct 1, 2024 19:41:09.290308952 CEST6021153192.168.2.161.1.1.1
          TimestampSource PortDest PortSource IPDest IP
          Oct 1, 2024 19:40:27.645509005 CEST53618041.1.1.1192.168.2.16
          Oct 1, 2024 19:40:27.673321009 CEST53577681.1.1.1192.168.2.16
          Oct 1, 2024 19:40:28.486149073 CEST6472553192.168.2.161.1.1.1
          Oct 1, 2024 19:40:28.486371994 CEST6284553192.168.2.161.1.1.1
          Oct 1, 2024 19:40:28.496690035 CEST53628451.1.1.1192.168.2.16
          Oct 1, 2024 19:40:28.497925997 CEST53647251.1.1.1192.168.2.16
          Oct 1, 2024 19:40:28.498522997 CEST4990253192.168.2.161.1.1.1
          Oct 1, 2024 19:40:28.530272007 CEST53499021.1.1.1192.168.2.16
          Oct 1, 2024 19:40:28.560626984 CEST5452253192.168.2.168.8.8.8
          Oct 1, 2024 19:40:28.561218977 CEST6418253192.168.2.161.1.1.1
          Oct 1, 2024 19:40:28.568506956 CEST53641821.1.1.1192.168.2.16
          Oct 1, 2024 19:40:28.569287062 CEST53545228.8.8.8192.168.2.16
          Oct 1, 2024 19:40:28.717904091 CEST53648531.1.1.1192.168.2.16
          Oct 1, 2024 19:40:29.577024937 CEST6505953192.168.2.161.1.1.1
          Oct 1, 2024 19:40:29.577162027 CEST5511753192.168.2.161.1.1.1
          Oct 1, 2024 19:40:29.673763990 CEST53551171.1.1.1192.168.2.16
          Oct 1, 2024 19:40:29.809654951 CEST53650591.1.1.1192.168.2.16
          Oct 1, 2024 19:40:32.410881996 CEST5753553192.168.2.161.1.1.1
          Oct 1, 2024 19:40:32.411047935 CEST5380653192.168.2.161.1.1.1
          Oct 1, 2024 19:40:32.418317080 CEST53575351.1.1.1192.168.2.16
          Oct 1, 2024 19:40:32.418972969 CEST53538061.1.1.1192.168.2.16
          Oct 1, 2024 19:40:34.829304934 CEST5265253192.168.2.161.1.1.1
          Oct 1, 2024 19:40:34.829483986 CEST5897553192.168.2.161.1.1.1
          Oct 1, 2024 19:40:34.841836929 CEST53589751.1.1.1192.168.2.16
          Oct 1, 2024 19:40:34.842292070 CEST53526521.1.1.1192.168.2.16
          Oct 1, 2024 19:40:34.843053102 CEST5989853192.168.2.161.1.1.1
          Oct 1, 2024 19:40:34.852209091 CEST53598981.1.1.1192.168.2.16
          Oct 1, 2024 19:40:45.717953920 CEST53505691.1.1.1192.168.2.16
          Oct 1, 2024 19:40:49.790102959 CEST5210153192.168.2.161.1.1.1
          Oct 1, 2024 19:40:49.790266991 CEST5875953192.168.2.161.1.1.1
          Oct 1, 2024 19:40:49.801469088 CEST53587591.1.1.1192.168.2.16
          Oct 1, 2024 19:40:49.824568033 CEST53521011.1.1.1192.168.2.16
          Oct 1, 2024 19:40:49.825330973 CEST5868453192.168.2.161.1.1.1
          Oct 1, 2024 19:40:49.837692976 CEST53586841.1.1.1192.168.2.16
          Oct 1, 2024 19:40:49.846635103 CEST4984653192.168.2.161.1.1.1
          Oct 1, 2024 19:40:49.846941948 CEST5853953192.168.2.168.8.8.8
          Oct 1, 2024 19:40:49.853985071 CEST53585398.8.8.8192.168.2.16
          Oct 1, 2024 19:40:49.855912924 CEST53498461.1.1.1192.168.2.16
          Oct 1, 2024 19:40:50.851736069 CEST6496453192.168.2.161.1.1.1
          Oct 1, 2024 19:40:50.851866007 CEST5790653192.168.2.161.1.1.1
          Oct 1, 2024 19:40:51.232024908 CEST53649641.1.1.1192.168.2.16
          Oct 1, 2024 19:40:51.233074903 CEST53579061.1.1.1192.168.2.16
          Oct 1, 2024 19:40:56.244482994 CEST6429353192.168.2.161.1.1.1
          Oct 1, 2024 19:40:56.244726896 CEST5208553192.168.2.161.1.1.1
          Oct 1, 2024 19:40:56.255490065 CEST53642931.1.1.1192.168.2.16
          Oct 1, 2024 19:40:56.255691051 CEST53520851.1.1.1192.168.2.16
          Oct 1, 2024 19:40:56.256392002 CEST5772053192.168.2.161.1.1.1
          Oct 1, 2024 19:40:56.267154932 CEST53577201.1.1.1192.168.2.16
          Oct 1, 2024 19:41:04.766398907 CEST53526061.1.1.1192.168.2.16
          Oct 1, 2024 19:41:08.823431969 CEST53539291.1.1.1192.168.2.16
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 1, 2024 19:40:28.486149073 CEST192.168.2.161.1.1.10x51b4Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.486371994 CEST192.168.2.161.1.1.10xd9b2Standard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:28.498522997 CEST192.168.2.161.1.1.10x20f9Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.560626984 CEST192.168.2.168.8.8.80x273aStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.561218977 CEST192.168.2.161.1.1.10x79f3Standard query (0)google.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:29.577024937 CEST192.168.2.161.1.1.10x9f70Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:29.577162027 CEST192.168.2.161.1.1.10xa91eStandard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:32.410881996 CEST192.168.2.161.1.1.10xa473Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:32.411047935 CEST192.168.2.161.1.1.10x1712Standard query (0)www.google.com65IN (0x0001)false
          Oct 1, 2024 19:40:34.829304934 CEST192.168.2.161.1.1.10x32e6Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:34.829483986 CEST192.168.2.161.1.1.10x854bStandard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:34.843053102 CEST192.168.2.161.1.1.10xd069Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.790102959 CEST192.168.2.161.1.1.10x4ea6Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.790266991 CEST192.168.2.161.1.1.10x3b13Standard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:49.825330973 CEST192.168.2.161.1.1.10x89d5Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.846635103 CEST192.168.2.161.1.1.10xe58dStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.846941948 CEST192.168.2.168.8.8.80x1419Standard query (0)google.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:50.851736069 CEST192.168.2.161.1.1.10x430aStandard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:50.851866007 CEST192.168.2.161.1.1.10x3283Standard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:56.244482994 CEST192.168.2.161.1.1.10xd58eStandard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:56.244726896 CEST192.168.2.161.1.1.10xe77eStandard query (0)finalstepgo.com65IN (0x0001)false
          Oct 1, 2024 19:40:56.256392002 CEST192.168.2.161.1.1.10x78c5Standard query (0)finalstepgo.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 1, 2024 19:40:28.496690035 CEST1.1.1.1192.168.2.160xd9b2Name error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:28.497925997 CEST1.1.1.1192.168.2.160x51b4Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.530272007 CEST1.1.1.1192.168.2.160x20f9Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.568506956 CEST1.1.1.1192.168.2.160x79f3No error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:28.569287062 CEST8.8.8.8192.168.2.160x273aNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:29.673763990 CEST1.1.1.1192.168.2.160xa91eName error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:29.809654951 CEST1.1.1.1192.168.2.160x9f70Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:32.418317080 CEST1.1.1.1192.168.2.160xa473No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:32.418972969 CEST1.1.1.1192.168.2.160x1712No error (0)www.google.com65IN (0x0001)false
          Oct 1, 2024 19:40:34.841836929 CEST1.1.1.1192.168.2.160x854bName error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:34.842292070 CEST1.1.1.1192.168.2.160x32e6Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:34.852209091 CEST1.1.1.1192.168.2.160xd069Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.801469088 CEST1.1.1.1192.168.2.160x3b13Name error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:49.824568033 CEST1.1.1.1192.168.2.160x4ea6Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.837692976 CEST1.1.1.1192.168.2.160x89d5Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.853985071 CEST8.8.8.8192.168.2.160x1419No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:49.855912924 CEST1.1.1.1192.168.2.160xe58dNo error (0)google.com142.250.185.238A (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:51.232024908 CEST1.1.1.1192.168.2.160x430aName error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:51.233074903 CEST1.1.1.1192.168.2.160x3283Name error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:56.255490065 CEST1.1.1.1192.168.2.160xd58eName error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          Oct 1, 2024 19:40:56.255691051 CEST1.1.1.1192.168.2.160xe77eName error (3)finalstepgo.comnonenone65IN (0x0001)false
          Oct 1, 2024 19:40:56.267154932 CEST1.1.1.1192.168.2.160x78c5Name error (3)finalstepgo.comnonenoneA (IP address)IN (0x0001)false
          • www.google.com
          • fs.microsoft.com
          • slscr.update.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.1649701172.217.16.1964436756C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-10-01 17:40:38 UTC613OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
          Host: www.google.com
          Connection: keep-alive
          X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIkqHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUX
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: empty
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-10-01 17:40:38 UTC1266INHTTP/1.1 200 OK
          Date: Tue, 01 Oct 2024 17:40:38 GMT
          Pragma: no-cache
          Expires: -1
          Cache-Control: no-cache, must-revalidate
          Content-Type: text/javascript; charset=UTF-8
          Strict-Transport-Security: max-age=31536000
          Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-d2X9doZAjF3wCZkD4DKs8Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
          Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
          Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
          Accept-CH: Sec-CH-Prefers-Color-Scheme
          Accept-CH: Sec-CH-UA-Form-Factors
          Accept-CH: Sec-CH-UA-Platform
          Accept-CH: Sec-CH-UA-Platform-Version
          Accept-CH: Sec-CH-UA-Full-Version
          Accept-CH: Sec-CH-UA-Arch
          Accept-CH: Sec-CH-UA-Model
          Accept-CH: Sec-CH-UA-Bitness
          Accept-CH: Sec-CH-UA-Full-Version-List
          Accept-CH: Sec-CH-UA-WoW64
          Permissions-Policy: unload=()
          Content-Disposition: attachment; filename="f.txt"
          Server: gws
          X-XSS-Protection: 0
          X-Frame-Options: SAMEORIGIN
          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
          Accept-Ranges: none
          Vary: Accept-Encoding
          Connection: close
          Transfer-Encoding: chunked
          2024-10-01 17:40:38 UTC124INData Raw: 32 66 37 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 63 6f 6c 6c 65 67 65 20 66 6f 6f 74 62 61 6c 6c 20 72 61 6e 6b 69 6e 67 73 22 2c 22 6e 79 74 20 73 74 72 61 6e 64 73 20 68 69 6e 74 73 22 2c 22 71 33 20 74 65 73 6c 61 20 64 65 6c 69 76 65 72 69 65 73 22 2c 22 61 70 70 6c 65 20 69 6e 74 65 6c 6c 69 67 65 6e 63 65 20 69 70 68 6f 6e 65 20 31 36 22 2c 22 73 65 65 20 63 6f 6d
          Data Ascii: 2f7)]}'["",["college football rankings","nyt strands hints","q3 tesla deliveries","apple intelligence iphone 16","see com
          2024-10-01 17:40:38 UTC642INData Raw: 65 74 20 61 33 22 2c 22 6e 79 74 20 63 72 6f 73 73 77 6f 72 64 20 63 6c 75 65 73 22 2c 22 66 6f 6f 74 62 61 6c 6c 20 70 6f 77 65 72 20 72 61 6e 6b 69 6e 67 73 20 6e 66 6c 22 2c 22 73 74 61 72 66 69 65 6c 64 20 73 68 61 74 74 65 72 65 64 20 73 70 61 63 65 20 64 6c 63 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70 73 69 6e 66 6f 22 3a 22 43 68 67 49 6b 6b 34 53 45 77 6f 52 56 48 4a 6c 62 6d 52 70 62 6d 63 67 63 32 56 68 63 6d 4e 6f 5a 58 4d 5c 75 30 30 33 64 22 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 64 65 74 61 69 6c 22 3a
          Data Ascii: et a3","nyt crossword clues","football power rankings nfl","starfield shattered space dlc"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":
          2024-10-01 17:40:38 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.1649707184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-01 17:40:38 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-01 17:40:38 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-neu-z1
          Cache-Control: public, max-age=169512
          Date: Tue, 01 Oct 2024 17:40:38 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.1649708184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-01 17:40:39 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-01 17:40:39 UTC515INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=169455
          Date: Tue, 01 Oct 2024 17:40:39 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-10-01 17:40:39 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.164970920.114.59.183443
          TimestampBytes transferredDirectionData
          2024-10-01 17:40:40 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=omMEF4aUzXBc213&MD=nXhxcus6 HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
          Host: slscr.update.microsoft.com
          2024-10-01 17:40:41 UTC560INHTTP/1.1 200 OK
          Cache-Control: no-cache
          Pragma: no-cache
          Content-Type: application/octet-stream
          Expires: -1
          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
          ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
          MS-CorrelationId: 430c8898-6e51-4ecd-a634-4dbd37a470a4
          MS-RequestId: cba65107-0c1d-4506-ad5e-5547380d42e4
          MS-CV: U79in84S8ku8NeD8.0
          X-Microsoft-SLSClientCache: 2880
          Content-Disposition: attachment; filename=environment.cab
          X-Content-Type-Options: nosniff
          Date: Tue, 01 Oct 2024 17:40:40 GMT
          Connection: close
          Content-Length: 24490
          2024-10-01 17:40:41 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
          Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
          2024-10-01 17:40:41 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
          Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:13:40:26
          Start date:01/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:13:40:26
          Start date:01/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1924,i,14654322300716869509,12622278140637358057,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:13:40:27
          Start date:01/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://finalstepgo.com/uploads/beta9.zip"
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly