Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://notification.3ds.com

Overview

General Information

Sample URL:http://notification.3ds.com
Analysis ID:1524412
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2692 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,16326268064856790536,10505784510517347814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6452 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notification.3ds.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: notification.3ds.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: notification.3ds.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: notification.3ds.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@18/0@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,16326268064856790536,10505784510517347814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notification.3ds.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,16326268064856790536,10505784510517347814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    notification.3ds.com
    192.243.228.1
    truefalse
      unknown
      www.google.com
      142.250.186.164
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://notification.3ds.com/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            192.243.228.1
            notification.3ds.comUnited States
            15224OMNITUREUSfalse
            142.250.186.164
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.13
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1524412
            Start date and time:2024-10-02 18:28:18 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 15s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://notification.3ds.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@18/0@4/5
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.195, 142.250.186.78, 108.177.15.84, 34.104.35.123, 20.114.59.183, 199.232.210.172, 192.229.221.95, 20.242.39.171, 52.165.164.15
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://notification.3ds.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 18:29:15.506751060 CEST4973980192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:15.507129908 CEST4974080192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:15.512517929 CEST8049739192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:15.512638092 CEST4973980192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:15.512828112 CEST4973980192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:15.513226986 CEST8049740192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:15.513303041 CEST4974080192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:15.519949913 CEST8049739192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:17.465017080 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:17.465079069 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:17.465150118 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:17.465572119 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:17.465596914 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.129683971 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.129960060 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:18.129986048 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.131108046 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.131170988 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:18.318545103 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:18.318572998 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:18.318629026 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:18.320266008 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:18.320276022 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:18.344388008 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:18.344566107 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.384758949 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:18.384824038 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:18.432704926 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:19.188980103 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.189161062 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.200844049 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.200860977 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.201308966 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.254892111 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.348275900 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.391412020 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.676568031 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.676649094 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.676764011 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.676795006 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.676810026 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.676810026 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.676816940 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.676822901 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.717231035 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.717308044 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:19.717396975 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.717647076 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:19.717680931 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.378259897 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.378338099 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:20.381201029 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:20.381217957 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.381555080 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.384713888 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:20.427395105 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.658127069 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.658201933 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:20.658771992 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:20.660244942 CEST49745443192.168.2.4184.28.90.27
            Oct 2, 2024 18:29:20.660267115 CEST44349745184.28.90.27192.168.2.4
            Oct 2, 2024 18:29:28.021770000 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:28.021836996 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:28.021881104 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:29.884124994 CEST49743443192.168.2.4142.250.186.164
            Oct 2, 2024 18:29:29.884149075 CEST44349743142.250.186.164192.168.2.4
            Oct 2, 2024 18:29:36.875355959 CEST8049739192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:36.875421047 CEST4973980192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:36.875844002 CEST4973980192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:36.880656004 CEST8049739192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:36.907422066 CEST8049740192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:36.907497883 CEST4974080192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:37.066493034 CEST4974080192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:37.072107077 CEST8049740192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:38.457340002 CEST4975280192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:38.458503008 CEST4975380192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:38.651727915 CEST8049752192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:38.651746988 CEST8049753192.243.228.1192.168.2.4
            Oct 2, 2024 18:29:38.651820898 CEST4975280192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:38.651854038 CEST4975380192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:38.683417082 CEST4975380192.168.2.4192.243.228.1
            Oct 2, 2024 18:29:38.689372063 CEST8049753192.243.228.1192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 18:29:13.618261099 CEST53595801.1.1.1192.168.2.4
            Oct 2, 2024 18:29:13.645009995 CEST53527401.1.1.1192.168.2.4
            Oct 2, 2024 18:29:14.824654102 CEST53545821.1.1.1192.168.2.4
            Oct 2, 2024 18:29:15.485457897 CEST5191953192.168.2.41.1.1.1
            Oct 2, 2024 18:29:15.485524893 CEST6546753192.168.2.41.1.1.1
            Oct 2, 2024 18:29:15.505994081 CEST53654671.1.1.1192.168.2.4
            Oct 2, 2024 18:29:15.506007910 CEST53519191.1.1.1192.168.2.4
            Oct 2, 2024 18:29:17.449157000 CEST6544553192.168.2.41.1.1.1
            Oct 2, 2024 18:29:17.451431036 CEST6289053192.168.2.41.1.1.1
            Oct 2, 2024 18:29:17.459331036 CEST53654451.1.1.1192.168.2.4
            Oct 2, 2024 18:29:17.463217974 CEST53628901.1.1.1192.168.2.4
            Oct 2, 2024 18:29:31.192655087 CEST138138192.168.2.4192.168.2.255
            Oct 2, 2024 18:29:31.980712891 CEST53618371.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 2, 2024 18:29:15.485457897 CEST192.168.2.41.1.1.10x914aStandard query (0)notification.3ds.comA (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:15.485524893 CEST192.168.2.41.1.1.10xc410Standard query (0)notification.3ds.com65IN (0x0001)false
            Oct 2, 2024 18:29:17.449157000 CEST192.168.2.41.1.1.10xd786Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:17.451431036 CEST192.168.2.41.1.1.10xf4c5Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 2, 2024 18:29:15.506007910 CEST1.1.1.1192.168.2.40x914aNo error (0)notification.3ds.com192.243.228.1A (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:17.459331036 CEST1.1.1.1192.168.2.40xd786No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:17.463217974 CEST1.1.1.1192.168.2.40xf4c5No error (0)www.google.com65IN (0x0001)false
            Oct 2, 2024 18:29:27.953394890 CEST1.1.1.1192.168.2.40xa8f4No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:27.953394890 CEST1.1.1.1192.168.2.40xa8f4No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:29.420098066 CEST1.1.1.1192.168.2.40xc5d9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 18:29:29.420098066 CEST1.1.1.1192.168.2.40xc5d9No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Oct 2, 2024 18:29:41.704189062 CEST1.1.1.1192.168.2.40x6efaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 18:29:41.704189062 CEST1.1.1.1192.168.2.40x6efaNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • notification.3ds.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449739192.243.228.1802692C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 2, 2024 18:29:15.512828112 CEST435OUTGET / HTTP/1.1
            Host: notification.3ds.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449753192.243.228.1802692C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 2, 2024 18:29:38.683417082 CEST461OUTGET / HTTP/1.1
            Host: notification.3ds.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449744184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 16:29:19 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 16:29:19 UTC466INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=87391
            Date: Wed, 02 Oct 2024 16:29:19 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449745184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 16:29:20 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 16:29:20 UTC514INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=87334
            Date: Wed, 02 Oct 2024 16:29:20 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-02 16:29:20 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:12:29:09
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:12:29:11
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,16326268064856790536,10505784510517347814,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:12:29:14
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notification.3ds.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly