Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js

Overview

General Information

Sample URL:https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js
Analysis ID:1531785
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1984,i,10761925805992295681,2982968312306074604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 41.63.96.0
Source: unknownTCP traffic detected without corresponding DNS query: 41.63.96.0
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /a215683d2d0ce8fecd54e01b99606d75/invoke.js HTTP/1.1Host: zqvee2re50mr.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: zqvee2re50mr.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.21.6Date: Fri, 11 Oct 2024 18:22:18 GMTContent-Type: application/javascriptContent-Length: 0Connection: closeP3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"Access-Control-Allow-Origin: *Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,Sec-CH-UA-PlatformUser-Agent,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UAHost: zqvee2re50mr.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@17/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1984,i,10761925805992295681,2982968312306074604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1984,i,10761925805992295681,2982968312306074604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.181.228
truefalse
    unknown
    zqvee2re50mr.com
    185.196.197.71
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.jsfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.181.228
          www.google.comUnited States
          15169GOOGLEUSfalse
          185.196.197.71
          zqvee2re50mr.comNetherlands
          34554ANTANETAntaresKommunikationstechnikAGCHfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1531785
          Start date and time:2024-10-11 20:21:19 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 54s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:5
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown0.win@17/0@4/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 216.58.206.67, 142.250.184.206, 74.125.133.84, 34.104.35.123, 52.149.20.212, 88.221.110.91, 2.16.100.168, 40.69.42.241, 192.229.221.95
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 11, 2024 20:22:15.536777973 CEST49675443192.168.2.4173.222.162.32
          Oct 11, 2024 20:22:17.778704882 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.778738976 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:17.778821945 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.779367924 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.779388905 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:17.779800892 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.779840946 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:17.779902935 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.780272007 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:17.780289888 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.572117090 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.575397015 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.575427055 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.577054024 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.577168941 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.578727007 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.578824043 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.578840971 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.592607021 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.623420000 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.630522013 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.630538940 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.636795998 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.674586058 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.755947113 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.756134033 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.756232023 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.830485106 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.830509901 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.834161043 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.834264994 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.878808022 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.879106998 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.884979010 CEST49736443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.885004044 CEST44349736185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.923121929 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:18.923136950 CEST44349735185.196.197.71192.168.2.4
          Oct 11, 2024 20:22:18.976872921 CEST49735443192.168.2.4185.196.197.71
          Oct 11, 2024 20:22:20.232186079 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.232279062 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.232377052 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.232572079 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.232613087 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.884258032 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.884795904 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.884854078 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.886504889 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.886590958 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.887654066 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.887752056 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:20.957930088 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:20.957995892 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:21.005902052 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:21.388883114 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:21.388928890 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:21.389009953 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:21.391190052 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:21.391206980 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.111800909 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.111900091 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.116163969 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.116193056 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.116616011 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.159053087 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.199493885 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.870512009 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.870671988 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.871010065 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.871010065 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.871010065 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.871100903 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.903115034 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.903203964 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:22.903316021 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.903650045 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:22.903707981 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.097942114 CEST49741443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.098006964 CEST44349741184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.599304914 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.599487066 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.600789070 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.600843906 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.601192951 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.602437973 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.643431902 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.930037975 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.930198908 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:23.931047916 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.931047916 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:23.931047916 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:24.238846064 CEST49742443192.168.2.4184.28.90.27
          Oct 11, 2024 20:22:24.238909960 CEST44349742184.28.90.27192.168.2.4
          Oct 11, 2024 20:22:31.004457951 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:31.004549026 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:31.004692078 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:32.882129908 CEST49740443192.168.2.4142.250.181.228
          Oct 11, 2024 20:22:32.882178068 CEST44349740142.250.181.228192.168.2.4
          Oct 11, 2024 20:22:33.203098059 CEST804972341.63.96.0192.168.2.4
          Oct 11, 2024 20:22:33.203257084 CEST4972380192.168.2.441.63.96.0
          Oct 11, 2024 20:22:33.203505039 CEST4972380192.168.2.441.63.96.0
          Oct 11, 2024 20:22:33.208307028 CEST804972341.63.96.0192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Oct 11, 2024 20:22:16.857887983 CEST53544801.1.1.1192.168.2.4
          Oct 11, 2024 20:22:16.858644009 CEST53538341.1.1.1192.168.2.4
          Oct 11, 2024 20:22:17.737364054 CEST6092753192.168.2.41.1.1.1
          Oct 11, 2024 20:22:17.737777948 CEST4978753192.168.2.41.1.1.1
          Oct 11, 2024 20:22:17.766853094 CEST53609271.1.1.1192.168.2.4
          Oct 11, 2024 20:22:17.800868034 CEST53497871.1.1.1192.168.2.4
          Oct 11, 2024 20:22:17.838068962 CEST53636271.1.1.1192.168.2.4
          Oct 11, 2024 20:22:20.223898888 CEST6455753192.168.2.41.1.1.1
          Oct 11, 2024 20:22:20.224036932 CEST5700753192.168.2.41.1.1.1
          Oct 11, 2024 20:22:20.231185913 CEST53645571.1.1.1192.168.2.4
          Oct 11, 2024 20:22:20.231278896 CEST53570071.1.1.1192.168.2.4
          Oct 11, 2024 20:22:33.683582067 CEST138138192.168.2.4192.168.2.255
          TimestampSource IPDest IPChecksumCodeType
          Oct 11, 2024 20:22:17.800947905 CEST192.168.2.41.1.1.1c22a(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 11, 2024 20:22:17.737364054 CEST192.168.2.41.1.1.10x4b83Standard query (0)zqvee2re50mr.comA (IP address)IN (0x0001)false
          Oct 11, 2024 20:22:17.737777948 CEST192.168.2.41.1.1.10x31b5Standard query (0)zqvee2re50mr.com65IN (0x0001)false
          Oct 11, 2024 20:22:20.223898888 CEST192.168.2.41.1.1.10xad0eStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 11, 2024 20:22:20.224036932 CEST192.168.2.41.1.1.10x76cfStandard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 11, 2024 20:22:17.766853094 CEST1.1.1.1192.168.2.40x4b83No error (0)zqvee2re50mr.com185.196.197.71A (IP address)IN (0x0001)false
          Oct 11, 2024 20:22:17.766853094 CEST1.1.1.1192.168.2.40x4b83No error (0)zqvee2re50mr.com185.196.197.72A (IP address)IN (0x0001)false
          Oct 11, 2024 20:22:20.231185913 CEST1.1.1.1192.168.2.40xad0eNo error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
          Oct 11, 2024 20:22:20.231278896 CEST1.1.1.1192.168.2.40x76cfNo error (0)www.google.com65IN (0x0001)false
          Oct 11, 2024 20:22:31.574651957 CEST1.1.1.1192.168.2.40x9efeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Oct 11, 2024 20:22:31.574651957 CEST1.1.1.1192.168.2.40x9efeNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
          • zqvee2re50mr.com
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449736185.196.197.714433548C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-10-11 18:22:18 UTC701OUTGET /a215683d2d0ce8fecd54e01b99606d75/invoke.js HTTP/1.1
          Host: zqvee2re50mr.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-10-11 18:22:18 UTC564INHTTP/1.1 403 Forbidden
          Server: nginx/1.21.6
          Date: Fri, 11 Oct 2024 18:22:18 GMT
          Content-Type: application/javascript
          Content-Length: 0
          Connection: close
          P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
          Access-Control-Allow-Origin: *
          Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,Sec-CH-UA-PlatformUser-Agent,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UA
          Host: zqvee2re50mr.com


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449741184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-11 18:22:22 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-11 18:22:22 UTC466INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF70)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=80581
          Date: Fri, 11 Oct 2024 18:22:22 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.449742184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-11 18:22:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-11 18:22:23 UTC514INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=80611
          Date: Fri, 11 Oct 2024 18:22:23 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-10-11 18:22:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:14:22:10
          Start date:11/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:14:22:14
          Start date:11/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1984,i,10761925805992295681,2982968312306074604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:14:22:16
          Start date:11/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://zqvee2re50mr.com/a215683d2d0ce8fecd54e01b99606d75/invoke.js"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly