Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://casadosvidrosmt.com.br

Overview

General Information

Sample URL:http://casadosvidrosmt.com.br
Analysis ID:1533053
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 1216 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3868 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,13301791348897924422,11942280521383577736,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6384 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://casadosvidrosmt.com.br" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://casadosvidrosmt.com.brVirustotal: Detection: 17%Perma Link
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: casadosvidrosmt.com.brConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: casadosvidrosmt.com.brConnection: keep-aliveCache-Control: max-age=0Authorization: Basic Og==Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: casadosvidrosmt.com.br
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,13301791348897924422,11942280521383577736,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://casadosvidrosmt.com.br"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,13301791348897924422,11942280521383577736,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://casadosvidrosmt.com.br18%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    172.217.18.4
    truefalse
      unknown
      casadosvidrosmt.com.br
      108.179.192.119
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://casadosvidrosmt.com.br/true
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            108.179.192.119
            casadosvidrosmt.com.brUnited States
            46606UNIFIEDLAYER-AS-1USfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            172.217.18.4
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1533053
            Start date and time:2024-10-14 11:14:15 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 3s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://casadosvidrosmt.com.br
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@18/0@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.131, 142.250.185.174, 173.194.76.84, 34.104.35.123, 4.175.87.197, 199.232.210.172, 192.229.221.95, 13.85.23.206
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 14, 2024 11:15:14.526545048 CEST49675443192.168.2.4173.222.162.32
            Oct 14, 2024 11:15:17.912487030 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:17.912765980 CEST4973680192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:17.917538881 CEST8049735108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:17.917601109 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:17.917638063 CEST8049736108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:17.917692900 CEST4973680192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:17.917841911 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:17.922600985 CEST8049735108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:18.432610989 CEST8049735108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:18.473310947 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:20.157993078 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.158035040 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.158118010 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.158401966 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.158415079 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.355643988 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:20.355680943 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:20.355750084 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:20.357657909 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:20.357670069 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:20.800760984 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.801084042 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.801106930 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.802324057 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.802385092 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.803612947 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.803675890 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.853364944 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:20.853372097 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:20.900234938 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:21.075150013 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.075206041 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.083909035 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.083924055 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.084317923 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.127370119 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.167397022 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.403451920 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.403563023 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.406656027 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.406656027 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.406873941 CEST49740443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.406897068 CEST44349740184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.452805996 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.452872992 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:21.453037024 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.453241110 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:21.453254938 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.159236908 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.160670042 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.160670996 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.160748959 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.161475897 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.162672997 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.203453064 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.491050005 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.491220951 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.491297960 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.492013931 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.492049932 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:22.492064953 CEST49741443192.168.2.4184.28.90.27
            Oct 14, 2024 11:15:22.492073059 CEST44349741184.28.90.27192.168.2.4
            Oct 14, 2024 11:15:23.434386969 CEST8049735108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:23.434495926 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:24.027307987 CEST4973580192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:24.032676935 CEST8049735108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:29.336134911 CEST4972380192.168.2.4199.232.214.172
            Oct 14, 2024 11:15:29.341763020 CEST8049723199.232.214.172192.168.2.4
            Oct 14, 2024 11:15:29.341823101 CEST4972380192.168.2.4199.232.214.172
            Oct 14, 2024 11:15:30.741204977 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:30.741281033 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:30.741390944 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:31.313131094 CEST49739443192.168.2.4172.217.18.4
            Oct 14, 2024 11:15:31.313169956 CEST44349739172.217.18.4192.168.2.4
            Oct 14, 2024 11:15:31.313776970 CEST4974880192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:31.318707943 CEST8049748108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:31.318772078 CEST4974880192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:31.334825039 CEST4973680192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:31.339711905 CEST8049736108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:31.459321976 CEST8049736108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:31.507872105 CEST4973680192.168.2.4108.179.192.119
            Oct 14, 2024 11:15:36.460557938 CEST8049736108.179.192.119192.168.2.4
            Oct 14, 2024 11:15:36.460644960 CEST4973680192.168.2.4108.179.192.119
            TimestampSource PortDest PortSource IPDest IP
            Oct 14, 2024 11:15:15.573611975 CEST53593081.1.1.1192.168.2.4
            Oct 14, 2024 11:15:15.683645010 CEST53528141.1.1.1192.168.2.4
            Oct 14, 2024 11:15:16.684504032 CEST53610801.1.1.1192.168.2.4
            Oct 14, 2024 11:15:17.692536116 CEST5002153192.168.2.41.1.1.1
            Oct 14, 2024 11:15:17.692670107 CEST6313853192.168.2.41.1.1.1
            Oct 14, 2024 11:15:17.907324076 CEST53500211.1.1.1192.168.2.4
            Oct 14, 2024 11:15:17.909396887 CEST53631381.1.1.1192.168.2.4
            Oct 14, 2024 11:15:20.147922039 CEST5761853192.168.2.41.1.1.1
            Oct 14, 2024 11:15:20.148075104 CEST6204753192.168.2.41.1.1.1
            Oct 14, 2024 11:15:20.154970884 CEST53620471.1.1.1192.168.2.4
            Oct 14, 2024 11:15:20.154989004 CEST53576181.1.1.1192.168.2.4
            Oct 14, 2024 11:15:29.812639952 CEST138138192.168.2.4192.168.2.255
            Oct 14, 2024 11:15:33.580777884 CEST53581811.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 14, 2024 11:15:17.692536116 CEST192.168.2.41.1.1.10x19d6Standard query (0)casadosvidrosmt.com.brA (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:17.692670107 CEST192.168.2.41.1.1.10xce0dStandard query (0)casadosvidrosmt.com.br65IN (0x0001)false
            Oct 14, 2024 11:15:20.147922039 CEST192.168.2.41.1.1.10x21b1Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:20.148075104 CEST192.168.2.41.1.1.10x100cStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 14, 2024 11:15:17.907324076 CEST1.1.1.1192.168.2.40x19d6No error (0)casadosvidrosmt.com.br108.179.192.119A (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:20.154970884 CEST1.1.1.1192.168.2.40x100cNo error (0)www.google.com65IN (0x0001)false
            Oct 14, 2024 11:15:20.154989004 CEST1.1.1.1192.168.2.40x21b1No error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:28.329534054 CEST1.1.1.1192.168.2.40x77f2No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:28.329534054 CEST1.1.1.1192.168.2.40x77f2No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 14, 2024 11:15:29.744570017 CEST1.1.1.1192.168.2.40x80e1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 14, 2024 11:15:29.744570017 CEST1.1.1.1192.168.2.40x80e1No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • casadosvidrosmt.com.br
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735108.179.192.119803868C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 14, 2024 11:15:17.917841911 CEST437OUTGET / HTTP/1.1
            Host: casadosvidrosmt.com.br
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Oct 14, 2024 11:15:18.432610989 CEST280INHTTP/1.1 401 Unauthorized
            Date: Mon, 14 Oct 2024 09:15:18 GMT
            Server: Apache
            WWW-Authenticate: Basic realm="Access Restricted (pwrestrict)"
            Content-Length: 14
            Keep-Alive: timeout=5, max=75
            Connection: Keep-Alive
            Content-Type: text/html; charset=iso-8859-1
            Data Raw: 41 63 63 65 73 73 20 44 65 6e 69 65 64 21
            Data Ascii: Access Denied!


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736108.179.192.119803868C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 14, 2024 11:15:31.334825039 CEST490OUTGET / HTTP/1.1
            Host: casadosvidrosmt.com.br
            Connection: keep-alive
            Cache-Control: max-age=0
            Authorization: Basic Og==
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Oct 14, 2024 11:15:31.459321976 CEST280INHTTP/1.1 401 Unauthorized
            Date: Mon, 14 Oct 2024 09:15:31 GMT
            Server: Apache
            WWW-Authenticate: Basic realm="Access Restricted (pwrestrict)"
            Content-Length: 14
            Keep-Alive: timeout=5, max=75
            Connection: Keep-Alive
            Content-Type: text/html; charset=iso-8859-1
            Data Raw: 41 63 63 65 73 73 20 44 65 6e 69 65 64 21
            Data Ascii: Access Denied!


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449740184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-14 09:15:21 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-14 09:15:21 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF70)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=113414
            Date: Mon, 14 Oct 2024 09:15:21 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449741184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-14 09:15:22 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-14 09:15:22 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=113354
            Date: Mon, 14 Oct 2024 09:15:22 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-14 09:15:22 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:05:15:09
            Start date:14/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:05:15:14
            Start date:14/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,13301791348897924422,11942280521383577736,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:05:15:16
            Start date:14/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://casadosvidrosmt.com.br"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly