Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://oneamerica.ws

Overview

General Information

Sample URL:http://oneamerica.ws
Analysis ID:1544491
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5556 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6780 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1928,i,9762095352043587412,14868542547525828690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://oneamerica.ws" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=tPoe9F9UXv8gl56&MD=aMEFwGxv HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=tPoe9F9UXv8gl56&MD=aMEFwGxv HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: oneamerica.wsConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: oneamerica.wsConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://oneamerica.ws/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: oneamerica.ws
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 29 Oct 2024 13:01:10 GMTServer: ApacheContent-Length: 315Keep-Alive: timeout=5, max=99Connection: Keep-AliveContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/10@4/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1928,i,9762095352043587412,14868542547525828690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://oneamerica.ws"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1928,i,9762095352043587412,14868542547525828690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
oneamerica.ws
104.37.175.156
truefalse
    unknown
    www.google.com
    142.250.185.164
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://oneamerica.ws/favicon.icofalse
        unknown
        http://oneamerica.ws/false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.185.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          104.37.175.156
          oneamerica.wsUnited States
          396073MAJESTIC-HOSTING-01USfalse
          IP
          192.168.2.16
          192.168.2.6
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1544491
          Start date and time:2024-10-29 14:00:37 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 18s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsinteractivecookbook.jbs
          Sample URL:http://oneamerica.ws
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:13
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@17/10@4/5
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.186.142, 173.194.76.84, 34.104.35.123, 93.184.221.240, 172.217.16.195, 142.250.186.46
          • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: http://oneamerica.ws
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:01:09 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2673
          Entropy (8bit):3.9823374871777126
          Encrypted:false
          SSDEEP:48:8YdBTpVoHEidAKZdA1FehwiZUklqehWy+3:8iPPJy
          MD5:729601A9AD4382BA67608A1709507B9B
          SHA1:E94798F9F9766BB49DF110C9028480D126C6D11C
          SHA-256:1E75D2B794DD9702BC87D8878BCAAB43B4090E2F8EB618D61497C3E573B0C3C3
          SHA-512:D548A6222A798E62E1CB7BD89D92AF42D7BDD556DD4741D52520EB7E54FAC8DE8CA41C59DEE4AE558D7D7553758F55B9FAA120A7F081DD854BB017DDE897E8E2
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....XR..*..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V]Y%h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:01:09 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2675
          Entropy (8bit):3.9992310389940084
          Encrypted:false
          SSDEEP:48:8tdBTpVoHEidAKZdA1seh/iZUkAQkqeh5y+2:8hP59Q0y
          MD5:5AE4F0B02FBA23B022E333987BE52E06
          SHA1:67DC0382CD052C18DB40FE83BBE7AA8BF2C480C3
          SHA-256:1F10F6D89B92D241AFDE200265FA792880F3EDB952C8030C939EF559244D960D
          SHA-512:B259E69C06892389B321865CEECD409DBA109970A1CE18F8FE21785C1FD9255E9315A7077BCE47000F6D4BF571745ED22F656EE1EB87C6FD903AC7A14EE5326A
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,........*..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V]Y%h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2689
          Entropy (8bit):4.006403792373883
          Encrypted:false
          SSDEEP:48:8DdBTpVAHEidAKZdA14meh7sFiZUkmgqeh7s3y+BX:8HPNnNy
          MD5:BEBA485475C4F6C6C08A530BF8795D89
          SHA1:70F004CAB14D2278096C2BD0927289F1C61E44AA
          SHA-256:62EAC92381029C201A3D5829DDE60C75F86574497D46B8D59BA0E0696B59338F
          SHA-512:FD24BCCE0715F623D2DD2AC7522F24A6FE41031333940590799689EC66E85719AF1304F599F46E35735FFF2093D8712409BE4A9BE66438983F4131F600641DE3
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:01:09 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9947487915256175
          Encrypted:false
          SSDEEP:48:8NdBTpVoHEidAKZdA1TehDiZUkwqehVy+R:8BPq/y
          MD5:CFFBA84D6A97418067AAFADBC68796B8
          SHA1:F34AA2D675E16901A7AF370FDB3611D9D304F026
          SHA-256:D1FB439C215B189181A31C7B7BCA12CFD28BB57812DFD3402417B3698663C1E5
          SHA-512:83CB5ACCED8F7336356D1F674B1361DF5939373EA85A233EF0B7B9F9F40008E72961B0A83DB6106942D52B22CAC080F5C8A8118BFEFA52242583B0ADFB1518AB
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....b..*..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V]Y%h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:01:09 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9855144037190056
          Encrypted:false
          SSDEEP:48:8HdBTpVoHEidAKZdA1dehBiZUk1W1qehry+C:87Pq9Ly
          MD5:2CF5A273096A8498E2D015DDF335027D
          SHA1:5C8C94668B0CD0FDA9C6A6E263423BFFF7C7D1AD
          SHA-256:43954389A8A178096342BF07C667DF5E6B04B9F694E7A93A1E7F1E6C7E90596C
          SHA-512:F8767743030B530C0120A4499755443F9F31A5CA59D4C5AF00CDBF7A71C41B7CCF38B18C798A8A2BC655E63DE1543B8F1EB42C6E135096AF9D26805AB229E128
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....A...*..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V]Y%h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:01:09 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.9932604741989386
          Encrypted:false
          SSDEEP:48:8AdBTpVoHEidAKZdA1duTeehOuTbbiZUk5OjqehOuTbNy+yT+:8qPgTfTbxWOvTbNy7T
          MD5:BCC2D2985D1F3AFA4F6A6764AD2760BD
          SHA1:6AAA03330DB44AA0EF4B7AD6D4179C71A88520BF
          SHA-256:EFD8EF5B6AAE37C763E1680C16EB2D9484B4C0886C98052951256FD3F3EFBD65
          SHA-512:64937F1672BF2384EE9CC7B04C112DAA2997F7FE14317B6704A82D6EF573521CFAF7FA66581BBF074B7F82985B91957B098B905F306C200D9808C9850C24C1EC
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,........*..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I]Y.h....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V]Y$h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V]Y$h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V]Y$h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V]Y%h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):315
          Entropy (8bit):5.0572271090563765
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
          MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
          SHA1:A82190FC530C265AA40A045C21770D967F4767B8
          SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
          SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
          Malicious:false
          Reputation:low
          URL:http://oneamerica.ws/favicon.ico
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with no line terminators
          Category:downloaded
          Size (bytes):10
          Entropy (8bit):3.1219280948873624
          Encrypted:false
          SSDEEP:3:h2V:h4
          MD5:0C5A1E92F0C9947556E036D125C7E1CD
          SHA1:E16A2CA2AAD91694E7B62330C08C735C772D74C6
          SHA-256:6881A4A575ED257C893AD0A870178D069B72F8713714C21F46317A187B919048
          SHA-512:A86FF07E52E2F40D532CBEA3350BA4FE155E4ED2AB6769D784EBDFC551B08E9DCBD9471A8067694593135ED3705227AE8E1D2CD5B5105FB9E2B6857DC525C30A
          Malicious:false
          Reputation:low
          URL:http://oneamerica.ws/
          Preview:This Sucks
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 29, 2024 14:01:09.866996050 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:09.867496014 CET4970180192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:09.872689962 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:09.872792006 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:09.872848034 CET8049701104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:09.872905016 CET4970180192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:09.872992039 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:09.878511906 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:10.008323908 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:10.311799049 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:10.484417915 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:10.531980038 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:10.559129953 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:10.564913034 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:10.689738989 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:10.737770081 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:10.912816048 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:12.126775980 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:13.265489101 CET4968980192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:13.540277958 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:13.540323973 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:13.540405035 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:13.540714025 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:13.540733099 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.420151949 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.420483112 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:14.420506001 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.421556950 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.421637058 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:14.422883987 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:14.423019886 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.473763943 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:14.473794937 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:14.521766901 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:14.537775993 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:15.696719885 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:15.696942091 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:16.275995970 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:16.276052952 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:16.276146889 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:16.278429031 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:16.278448105 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.002470016 CET4970080192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:17.008040905 CET8049700104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:17.133687973 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.133980989 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.142405033 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.142431021 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.142822027 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.186072111 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.231339931 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.431062937 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.431138039 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.431221962 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.431617022 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.431652069 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.431679010 CET49709443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.431685925 CET44349709184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.513348103 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.513401031 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:17.513565063 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.513839960 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:17.513850927 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.167134047 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:18.362904072 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.363070965 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.364670992 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.364692926 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.365668058 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.367105007 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.407339096 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.469815016 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:18.616561890 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.616673946 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.616764069 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.617561102 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.617583990 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:18.617594957 CET49710443192.168.2.16184.28.90.27
          Oct 29, 2024 14:01:18.617602110 CET44349710184.28.90.27192.168.2.16
          Oct 29, 2024 14:01:19.071810007 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:19.341804028 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:19.748518944 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:19.748564959 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:19.748668909 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:19.749742985 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:19.749756098 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.277811050 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:20.613956928 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.614059925 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.617245913 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.617258072 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.617592096 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.659781933 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.682085991 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.723335028 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966037989 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966109037 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966129065 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966178894 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966233015 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966394901 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.966434956 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.966492891 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.967350960 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.967427015 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.967442989 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.967494011 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.986980915 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.987020016 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:20.987035990 CET49711443192.168.2.1620.12.23.50
          Oct 29, 2024 14:01:20.987045050 CET4434971120.12.23.50192.168.2.16
          Oct 29, 2024 14:01:22.640981913 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:22.688779116 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:22.943901062 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:23.549810886 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:24.422575951 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:24.422648907 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:24.422792912 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:24.761795044 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:25.005902052 CET49707443192.168.2.16142.250.185.164
          Oct 29, 2024 14:01:25.005940914 CET44349707142.250.185.164192.168.2.16
          Oct 29, 2024 14:01:27.171808958 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:27.490828991 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:28.954368114 CET49673443192.168.2.16204.79.197.203
          Oct 29, 2024 14:01:31.986841917 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:37.104887962 CET49678443192.168.2.1620.189.173.10
          Oct 29, 2024 14:01:41.587831974 CET4968080192.168.2.16192.229.211.108
          Oct 29, 2024 14:01:49.021097898 CET8049701104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:49.021210909 CET4970180192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:51.008795977 CET4970180192.168.2.16104.37.175.156
          Oct 29, 2024 14:01:51.014414072 CET8049701104.37.175.156192.168.2.16
          Oct 29, 2024 14:01:57.566169977 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:57.566265106 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:57.566410065 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:57.567425966 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:57.567444086 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.489224911 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.489376068 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.491266966 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.491300106 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.491739988 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.493535042 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.539344072 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.789820910 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.789851904 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.789870977 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.790186882 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.790263891 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.790370941 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.792608976 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.792670012 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.792685032 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.792706013 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.792728901 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.792738914 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.792793036 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.793526888 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.793566942 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:01:58.793596029 CET49712443192.168.2.1652.149.20.212
          Oct 29, 2024 14:01:58.793611050 CET4434971252.149.20.212192.168.2.16
          Oct 29, 2024 14:02:13.598222017 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:13.598274946 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:13.598368883 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:13.598650932 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:13.598675013 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:14.459069014 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:14.459428072 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:14.459461927 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:14.459810972 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:14.460115910 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:14.460186005 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:14.507920980 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:24.451236963 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:24.451307058 CET44349714142.250.185.164192.168.2.16
          Oct 29, 2024 14:02:24.451597929 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:25.008748055 CET49714443192.168.2.16142.250.185.164
          Oct 29, 2024 14:02:25.008758068 CET44349714142.250.185.164192.168.2.16
          TimestampSource PortDest PortSource IPDest IP
          Oct 29, 2024 14:01:08.854022026 CET53505641.1.1.1192.168.2.16
          Oct 29, 2024 14:01:08.910015106 CET53542241.1.1.1192.168.2.16
          Oct 29, 2024 14:01:09.579545021 CET5733553192.168.2.161.1.1.1
          Oct 29, 2024 14:01:09.579921961 CET5801453192.168.2.161.1.1.1
          Oct 29, 2024 14:01:09.838144064 CET53580141.1.1.1192.168.2.16
          Oct 29, 2024 14:01:09.866131067 CET53573351.1.1.1192.168.2.16
          Oct 29, 2024 14:01:10.298007011 CET53585141.1.1.1192.168.2.16
          Oct 29, 2024 14:01:13.531857014 CET5370053192.168.2.161.1.1.1
          Oct 29, 2024 14:01:13.532064915 CET6117853192.168.2.161.1.1.1
          Oct 29, 2024 14:01:13.539252043 CET53611781.1.1.1192.168.2.16
          Oct 29, 2024 14:01:13.539464951 CET53537001.1.1.1192.168.2.16
          Oct 29, 2024 14:01:27.340677023 CET53557281.1.1.1192.168.2.16
          Oct 29, 2024 14:01:46.289530039 CET53545761.1.1.1192.168.2.16
          Oct 29, 2024 14:02:08.610850096 CET53605901.1.1.1192.168.2.16
          Oct 29, 2024 14:02:08.692404985 CET53626591.1.1.1192.168.2.16
          Oct 29, 2024 14:02:14.338325024 CET138138192.168.2.16192.168.2.255
          Oct 29, 2024 14:02:37.894341946 CET53499371.1.1.1192.168.2.16
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 29, 2024 14:01:09.579545021 CET192.168.2.161.1.1.10x85c8Standard query (0)oneamerica.wsA (IP address)IN (0x0001)false
          Oct 29, 2024 14:01:09.579921961 CET192.168.2.161.1.1.10xb54fStandard query (0)oneamerica.ws65IN (0x0001)false
          Oct 29, 2024 14:01:13.531857014 CET192.168.2.161.1.1.10x561fStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 29, 2024 14:01:13.532064915 CET192.168.2.161.1.1.10x254aStandard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 29, 2024 14:01:09.866131067 CET1.1.1.1192.168.2.160x85c8No error (0)oneamerica.ws104.37.175.156A (IP address)IN (0x0001)false
          Oct 29, 2024 14:01:13.539252043 CET1.1.1.1192.168.2.160x254aNo error (0)www.google.com65IN (0x0001)false
          Oct 29, 2024 14:01:13.539464951 CET1.1.1.1192.168.2.160x561fNo error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • slscr.update.microsoft.com
          • oneamerica.ws
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.1649700104.37.175.156806780C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Oct 29, 2024 14:01:09.872992039 CET428OUTGET / HTTP/1.1
          Host: oneamerica.ws
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Oct 29, 2024 14:01:10.484417915 CET333INHTTP/1.1 200 OK
          Date: Tue, 29 Oct 2024 13:01:10 GMT
          Server: Apache
          Upgrade: h2,h2c
          Connection: Upgrade, Keep-Alive
          Accept-Ranges: bytes
          X-Mod-Pagespeed: 1.13.35.2-0
          Vary: Accept-Encoding
          Cache-Control: max-age=0, no-cache, s-maxage=10
          Content-Length: 10
          Keep-Alive: timeout=5, max=100
          Content-Type: text/html
          Data Raw: 54 68 69 73 20 53 75 63 6b 73
          Data Ascii: This Sucks
          Oct 29, 2024 14:01:10.559129953 CET370OUTGET /favicon.ico HTTP/1.1
          Host: oneamerica.ws
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://oneamerica.ws/
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Oct 29, 2024 14:01:10.689738989 CET515INHTTP/1.1 404 Not Found
          Date: Tue, 29 Oct 2024 13:01:10 GMT
          Server: Apache
          Content-Length: 315
          Keep-Alive: timeout=5, max=99
          Connection: Keep-Alive
          Content-Type: text/html; charset=iso-8859-1
          Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.1649709184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-29 13:01:17 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-29 13:01:17 UTC466INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=86011
          Date: Tue, 29 Oct 2024 13:01:17 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.1649710184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-10-29 13:01:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-10-29 13:01:18 UTC514INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=86064
          Date: Tue, 29 Oct 2024 13:01:18 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-10-29 13:01:18 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.164971120.12.23.50443
          TimestampBytes transferredDirectionData
          2024-10-29 13:01:20 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=tPoe9F9UXv8gl56&MD=aMEFwGxv HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
          Host: slscr.update.microsoft.com
          2024-10-29 13:01:20 UTC560INHTTP/1.1 200 OK
          Cache-Control: no-cache
          Pragma: no-cache
          Content-Type: application/octet-stream
          Expires: -1
          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
          ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
          MS-CorrelationId: e41f1cd9-3807-4395-9f04-5ba353badc04
          MS-RequestId: b4c7bbaa-e4c6-468f-925a-cfbb48b7beb9
          MS-CV: DvmnEgHvhUKGIyiP.0
          X-Microsoft-SLSClientCache: 2880
          Content-Disposition: attachment; filename=environment.cab
          X-Content-Type-Options: nosniff
          Date: Tue, 29 Oct 2024 13:01:20 GMT
          Connection: close
          Content-Length: 24490
          2024-10-29 13:01:20 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
          Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
          2024-10-29 13:01:20 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
          Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.164971252.149.20.212443
          TimestampBytes transferredDirectionData
          2024-10-29 13:01:58 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=tPoe9F9UXv8gl56&MD=aMEFwGxv HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
          Host: slscr.update.microsoft.com
          2024-10-29 13:01:58 UTC560INHTTP/1.1 200 OK
          Cache-Control: no-cache
          Pragma: no-cache
          Content-Type: application/octet-stream
          Expires: -1
          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
          ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
          MS-CorrelationId: d3777bb0-2b75-4193-a4d5-cf1ff33a5cc4
          MS-RequestId: 89ad1a5a-ce42-4050-bd6b-79b00e423739
          MS-CV: dAJUPEK/Y0qJJDKu.0
          X-Microsoft-SLSClientCache: 1440
          Content-Disposition: attachment; filename=environment.cab
          X-Content-Type-Options: nosniff
          Date: Tue, 29 Oct 2024 13:01:58 GMT
          Connection: close
          Content-Length: 30005
          2024-10-29 13:01:58 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
          Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
          2024-10-29 13:01:58 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
          Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:09:01:06
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:09:01:07
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1928,i,9762095352043587412,14868542547525828690,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:09:01:08
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://oneamerica.ws"
          Imagebase:0x7ff7f9810000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly