Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://pks-boxler.kitasmurifeld.ch

Overview

General Information

Sample URL:http://pks-boxler.kitasmurifeld.ch
Analysis ID:1545293
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2268,i,13885804189598203526,15114074365841423246,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pks-boxler.kitasmurifeld.ch" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: pks-boxler.kitasmurifeld.chConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: pks-boxler.kitasmurifeld.chConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: pks-boxler.kitasmurifeld.chConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: pks-boxler.kitasmurifeld.chConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: pks-boxler.kitasmurifeld.chConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: pks-boxler.kitasmurifeld.ch
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: classification engineClassification label: unknown0.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2268,i,13885804189598203526,15114074365841423246,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pks-boxler.kitasmurifeld.ch"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2268,i,13885804189598203526,15114074365841423246,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
pks-boxler.kitasmurifeld.ch
109.70.114.185
truefalse
    unknown
    www.google.com
    142.250.186.164
    truefalse
      unknown
      default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
      217.20.57.19
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://pks-boxler.kitasmurifeld.ch/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.164
            www.google.comUnited States
            15169GOOGLEUSfalse
            109.70.114.185
            pks-boxler.kitasmurifeld.chSwitzerland
            1764NEXTLAYER-ASATfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1545293
            Start date and time:2024-10-30 11:35:13 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 57s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://pks-boxler.kitasmurifeld.ch
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@4/4
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.16.195, 216.58.206.46, 64.233.167.84, 34.104.35.123, 184.28.90.27, 20.109.210.53, 217.20.57.19, 20.242.39.171, 192.229.221.95
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://pks-boxler.kitasmurifeld.ch
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 30, 2024 11:35:59.828224897 CET49675443192.168.2.4173.222.162.32
            Oct 30, 2024 11:36:09.437001944 CET49675443192.168.2.4173.222.162.32
            Oct 30, 2024 11:36:11.397995949 CET4973580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:11.398497105 CET4973680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:11.403398991 CET8049735109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:11.403491974 CET4973580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:11.403652906 CET4973580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:11.403815031 CET8049736109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:11.403892040 CET4973680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:11.409010887 CET8049735109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:12.011087894 CET8049736109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:12.011224985 CET4973680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:12.016558886 CET8049735109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:12.016675949 CET4973580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:12.020781040 CET4973580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:12.026122093 CET8049735109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:12.961952925 CET4973680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:12.967618942 CET8049736109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.052999020 CET4973980192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.053497076 CET4974080192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.058651924 CET8049739109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.058737993 CET4973980192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.058928967 CET8049740109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.058998108 CET4974080192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.084559917 CET4974080192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.090032101 CET8049740109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.673940897 CET8049740109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.674016953 CET4974080192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.674139023 CET4974080192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.674170971 CET8049739109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.674237013 CET4973980192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.674552917 CET4973980192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.674947977 CET4974180192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.679694891 CET8049740109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.679847956 CET8049739109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.680425882 CET8049741109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.680504084 CET4974180192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.680680990 CET4974180192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:13.686141014 CET8049741109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:13.858139038 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:13.858208895 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:13.858269930 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:13.859699011 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:13.859726906 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.394752979 CET8049741109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:14.394895077 CET4974180192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:14.431334972 CET4974180192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:14.436690092 CET8049741109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:14.724756002 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.725393057 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:14.725425959 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.726450920 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.726511955 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:14.727999926 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:14.728065014 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.779702902 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:14.779716969 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:14.826577902 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:19.479306936 CET4974580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:19.479564905 CET4974680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:19.484827995 CET8049745109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:19.485037088 CET8049746109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:19.485125065 CET4974580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:19.487306118 CET4974680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:19.494538069 CET4974680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:19.500438929 CET8049746109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.099644899 CET8049745109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.099778891 CET4974580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.101766109 CET8049746109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.101834059 CET4974680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.102390051 CET4974680192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.103256941 CET4974580192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.103918076 CET4974780192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.108747959 CET8049746109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.108762980 CET8049745109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.109276056 CET8049747109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.109353065 CET4974780192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.111367941 CET4974780192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.116755009 CET8049747109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.714339018 CET8049747109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:20.714605093 CET4974780192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.715754032 CET4974780192.168.2.4109.70.114.185
            Oct 30, 2024 11:36:20.721072912 CET8049747109.70.114.185192.168.2.4
            Oct 30, 2024 11:36:24.721558094 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:24.721708059 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:24.722311020 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:25.735377073 CET49742443192.168.2.4142.250.186.164
            Oct 30, 2024 11:36:25.735426903 CET44349742142.250.186.164192.168.2.4
            Oct 30, 2024 11:36:27.746891022 CET4972380192.168.2.488.221.110.91
            Oct 30, 2024 11:36:27.752934933 CET804972388.221.110.91192.168.2.4
            Oct 30, 2024 11:36:27.753000975 CET4972380192.168.2.488.221.110.91
            TimestampSource PortDest PortSource IPDest IP
            Oct 30, 2024 11:36:09.079694033 CET53555501.1.1.1192.168.2.4
            Oct 30, 2024 11:36:09.090261936 CET53649121.1.1.1192.168.2.4
            Oct 30, 2024 11:36:10.564588070 CET53649971.1.1.1192.168.2.4
            Oct 30, 2024 11:36:11.157588959 CET5132053192.168.2.41.1.1.1
            Oct 30, 2024 11:36:11.157748938 CET6355153192.168.2.41.1.1.1
            Oct 30, 2024 11:36:11.397172928 CET53635511.1.1.1192.168.2.4
            Oct 30, 2024 11:36:11.397193909 CET53513201.1.1.1192.168.2.4
            Oct 30, 2024 11:36:13.847845078 CET6402853192.168.2.41.1.1.1
            Oct 30, 2024 11:36:13.849123001 CET5121653192.168.2.41.1.1.1
            Oct 30, 2024 11:36:13.855237007 CET53640281.1.1.1192.168.2.4
            Oct 30, 2024 11:36:13.856296062 CET53512161.1.1.1192.168.2.4
            Oct 30, 2024 11:36:26.428744078 CET138138192.168.2.4192.168.2.255
            Oct 30, 2024 11:36:27.492007017 CET53516421.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 30, 2024 11:36:11.157588959 CET192.168.2.41.1.1.10x73c7Standard query (0)pks-boxler.kitasmurifeld.chA (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:11.157748938 CET192.168.2.41.1.1.10xfd07Standard query (0)pks-boxler.kitasmurifeld.ch65IN (0x0001)false
            Oct 30, 2024 11:36:13.847845078 CET192.168.2.41.1.1.10x7c87Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:13.849123001 CET192.168.2.41.1.1.10x1a6aStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 30, 2024 11:36:11.397193909 CET1.1.1.1192.168.2.40x73c7No error (0)pks-boxler.kitasmurifeld.ch109.70.114.185A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:13.855237007 CET1.1.1.1192.168.2.40x7c87No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:13.856296062 CET1.1.1.1192.168.2.40x1a6aNo error (0)www.google.com65IN (0x0001)false
            Oct 30, 2024 11:36:23.906244040 CET1.1.1.1192.168.2.40x540bNo error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
            Oct 30, 2024 11:36:23.906244040 CET1.1.1.1192.168.2.40x540bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.19A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:23.906244040 CET1.1.1.1192.168.2.40x540bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.18A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:23.906244040 CET1.1.1.1192.168.2.40x540bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.35A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:23.906244040 CET1.1.1.1192.168.2.40x540bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.34A (IP address)IN (0x0001)false
            Oct 30, 2024 11:36:26.440248966 CET1.1.1.1192.168.2.40x2bbcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 30, 2024 11:36:26.440248966 CET1.1.1.1192.168.2.40x2bbcNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • pks-boxler.kitasmurifeld.ch
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735109.70.114.185803992C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 30, 2024 11:36:11.403652906 CET442OUTGET / HTTP/1.1
            Host: pks-boxler.kitasmurifeld.ch
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449740109.70.114.185803992C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 30, 2024 11:36:13.084559917 CET468OUTGET / HTTP/1.1
            Host: pks-boxler.kitasmurifeld.ch
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449741109.70.114.185803992C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 30, 2024 11:36:13.680680990 CET468OUTGET / HTTP/1.1
            Host: pks-boxler.kitasmurifeld.ch
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449746109.70.114.185803992C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 30, 2024 11:36:19.494538069 CET468OUTGET / HTTP/1.1
            Host: pks-boxler.kitasmurifeld.ch
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449747109.70.114.185803992C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 30, 2024 11:36:20.111367941 CET468OUTGET / HTTP/1.1
            Host: pks-boxler.kitasmurifeld.ch
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:06:36:03
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:06:36:07
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2268,i,13885804189598203526,15114074365841423246,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:06:36:10
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pks-boxler.kitasmurifeld.ch"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly