Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://trevoruserandco.uk

Overview

General Information

Sample URL:https://trevoruserandco.uk
Analysis ID:1562620
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2204,i,11608772012737698721,1987497195818091642,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6348 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://trevoruserandco.uk" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: trevoruserandco.uk
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@20/0@16/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2204,i,11608772012737698721,1987497195818091642,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://trevoruserandco.uk"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2204,i,11608772012737698721,1987497195818091642,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1562620 URL: https://trevoruserandco.uk Startdate: 25/11/2024 Architecture: WINDOWS Score: 0 14 trevoruserandco.uk 2->14 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.4, 138, 443, 49494 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 172.217.21.36, 443, 49737 GOOGLEUS United States 11->20 22 trevoruserandco.uk 11->22 24 google.com 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://trevoruserandco.uk0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.17.78
truefalse
    high
    www.google.com
    172.217.21.36
    truefalse
      high
      trevoruserandco.uk
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        172.217.21.36
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1562620
        Start date and time:2024-11-25 19:31:18 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 1m 50s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://trevoruserandco.uk
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@20/0@16/3
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.19.227, 172.217.19.238, 74.125.205.84, 34.104.35.123, 217.20.56.99
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://trevoruserandco.uk
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Nov 25, 2024 19:32:18.103018999 CET49675443192.168.2.4173.222.162.32
        Nov 25, 2024 19:32:20.805797100 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:20.805840969 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:20.805908918 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:20.806301117 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:20.806314945 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:21.715231895 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:21.715286970 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:21.715449095 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:21.717842102 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:21.717854977 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:22.627389908 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:22.639839888 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:22.639868975 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:22.640955925 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:22.641021013 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:22.643100977 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:22.643177986 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:22.697201967 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:22.697211981 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:22.744071960 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:23.117712975 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.117866039 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.121716976 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.121731997 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.121975899 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.158119917 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.203330994 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.624948978 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.625035048 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.625087023 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.625161886 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.625189066 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.625195980 CET49738443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.625202894 CET443497382.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.655545950 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.655591965 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:23.655661106 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.655956984 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:23.655967951 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.056030989 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.056150913 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.057986021 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.057996035 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.058327913 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.059341908 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.103355885 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.604353905 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.604424000 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.604645014 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.605412006 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.605432987 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:25.605444908 CET49739443192.168.2.42.18.109.164
        Nov 25, 2024 19:32:25.605452061 CET443497392.18.109.164192.168.2.4
        Nov 25, 2024 19:32:30.986404896 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:30.986469030 CET44349740172.202.163.200192.168.2.4
        Nov 25, 2024 19:32:30.986685991 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:30.988117933 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:30.988132954 CET44349740172.202.163.200192.168.2.4
        Nov 25, 2024 19:32:32.308525085 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:32.308592081 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:32.308793068 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:32.788856983 CET44349740172.202.163.200192.168.2.4
        Nov 25, 2024 19:32:32.789395094 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:32.791948080 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:32.791985035 CET44349740172.202.163.200192.168.2.4
        Nov 25, 2024 19:32:32.792393923 CET44349740172.202.163.200192.168.2.4
        Nov 25, 2024 19:32:32.837318897 CET49740443192.168.2.4172.202.163.200
        Nov 25, 2024 19:32:33.182866096 CET49737443192.168.2.4172.217.21.36
        Nov 25, 2024 19:32:33.182899952 CET44349737172.217.21.36192.168.2.4
        Nov 25, 2024 19:32:34.470115900 CET4972380192.168.2.493.184.221.240
        Nov 25, 2024 19:32:34.590645075 CET804972393.184.221.240192.168.2.4
        Nov 25, 2024 19:32:34.590696096 CET4972380192.168.2.493.184.221.240
        TimestampSource PortDest PortSource IPDest IP
        Nov 25, 2024 19:32:17.154233932 CET53584191.1.1.1192.168.2.4
        Nov 25, 2024 19:32:17.280556917 CET53498811.1.1.1192.168.2.4
        Nov 25, 2024 19:32:18.186563015 CET5347653192.168.2.41.1.1.1
        Nov 25, 2024 19:32:18.187030077 CET5260553192.168.2.41.1.1.1
        Nov 25, 2024 19:32:18.419018030 CET53526051.1.1.1192.168.2.4
        Nov 25, 2024 19:32:18.424614906 CET53534761.1.1.1192.168.2.4
        Nov 25, 2024 19:32:18.425339937 CET6486353192.168.2.41.1.1.1
        Nov 25, 2024 19:32:18.564261913 CET53648631.1.1.1192.168.2.4
        Nov 25, 2024 19:32:18.620362043 CET6378053192.168.2.48.8.8.8
        Nov 25, 2024 19:32:18.620971918 CET6263753192.168.2.41.1.1.1
        Nov 25, 2024 19:32:18.759924889 CET53626371.1.1.1192.168.2.4
        Nov 25, 2024 19:32:18.875750065 CET53637808.8.8.8192.168.2.4
        Nov 25, 2024 19:32:19.635469913 CET6197353192.168.2.41.1.1.1
        Nov 25, 2024 19:32:19.636051893 CET5515253192.168.2.41.1.1.1
        Nov 25, 2024 19:32:19.780100107 CET53619731.1.1.1192.168.2.4
        Nov 25, 2024 19:32:19.780199051 CET53551521.1.1.1192.168.2.4
        Nov 25, 2024 19:32:20.093059063 CET53494941.1.1.1192.168.2.4
        Nov 25, 2024 19:32:20.656233072 CET6155353192.168.2.41.1.1.1
        Nov 25, 2024 19:32:20.656465054 CET5875353192.168.2.41.1.1.1
        Nov 25, 2024 19:32:20.797089100 CET53587531.1.1.1192.168.2.4
        Nov 25, 2024 19:32:20.804799080 CET53615531.1.1.1192.168.2.4
        Nov 25, 2024 19:32:24.798516035 CET6007553192.168.2.41.1.1.1
        Nov 25, 2024 19:32:24.798656940 CET5236253192.168.2.41.1.1.1
        Nov 25, 2024 19:32:24.938081980 CET53600751.1.1.1192.168.2.4
        Nov 25, 2024 19:32:24.938426971 CET53523621.1.1.1192.168.2.4
        Nov 25, 2024 19:32:24.939090967 CET5620053192.168.2.41.1.1.1
        Nov 25, 2024 19:32:25.079941034 CET53562001.1.1.1192.168.2.4
        Nov 25, 2024 19:32:25.742721081 CET5592153192.168.2.41.1.1.1
        Nov 25, 2024 19:32:25.743031025 CET6421953192.168.2.41.1.1.1
        Nov 25, 2024 19:32:25.886207104 CET53559211.1.1.1192.168.2.4
        Nov 25, 2024 19:32:25.887015104 CET53642191.1.1.1192.168.2.4
        Nov 25, 2024 19:32:25.899164915 CET5206353192.168.2.41.1.1.1
        Nov 25, 2024 19:32:25.899369001 CET5821353192.168.2.48.8.8.8
        Nov 25, 2024 19:32:26.042550087 CET53520631.1.1.1192.168.2.4
        Nov 25, 2024 19:32:26.157115936 CET53582138.8.8.8192.168.2.4
        Nov 25, 2024 19:32:31.858211994 CET138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Nov 25, 2024 19:32:18.186563015 CET192.168.2.41.1.1.10x6d71Standard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.187030077 CET192.168.2.41.1.1.10x82dcStandard query (0)trevoruserandco.uk65IN (0x0001)false
        Nov 25, 2024 19:32:18.425339937 CET192.168.2.41.1.1.10x30eStandard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.620362043 CET192.168.2.48.8.8.80xf0b9Standard query (0)google.comA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.620971918 CET192.168.2.41.1.1.10x73ddStandard query (0)google.comA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:19.635469913 CET192.168.2.41.1.1.10x76ddStandard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:19.636051893 CET192.168.2.41.1.1.10x56bdStandard query (0)trevoruserandco.uk65IN (0x0001)false
        Nov 25, 2024 19:32:20.656233072 CET192.168.2.41.1.1.10xb2eaStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:20.656465054 CET192.168.2.41.1.1.10x6f64Standard query (0)www.google.com65IN (0x0001)false
        Nov 25, 2024 19:32:24.798516035 CET192.168.2.41.1.1.10xbea0Standard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:24.798656940 CET192.168.2.41.1.1.10x5626Standard query (0)trevoruserandco.uk65IN (0x0001)false
        Nov 25, 2024 19:32:24.939090967 CET192.168.2.41.1.1.10xfd1fStandard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:25.742721081 CET192.168.2.41.1.1.10xa220Standard query (0)trevoruserandco.ukA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:25.743031025 CET192.168.2.41.1.1.10x1173Standard query (0)trevoruserandco.uk65IN (0x0001)false
        Nov 25, 2024 19:32:25.899164915 CET192.168.2.41.1.1.10xdb0Standard query (0)google.comA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:25.899369001 CET192.168.2.48.8.8.80xab5cStandard query (0)google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Nov 25, 2024 19:32:18.419018030 CET1.1.1.1192.168.2.40x82dcName error (3)trevoruserandco.uknonenone65IN (0x0001)false
        Nov 25, 2024 19:32:18.424614906 CET1.1.1.1192.168.2.40x6d71Name error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.564261913 CET1.1.1.1192.168.2.40x30eName error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.759924889 CET1.1.1.1192.168.2.40x73ddNo error (0)google.com172.217.17.78A (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:18.875750065 CET8.8.8.8192.168.2.40xf0b9No error (0)google.com142.250.181.110A (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:19.780100107 CET1.1.1.1192.168.2.40x76ddName error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:19.780199051 CET1.1.1.1192.168.2.40x56bdName error (3)trevoruserandco.uknonenone65IN (0x0001)false
        Nov 25, 2024 19:32:20.797089100 CET1.1.1.1192.168.2.40x6f64No error (0)www.google.com65IN (0x0001)false
        Nov 25, 2024 19:32:20.804799080 CET1.1.1.1192.168.2.40xb2eaNo error (0)www.google.com172.217.21.36A (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:24.938081980 CET1.1.1.1192.168.2.40xbea0Name error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:24.938426971 CET1.1.1.1192.168.2.40x5626Name error (3)trevoruserandco.uknonenone65IN (0x0001)false
        Nov 25, 2024 19:32:25.079941034 CET1.1.1.1192.168.2.40xfd1fName error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:25.886207104 CET1.1.1.1192.168.2.40xa220Name error (3)trevoruserandco.uknonenoneA (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:25.887015104 CET1.1.1.1192.168.2.40x1173Name error (3)trevoruserandco.uknonenone65IN (0x0001)false
        Nov 25, 2024 19:32:26.042550087 CET1.1.1.1192.168.2.40xdb0No error (0)google.com142.250.181.142A (IP address)IN (0x0001)false
        Nov 25, 2024 19:32:26.157115936 CET8.8.8.8192.168.2.40xab5cNo error (0)google.com142.250.181.110A (IP address)IN (0x0001)false
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.4497382.18.109.164443
        TimestampBytes transferredDirectionData
        2024-11-25 18:32:23 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-11-25 18:32:23 UTC478INHTTP/1.1 200 OK
        Content-Type: application/octet-stream
        Server: Kestrel
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus-z1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-OSID: 2
        X-CID: 2
        X-CCC: GB
        Cache-Control: public, max-age=54032
        Date: Mon, 25 Nov 2024 18:32:23 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.4497392.18.109.164443
        TimestampBytes transferredDirectionData
        2024-11-25 18:32:25 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-11-25 18:32:25 UTC534INHTTP/1.1 200 OK
        Content-Type: application/octet-stream
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
        Cache-Control: public, max-age=54056
        Date: Mon, 25 Nov 2024 18:32:25 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-11-25 18:32:25 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:13:32:13
        Start date:25/11/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:13:32:15
        Start date:25/11/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2204,i,11608772012737698721,1987497195818091642,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:13:32:17
        Start date:25/11/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://trevoruserandco.uk"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly