Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://s.ksrndkehqnwntyxlhgto.com

Overview

General Information

Sample URL:http://s.ksrndkehqnwntyxlhgto.com
Analysis ID:1562621
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1936,i,13978813817988735767,11448808675129081722,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://s.ksrndkehqnwntyxlhgto.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.0
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.0
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.0
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.0
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.109.164
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://s.ksrndkehqnwntyxlhgto.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=HKMDLL9PR+zaBhB&MD=+lLD4y3r HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=HKMDLL9PR+zaBhB&MD=+lLD4y3r HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=http%3A%2F%2Fs.ksrndkehqnwntyxlhgto.com&oit=3&cp=4&pgcl=4&gs_rn=42&psi=iSR4VaPXe_50Me9V&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIk6HLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://s.ksrndkehqnwntyxlhgto.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: s.ksrndkehqnwntyxlhgto.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: s.ksrndkehqnwntyxlhgto.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeServer: AmazonS3Date: Mon, 25 Nov 2024 18:35:00 GMTX-Cache: Error from cloudfrontVia: 1.1 5cf26f8164e0cad37f6634ff6aeac4ce.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P5X-Amz-Cf-Id: AVf1npSVGLuDCW7X1BO31pZIai2Bp-Nx899T9k_R7Rl8swlxg7sgbg==
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeServer: AmazonS3Date: Mon, 25 Nov 2024 18:35:52 GMTX-Cache: Error from cloudfrontVia: 1.1 0254a3d4b384cab4933ea28efe6685c2.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P5X-Amz-Cf-Id: RPiFYZ_vxQolLLdYwe8-yFH_B1H9HPRhpNy8SWv8z8qrlCGGr4ErMQ==
Source: chromecache_60.1.drString found in binary or memory: http://s.ksrndkehqnwntyxlhgto.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.109.164:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: classification engineClassification label: clean0.win@19/12@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1936,i,13978813817988735767,11448808675129081722,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1936,i,13978813817988735767,11448808675129081722,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://s.ksrndkehqnwntyxlhgto.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s.ksrndkehqnwntyxlhgto.com
18.245.60.90
truefalse
    high
    www.google.com
    142.250.181.68
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      http://s.ksrndkehqnwntyxlhgto.com/false
        high
        https://s.ksrndkehqnwntyxlhgto.com/false
          high
          https://s.ksrndkehqnwntyxlhgto.com/favicon.icofalse
            high
            https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=http%3A%2F%2Fs.ksrndkehqnwntyxlhgto.com&oit=3&cp=4&pgcl=4&gs_rn=42&psi=iSR4VaPXe_50Me9V&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
              high
              NameSourceMaliciousAntivirus DetectionReputation
              http://s.ksrndkehqnwntyxlhgto.comchromecache_60.1.drfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                18.245.60.9
                unknownUnited States
                16509AMAZON-02USfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                18.245.60.90
                s.ksrndkehqnwntyxlhgto.comUnited States
                16509AMAZON-02USfalse
                142.250.181.68
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.17
                192.168.2.16
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1562621
                Start date and time:2024-11-25 19:34:24 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 13s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Sample URL:http://s.ksrndkehqnwntyxlhgto.com
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:13
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@19/12@6/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.217.19.227, 172.217.17.46, 74.125.205.84, 34.104.35.123, 172.217.17.67
                • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: http://s.ksrndkehqnwntyxlhgto.com
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 17:34:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2673
                Entropy (8bit):3.99002199649846
                Encrypted:false
                SSDEEP:48:85dqOTKKrXH8idAKZdA1FehwiZUklqeh1y+3:8zHSyy
                MD5:E7CA2937474500F159C74940C37BC00D
                SHA1:4204B788D72CB171C762C5F023964AB74426AB0D
                SHA-256:4B6EB3C15C09103876A63508038D0E77BBF1509C7CEB66BDD81CD3D27B1428D5
                SHA-512:7714336E2DD4A1DFA97331AFBC8013957E812C3FB2BC883C73905939A15E9CEAC42A3F52AD1CDA9CA240776CBE02FCD9A0B25A141F3185FF3740725CDC2EB455
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,........h?..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VyY\............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 17:34:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2675
                Entropy (8bit):4.007002883969792
                Encrypted:false
                SSDEEP:48:8HbdqOTKKrXH8idAKZdA1seh/iZUkAQkqehiy+2:8HhHM9Qvy
                MD5:84ED3009EFA6923FB215AFD1AD60BC6D
                SHA1:5CF8BC59646B90393BCA708CEE10A3A4B659B912
                SHA-256:D3A8E95872BCB1A420923052965FF70AA86BD2FE41AE5BEFCAC167519C5322AE
                SHA-512:6301762E153191FCC4D9E64D32B8FA0C003A0511961596A6CFFA0DF02C873564B7422B0707C0433A6816692CE06AB5E93127DDDCE6F28F5795C75CC3AD0B4A4E
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,..../,..h?..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VyY\............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2689
                Entropy (8bit):4.015746705247201
                Encrypted:false
                SSDEEP:48:8jdqOTKKrAH8idAKZdA14meh7sFiZUkmgqeh7s8y+BX:8JH9ney
                MD5:6A45107D4C287C36E6B668BC998681A3
                SHA1:B1A3B78471BC405392006C6862742AED41A52112
                SHA-256:BF897AFE6F8B0B8A23FFA9E470E9A24B34D2BB4ABD7AA6CF7F17A26A447104E4
                SHA-512:4007FFF64064070E506AC4A9A26E55BDF0B9DCDAF0563CB67985EECBAEAE6C7CA632BD77BEADF23B613AB055FD0CDEA53D80DFA3AB33D640ED1F7EF5F9EF6B5B
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 17:34:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):4.002439739251875
                Encrypted:false
                SSDEEP:48:8PzdqOTKKrXH8idAKZdA1TehDiZUkwqehWy+R:8PZHHUy
                MD5:F7E40993FEB82F4891EFAFF1F3E9AC93
                SHA1:089163E2ACB1228BC6398ACD8AC100711E6BF39B
                SHA-256:F60EC24C0D0B8DC1A292576804A8D1532284B95448F2EA0FBDD6A6A3DCC2052F
                SHA-512:8AB2BCD56B20C8547BCB497D36538A300C0FF96C4FA302017BDB7038D24563D0382604FD263CE446FEFBDA834E7C71AA705603A8E09CEA41FE20BAEDF4FDE9DB
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......y.h?..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VyY\............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 17:34:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9947027869695675
                Encrypted:false
                SSDEEP:48:8JdqOTKKrXH8idAKZdA1dehBiZUk1W1qehYy+C:8DHX94y
                MD5:61F051365587159A20CFDA8F90652C0E
                SHA1:9FC23F752059C3217E82690A569CCA6CA2CDA67A
                SHA-256:35E26B700AC7B0ED604F381A4AD7B98F9F81878B19B28CDBF22CDF7400A98B2E
                SHA-512:A9B6C054D141A6733AAD879334CCF5FBF1ABD199B405FEC607B4C80487BADD43579DCE8480E730B6A91D6136C129BDD07CE4B0805D087BC8041A6D9A83CE74EC
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.......h?..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VyY\............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 17:34:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):4.002826053735063
                Encrypted:false
                SSDEEP:48:8NdqOTKKrXH8idAKZdA1duTeehOuTbbiZUk5OjqehOuTbey+yT+:8PHbTfTbxWOvTbey7T
                MD5:D011DCEC837895C090F456A9F4E08D4C
                SHA1:E9C00EEB223BE1F9FE1AEC56AAA32468C5FFE31F
                SHA-256:C2F59FA143A831D23F15254DF828EFF0BA95E467AC988BF88987870785E617F0
                SHA-512:233E81CEDC5F7FAB4FF4736904AE2D2A231A3CA8BAF2D8AA93806195386D07540C21C00D0BBB2CC5BF68158459B5F9F18BA81900FFE581E74CB513F8F31BF5A9
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......q.h?..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IyYQ.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VyYZ.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VyYZ.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VyYZ............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VyY\............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............#......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, ASCII text
                Category:downloaded
                Size (bytes):243
                Entropy (8bit):5.590088876555848
                Encrypted:false
                SSDEEP:6:TMVBd/ZbZjZvKtWRVzji8fhHyIFFezUan:TMHd9BZKtWR8A5FFUUa
                MD5:E7D35F1B3FCAF8545E0D480DE15824F6
                SHA1:D452DD86BB1475E7E82DE163D46A84782F2A63B1
                SHA-256:D0D07995D036BDB3E5875A6FF5CF99DDDCF2DFEC3E029C806D041DA449A24EF3
                SHA-512:0309A42186DD6D55436838025392BCDBCF5DDEA5381C066E5D20D25D609161572864BCD7781779CA17BE0FB725A0274AC37D62820993CF738D22994DE4E8C1A9
                Malicious:false
                Reputation:low
                URL:https://s.ksrndkehqnwntyxlhgto.com/favicon.ico
                Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>PMBX5P63HMDD70M9</RequestId><HostId>x9rt2OlqLU6vfAq8jw+XzTqoUuLu71cHwur2EjD3QvAJgNOyYawFXMGBOJrTD5LFOsZf+FEg5iU=</HostId></Error>
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):20
                Entropy (8bit):3.3841837197791884
                Encrypted:false
                SSDEEP:3:OHKW3Ae:OqOAe
                MD5:DC5BCBF7F9372CCC9AEDB581FE88EDFE
                SHA1:79097FE77C29B4CA590114BDD0331431A1EFC470
                SHA-256:D872E8E4176213EA84EBC76D8FB621C31B4CA116FD0A51258813E804FE110CA4
                SHA-512:1EA2F632E9647FBDE1DA45DB3F295620E3B8228E48C237134DE7ADCE74121F9F12B0A647D27A574B4172A93A4E86B9C1B5868C24ABA5F48253E6283EAB35F6F0
                Malicious:false
                Reputation:low
                URL:https://s.ksrndkehqnwntyxlhgto.com/
                Preview:Nothing to see here.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text
                Category:downloaded
                Size (bytes):154
                Entropy (8bit):4.835928340972722
                Encrypted:false
                SSDEEP:3:Vw/KN6WlOoh3wwBHsLpYJWriFGWjLwWkzXFETH1u4:VwCpVV5BHsL2YriFGAwWeXFEL13
                MD5:6B13A3BBFDDCEED69F437879BE8EC4ED
                SHA1:0D40F17D32466F7FAF2683FA5F8484AD2A6B5D7F
                SHA-256:29D3BE350A8AB75A8F36EDB7AB255DDAB8F7EB5F7936C7F72C8F7950C0730440
                SHA-512:DFE2A9B6E54ECF7EA6A62CDB7A7F5BD4EC43A960BA9B2D0DDBDE9FC118D75E1E8EB7D20E1A105282F4CC88C4D54E3A5D2032EDDCC4B059006FEEFC66149047DD
                Malicious:false
                Reputation:low
                URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=http%3A%2F%2Fs.ksrndkehqnwntyxlhgto.com&oit=3&cp=4&pgcl=4&gs_rn=42&psi=iSR4VaPXe_50Me9V&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                Preview:)]}'.["http://s.ksrndkehqnwntyxlhgto.com",[],[],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:suggesttype":[],"google:verbatimrelevance":851}]
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Nov 25, 2024 19:34:48.174381971 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174400091 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174415112 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174424887 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174432039 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174438000 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.174582005 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:34:48.182697058 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.182755947 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.182816982 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:34:48.191135883 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.191282988 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.191342115 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:34:48.199619055 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:34:48.244977951 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:34:54.593945026 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:54.594291925 CET4970580192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:54.719995022 CET804970418.245.60.90192.168.2.16
                Nov 25, 2024 19:34:54.720113993 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:54.720215082 CET804970518.245.60.90192.168.2.16
                Nov 25, 2024 19:34:54.720271111 CET4970580192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:54.720396996 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:54.847245932 CET804970418.245.60.90192.168.2.16
                Nov 25, 2024 19:34:55.460501909 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:34:55.761692047 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:34:56.032711983 CET804970418.245.60.90192.168.2.16
                Nov 25, 2024 19:34:56.081687927 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:34:56.182605982 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:56.182660103 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:56.182729959 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:56.182997942 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:56.183027983 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:56.365678072 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:34:57.572724104 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:34:57.764997005 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:57.765300035 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:57.765335083 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:57.766318083 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:57.766395092 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:57.767281055 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:57.767350912 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:57.767436028 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:57.767443895 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:57.810662031 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.268033981 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:34:58.268080950 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:34:58.268155098 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:34:58.268382072 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:34:58.268394947 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:34:58.294164896 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:58.294271946 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:58.294331074 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.294785976 CET49707443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.294806004 CET4434970718.245.60.9192.168.2.16
                Nov 25, 2024 19:34:58.359189987 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.359239101 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:34:58.359318018 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.359508038 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:34:58.359519958 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:34:59.980679989 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:35:00.026030064 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:00.026344061 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:00.026395082 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:00.028269053 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:00.028345108 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:00.029469967 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:00.029563904 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:00.057427883 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:00.057701111 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:00.057730913 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:00.058193922 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:00.058542967 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:00.058614969 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:00.058623075 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:00.058634043 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:00.075692892 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:00.075728893 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:00.107672930 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:00.123677015 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:00.143737078 CET4969080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:01.001692057 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:01.001864910 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:01.001918077 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:01.002692938 CET49711443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:01.002717018 CET4434971118.245.60.9192.168.2.16
                Nov 25, 2024 19:35:01.870754004 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:01.870805025 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:01.870883942 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:01.872786045 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:01.872802973 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:02.828257084 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:02.828310013 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:02.829015017 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:02.830037117 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:02.830050945 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:03.272159100 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.272243977 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.276101112 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.276119947 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.276525974 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.314531088 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.355359077 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.622028112 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:03.898207903 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.898277998 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.898344994 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.898387909 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.898406982 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.898417950 CET49713443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.898423910 CET443497132.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.923686028 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:03.928839922 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.928862095 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:03.928926945 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.929227114 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:03.929239988 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:04.524837017 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:04.587549925 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:04.587646008 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:04.590121984 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:04.590132952 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:04.590370893 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:04.636652946 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:04.639832020 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:04.683335066 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:04.780742884 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:35:05.279057980 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.279149055 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.281018019 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.281028032 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.281929970 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.283329010 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.285264015 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285291910 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285300016 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285310030 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285329103 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285363913 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.285391092 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.285402060 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.285442114 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.307488918 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.307559967 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.307586908 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.307598114 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.307663918 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.307712078 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.307724953 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.307742119 CET49714443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:05.307746887 CET443497144.245.163.56192.168.2.16
                Nov 25, 2024 19:35:05.327331066 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.737683058 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:05.780121088 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.780328035 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.780395031 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.781003952 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.781033039 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:05.781045914 CET49715443192.168.2.162.18.109.164
                Nov 25, 2024 19:35:05.781053066 CET443497152.18.109.164192.168.2.16
                Nov 25, 2024 19:35:08.102850914 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:08.150688887 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:08.406709909 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:09.014731884 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:09.704977036 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:09.705041885 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:09.705149889 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:10.228725910 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:11.509258032 CET49710443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:11.509306908 CET44349710142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:12.641788006 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:12.964792013 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:14.381903887 CET49673443192.168.2.16204.79.197.203
                Nov 25, 2024 19:35:17.445744991 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:22.575810909 CET49678443192.168.2.1620.189.173.10
                Nov 25, 2024 19:35:25.870428085 CET804970518.245.60.90192.168.2.16
                Nov 25, 2024 19:35:25.870518923 CET4970580192.168.2.1618.245.60.90
                Nov 25, 2024 19:35:27.046746969 CET4968080192.168.2.16192.229.211.108
                Nov 25, 2024 19:35:27.512228012 CET4970580192.168.2.1618.245.60.90
                Nov 25, 2024 19:35:27.634025097 CET804970518.245.60.90192.168.2.16
                Nov 25, 2024 19:35:39.260421991 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:39.260489941 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:39.260570049 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:39.260796070 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:39.260816097 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:41.005521059 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:41.005825043 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:41.005881071 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:41.006211042 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:41.006503105 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:41.006572962 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:41.043771029 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:35:41.059761047 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:41.169354916 CET804970418.245.60.90192.168.2.16
                Nov 25, 2024 19:35:41.655662060 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:41.655730963 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:41.655824900 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:41.656152964 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:41.656167030 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:43.477581024 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:43.477670908 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:43.478925943 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:43.478938103 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:43.479435921 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:43.480707884 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:43.523332119 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.196536064 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.196594000 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.196634054 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.196677923 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.196705103 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.196734905 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.196757078 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.237631083 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.237693071 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.237725973 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.237744093 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.237744093 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.237849951 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.237860918 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.237873077 CET49717443192.168.2.164.245.163.56
                Nov 25, 2024 19:35:44.237879992 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:44.237890005 CET443497174.245.163.56192.168.2.16
                Nov 25, 2024 19:35:47.431948900 CET4969880192.168.2.16178.79.238.128
                Nov 25, 2024 19:35:47.431966066 CET4970080192.168.2.16178.79.238.128
                Nov 25, 2024 19:35:47.560334921 CET8049698178.79.238.128192.168.2.16
                Nov 25, 2024 19:35:47.560400963 CET4969880192.168.2.16178.79.238.128
                Nov 25, 2024 19:35:47.561467886 CET8049700178.79.238.128192.168.2.16
                Nov 25, 2024 19:35:47.561543941 CET4970080192.168.2.16178.79.238.128
                Nov 25, 2024 19:35:50.040312052 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:50.083343029 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:50.722115993 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:50.724452972 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:50.724533081 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:50.731174946 CET49716443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:50.731221914 CET44349716142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:51.106910944 CET4971880192.168.2.1618.245.60.90
                Nov 25, 2024 19:35:51.130043030 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:51.130137920 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:51.130248070 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:51.130568027 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:51.130616903 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:51.227205038 CET804971818.245.60.90192.168.2.16
                Nov 25, 2024 19:35:51.227300882 CET4971880192.168.2.1618.245.60.90
                Nov 25, 2024 19:35:52.764951944 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:52.765398026 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:52.765460968 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:52.765822887 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:52.766141891 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:52.766216993 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:52.766264915 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:52.807336092 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:52.817805052 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:53.704761028 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:53.705359936 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:53.705421925 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:53.705624104 CET49719443192.168.2.1618.245.60.9
                Nov 25, 2024 19:35:53.705676079 CET4434971918.245.60.9192.168.2.16
                Nov 25, 2024 19:35:58.192820072 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:58.192862988 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:58.192974091 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:58.193181038 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:58.193196058 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:59.893016100 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:59.893335104 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:59.893363953 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:59.893687010 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:59.894095898 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:35:59.894196987 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:35:59.949897051 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:09.603405952 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:36:09.603475094 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:36:09.603682041 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:11.504230976 CET49721443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:11.504265070 CET44349721142.250.181.68192.168.2.16
                Nov 25, 2024 19:36:22.371903896 CET804971818.245.60.90192.168.2.16
                Nov 25, 2024 19:36:22.372112989 CET4971880192.168.2.1618.245.60.90
                Nov 25, 2024 19:36:23.203733921 CET4971880192.168.2.1618.245.60.90
                Nov 25, 2024 19:36:23.329447031 CET804971818.245.60.90192.168.2.16
                Nov 25, 2024 19:36:26.172931910 CET4970480192.168.2.1618.245.60.90
                Nov 25, 2024 19:36:26.295331955 CET804970418.245.60.90192.168.2.16
                Nov 25, 2024 19:36:30.876152039 CET49696443192.168.2.1620.190.147.0
                Nov 25, 2024 19:36:30.876359940 CET4969780192.168.2.16192.229.221.95
                Nov 25, 2024 19:36:30.997884035 CET4434969620.190.147.0192.168.2.16
                Nov 25, 2024 19:36:30.998090982 CET49696443192.168.2.1620.190.147.0
                Nov 25, 2024 19:36:30.998325109 CET8049697192.229.221.95192.168.2.16
                Nov 25, 2024 19:36:30.998404026 CET4969780192.168.2.16192.229.221.95
                Nov 25, 2024 19:36:35.816201925 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:36:35.941663980 CET4434969920.190.147.0192.168.2.16
                Nov 25, 2024 19:36:35.941864967 CET49699443192.168.2.1620.190.147.0
                Nov 25, 2024 19:36:58.249037027 CET49723443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:58.249079943 CET44349723142.250.181.68192.168.2.16
                Nov 25, 2024 19:36:58.249181986 CET49723443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:58.249521017 CET49723443192.168.2.16142.250.181.68
                Nov 25, 2024 19:36:58.249535084 CET44349723142.250.181.68192.168.2.16
                TimestampSource PortDest PortSource IPDest IP
                Nov 25, 2024 19:34:53.453252077 CET53523841.1.1.1192.168.2.16
                Nov 25, 2024 19:34:53.468729973 CET53631451.1.1.1192.168.2.16
                Nov 25, 2024 19:34:54.267447948 CET5344553192.168.2.161.1.1.1
                Nov 25, 2024 19:34:54.267792940 CET5061653192.168.2.161.1.1.1
                Nov 25, 2024 19:34:54.406770945 CET53506161.1.1.1192.168.2.16
                Nov 25, 2024 19:34:54.593180895 CET53534451.1.1.1192.168.2.16
                Nov 25, 2024 19:34:56.036570072 CET5111353192.168.2.161.1.1.1
                Nov 25, 2024 19:34:56.036751986 CET5820353192.168.2.161.1.1.1
                Nov 25, 2024 19:34:56.179882050 CET53511131.1.1.1192.168.2.16
                Nov 25, 2024 19:34:56.182096004 CET53582031.1.1.1192.168.2.16
                Nov 25, 2024 19:34:56.414354086 CET53572041.1.1.1192.168.2.16
                Nov 25, 2024 19:34:58.128523111 CET5202553192.168.2.161.1.1.1
                Nov 25, 2024 19:34:58.128675938 CET6488053192.168.2.161.1.1.1
                Nov 25, 2024 19:34:58.267038107 CET53520251.1.1.1192.168.2.16
                Nov 25, 2024 19:34:58.267057896 CET53648801.1.1.1192.168.2.16
                Nov 25, 2024 19:35:13.421895027 CET53642291.1.1.1192.168.2.16
                Nov 25, 2024 19:35:32.469012976 CET53653451.1.1.1192.168.2.16
                Nov 25, 2024 19:35:53.390532970 CET53522181.1.1.1192.168.2.16
                Nov 25, 2024 19:35:55.284250975 CET53527581.1.1.1192.168.2.16
                Nov 25, 2024 19:35:59.796555042 CET138138192.168.2.16192.168.2.255
                Nov 25, 2024 19:36:23.347421885 CET53589171.1.1.1192.168.2.16
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Nov 25, 2024 19:34:54.267447948 CET192.168.2.161.1.1.10x22f9Standard query (0)s.ksrndkehqnwntyxlhgto.comA (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:54.267792940 CET192.168.2.161.1.1.10xc76bStandard query (0)s.ksrndkehqnwntyxlhgto.com65IN (0x0001)false
                Nov 25, 2024 19:34:56.036570072 CET192.168.2.161.1.1.10xed1fStandard query (0)s.ksrndkehqnwntyxlhgto.comA (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:56.036751986 CET192.168.2.161.1.1.10x51bdStandard query (0)s.ksrndkehqnwntyxlhgto.com65IN (0x0001)false
                Nov 25, 2024 19:34:58.128523111 CET192.168.2.161.1.1.10x1977Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:58.128675938 CET192.168.2.161.1.1.10xaea0Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Nov 25, 2024 19:34:54.593180895 CET1.1.1.1192.168.2.160x22f9No error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.90A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:54.593180895 CET1.1.1.1192.168.2.160x22f9No error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.77A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:54.593180895 CET1.1.1.1192.168.2.160x22f9No error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.3A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:54.593180895 CET1.1.1.1192.168.2.160x22f9No error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.9A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:56.179882050 CET1.1.1.1192.168.2.160xed1fNo error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.9A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:56.179882050 CET1.1.1.1192.168.2.160xed1fNo error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.77A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:56.179882050 CET1.1.1.1192.168.2.160xed1fNo error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.3A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:56.179882050 CET1.1.1.1192.168.2.160xed1fNo error (0)s.ksrndkehqnwntyxlhgto.com18.245.60.90A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:58.267038107 CET1.1.1.1192.168.2.160x1977No error (0)www.google.com142.250.181.68A (IP address)IN (0x0001)false
                Nov 25, 2024 19:34:58.267057896 CET1.1.1.1192.168.2.160xaea0No error (0)www.google.com65IN (0x0001)false
                • s.ksrndkehqnwntyxlhgto.com
                • https:
                • slscr.update.microsoft.com
                • fs.microsoft.com
                • www.google.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.164970418.245.60.90807004C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Nov 25, 2024 19:34:54.720396996 CET441OUTGET / HTTP/1.1
                Host: s.ksrndkehqnwntyxlhgto.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Nov 25, 2024 19:34:56.032711983 CET576INHTTP/1.1 301 Moved Permanently
                Server: CloudFront
                Date: Mon, 25 Nov 2024 18:34:55 GMT
                Content-Type: text/html
                Content-Length: 167
                Connection: keep-alive
                Location: https://s.ksrndkehqnwntyxlhgto.com/
                X-Cache: Redirect from cloudfront
                Via: 1.1 c9b44fbd4230c7c5b0750a98fbcd9df6.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: FRA60-P5
                X-Amz-Cf-Id: 1xjbZ0QJhtn5tje90NYRw3LIYgj2GiRvdtW7UquMeaYhsXPWhAvPJQ==
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 43 6c 6f 75 64 46 72 6f 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>CloudFront</center></body></html>
                Nov 25, 2024 19:35:41.043771029 CET6OUTData Raw: 00
                Data Ascii:
                Nov 25, 2024 19:36:26.172931910 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.164970718.245.60.94437004C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-11-25 18:34:57 UTC669OUTGET / HTTP/1.1
                Host: s.ksrndkehqnwntyxlhgto.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-11-25 18:34:58 UTC481INHTTP/1.1 200 OK
                Content-Type: text/plain
                Content-Length: 20
                Connection: close
                Date: Mon, 25 Nov 2024 01:24:59 GMT
                Last-Modified: Wed, 13 Jun 2018 16:12:20 GMT
                ETag: "dc5bcbf7f9372ccc9aedb581fe88edfe"
                x-amz-version-id: null
                Accept-Ranges: bytes
                Server: AmazonS3
                X-Cache: Hit from cloudfront
                Via: 1.1 b459d8cae3f218ce39711fc3ecdcc998.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: FRA60-P5
                X-Amz-Cf-Id: HzitxRG_nqb4tFu86cD9ZOhNFCz-UdFgjrW9zkFu9D2UEj-DL1000w==
                Age: 61800
                2024-11-25 18:34:58 UTC20INData Raw: 4e 6f 74 68 69 6e 67 20 74 6f 20 73 65 65 20 68 65 72 65 2e
                Data Ascii: Nothing to see here.


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.164971118.245.60.94437004C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:00 UTC608OUTGET /favicon.ico HTTP/1.1
                Host: s.ksrndkehqnwntyxlhgto.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://s.ksrndkehqnwntyxlhgto.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-11-25 18:35:00 UTC357INHTTP/1.1 403 Forbidden
                Content-Type: application/xml
                Transfer-Encoding: chunked
                Connection: close
                Server: AmazonS3
                Date: Mon, 25 Nov 2024 18:35:00 GMT
                X-Cache: Error from cloudfront
                Via: 1.1 5cf26f8164e0cad37f6634ff6aeac4ce.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: FRA60-P5
                X-Amz-Cf-Id: AVf1npSVGLuDCW7X1BO31pZIai2Bp-Nx899T9k_R7Rl8swlxg7sgbg==
                2024-11-25 18:35:00 UTC282INData Raw: 31 31 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 4b 33 30 38 32 31 4b 48 58 4a 51 43 37 46 4d 59 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 68 48 79 75 32 2f 31 41 79 75 6f 74 4f 45 38 51 4a 31 33 62 72 79 77 48 62 55 54 36 50 36 78 37 48 34 2b 63 4f 4e 30 54 65 46 74 55 38 48 75 46 31 62 54 42 6d 4a 42 47 6d 48 49 49 6c 64 64 6a 47 6f 4e 76 6b 73 35 66 54 55 7a 49 50 7a 55 33 79 68 69 64 67 75 39 64 67 62 56 42 33 63 5a 31 30 6b 79 75
                Data Ascii: 113<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>K30821KHXJQC7FMY</RequestId><HostId>hHyu2/1AyuotOE8QJ13brywHbUT6P6x7H4+cON0TeFtU8HuF1bTBmJBGmHIIlddjGoNvks5fTUzIPzU3yhidgu9dgbVB3cZ10kyu
                2024-11-25 18:35:00 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.16497132.18.109.164443
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:03 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-11-25 18:35:03 UTC478INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Server: Kestrel
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-OSID: 2
                X-CID: 2
                X-CCC: GB
                Cache-Control: public, max-age=53872
                Date: Mon, 25 Nov 2024 18:35:03 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.16497144.245.163.56443
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:04 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=HKMDLL9PR+zaBhB&MD=+lLD4y3r HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2024-11-25 18:35:05 UTC560INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                MS-CorrelationId: 5720bc7a-373f-4c5f-b9d7-b93620344dcd
                MS-RequestId: d58a02e9-859c-48f0-80a3-d1e33118217e
                MS-CV: Mlk9+traikKm9oIb.0
                X-Microsoft-SLSClientCache: 2880
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Mon, 25 Nov 2024 18:35:04 GMT
                Connection: close
                Content-Length: 24490
                2024-11-25 18:35:05 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                2024-11-25 18:35:05 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.16497152.18.109.164443
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:05 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-11-25 18:35:05 UTC534INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                Cache-Control: public, max-age=53896
                Date: Mon, 25 Nov 2024 18:35:05 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-11-25 18:35:05 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.16497174.245.163.56443
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:43 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=HKMDLL9PR+zaBhB&MD=+lLD4y3r HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2024-11-25 18:35:44 UTC560INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                MS-CorrelationId: c346dd8f-0f20-4aff-b409-1e92e53a840f
                MS-RequestId: 894e430b-da57-4572-b61f-1331be3c8ae5
                MS-CV: t3q11UQxrUmhl40+.0
                X-Microsoft-SLSClientCache: 1440
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Mon, 25 Nov 2024 18:35:43 GMT
                Connection: close
                Content-Length: 30005
                2024-11-25 18:35:44 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                2024-11-25 18:35:44 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.1649716142.250.181.684437004C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:50 UTC685OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=http%3A%2F%2Fs.ksrndkehqnwntyxlhgto.com&oit=3&cp=4&pgcl=4&gs_rn=42&psi=iSR4VaPXe_50Me9V&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIk6HLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUX
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-11-25 18:35:50 UTC1266INHTTP/1.1 200 OK
                Date: Mon, 25 Nov 2024 18:35:50 GMT
                Pragma: no-cache
                Expires: -1
                Cache-Control: no-cache, must-revalidate
                Content-Type: text/javascript; charset=UTF-8
                Strict-Transport-Security: max-age=31536000
                Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-bkyq5Meh2n8b_5Ye5HkS6A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                Accept-CH: Sec-CH-Prefers-Color-Scheme
                Accept-CH: Sec-CH-UA-Form-Factors
                Accept-CH: Sec-CH-UA-Platform
                Accept-CH: Sec-CH-UA-Platform-Version
                Accept-CH: Sec-CH-UA-Full-Version
                Accept-CH: Sec-CH-UA-Arch
                Accept-CH: Sec-CH-UA-Model
                Accept-CH: Sec-CH-UA-Bitness
                Accept-CH: Sec-CH-UA-Full-Version-List
                Accept-CH: Sec-CH-UA-WoW64
                Permissions-Policy: unload=()
                Content-Disposition: attachment; filename="f.txt"
                Server: gws
                X-XSS-Protection: 0
                X-Frame-Options: SAMEORIGIN
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-11-25 18:35:50 UTC124INData Raw: 39 61 0d 0a 29 5d 7d 27 0a 5b 22 68 74 74 70 3a 2f 2f 73 2e 6b 73 72 6e 64 6b 65 68 71 6e 77 6e 74 79 78 6c 68 67 74 6f 2e 63 6f 6d 22 2c 5b 5d 2c 5b 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 74 79 70 65 22 3a 5b
                Data Ascii: 9a)]}'["http://s.ksrndkehqnwntyxlhgto.com",[],[],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:suggesttype":[
                2024-11-25 18:35:50 UTC36INData Raw: 5d 2c 22 67 6f 6f 67 6c 65 3a 76 65 72 62 61 74 69 6d 72 65 6c 65 76 61 6e 63 65 22 3a 38 35 31 7d 5d 0d 0a
                Data Ascii: ],"google:verbatimrelevance":851}]
                2024-11-25 18:35:50 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                7192.168.2.164971918.245.60.94437004C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-11-25 18:35:52 UTC608OUTGET /favicon.ico HTTP/1.1
                Host: s.ksrndkehqnwntyxlhgto.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://s.ksrndkehqnwntyxlhgto.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-11-25 18:35:53 UTC357INHTTP/1.1 403 Forbidden
                Content-Type: application/xml
                Transfer-Encoding: chunked
                Connection: close
                Server: AmazonS3
                Date: Mon, 25 Nov 2024 18:35:52 GMT
                X-Cache: Error from cloudfront
                Via: 1.1 0254a3d4b384cab4933ea28efe6685c2.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: FRA60-P5
                X-Amz-Cf-Id: RPiFYZ_vxQolLLdYwe8-yFH_B1H9HPRhpNy8SWv8z8qrlCGGr4ErMQ==
                2024-11-25 18:35:53 UTC249INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 50 4d 42 58 35 50 36 33 48 4d 44 44 37 30 4d 39 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 78 39 72 74 32 4f 6c 71 4c 55 36 76 66 41 71 38 6a 77 2b 58 7a 54 71 6f 55 75 4c 75 37 31 63 48 77 75 72 32 45 6a 44 33 51 76 41 4a 67 4e 4f 79 59 61 77 46 58 4d 47 42 4f 4a 72 54 44 35 4c 46 4f 73 5a 66 2b 46 45 67 35 69 55 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a
                Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>PMBX5P63HMDD70M9</RequestId><HostId>x9rt2OlqLU6vfAq8jw+XzTqoUuLu71cHwur2EjD3QvAJgNOyYawFXMGBOJrTD5LFOsZf+FEg5iU=</HostId></Error>
                2024-11-25 18:35:53 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:13:34:51
                Start date:25/11/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff7f9810000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:13:34:51
                Start date:25/11/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1936,i,13978813817988735767,11448808675129081722,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff7f9810000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:13:34:52
                Start date:25/11/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.ksrndkehqnwntyxlhgto.com"
                Imagebase:0x7ff7f9810000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly