Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49740 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49825 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49939 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50000 version: TLS 1.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49674 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49672 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49740 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49740 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 50000 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49719 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 50000 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49825 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49939 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49719 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49939 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49825 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49999 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49999 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49740 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49825 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49939 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50000 version: TLS 1.2 |
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2044,i,2681339334101602418,8801684867977286478,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
|
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-light.woff2" |
|
Source: unknown |
Process created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2044,i,2681339334101602418,8801684867977286478,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: twinui.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: pdh.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: actxprxy.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.ui.appdefaults.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.ui.immersive.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: uiautomationcore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dui70.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: duser.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: bcp47mrm.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: uianimation.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.ui.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windowmanagementapi.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: inputhost.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: thumbcache.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: tiledatarepository.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: staterepository.core.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.staterepository.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: windows.staterepositorycore.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: mrmcorer.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: appxdeploymentclient.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: directmanipulation.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |