Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://o28sy4q7wu-dsn.algolia.net

Overview

General Information

Sample URL:http://o28sy4q7wu-dsn.algolia.net
Analysis ID:1592532
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 4396 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3356 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=1984,i,14920574979149296530,234398221182212426,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://algolia.net/1/404HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /1/404 HTTP/1.1Host: algolia.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: algolia.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://algolia.net/1/404Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /1/404 HTTP/1.1Host: algolia.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://algolia.net/1/404Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: o28sy4q7wu-dsn.algolia.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: o28sy4q7wu-dsn.algolia.net
Source: global trafficDNS traffic detected: DNS query: algolia.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 16 Jan 2025 08:07:32 GMTContent-Type: application/json; charset=UTF-8Content-Length: 164Connection: closeAccess-Control-Allow-Origin: *Timing-Allow-Origin: *X-Content-Type-Options: nosniffStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Disposition: inline; filename=a.txt
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 16 Jan 2025 08:07:34 GMTContent-Type: application/json; charset=UTF-8Content-Length: 164Connection: closeAccess-Control-Allow-Origin: *Timing-Allow-Origin: *X-Content-Type-Options: nosniffStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Disposition: inline; filename=a.txt
Source: chromecache_60.2.drString found in binary or memory: https://www.algolia.com/doc/rest-api/search/
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49993 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: classification engineClassification label: clean0.win@17/8@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=1984,i,14920574979149296530,234398221182212426,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=1984,i,14920574979149296530,234398221182212426,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://o28sy4q7wu-dsn.algolia.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
d124-use-2.algolia.net
162.210.192.5
truefalse
    unknown
    www.google.com
    216.58.212.164
    truefalse
      high
      algolia.net
      149.202.84.123
      truefalse
        high
        o28sy4q7wu-dsn.algolia.net
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          http://o28sy4q7wu-dsn.algolia.net/false
            high
            https://algolia.net/1/404false
              high
              https://algolia.net/favicon.icofalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.algolia.com/doc/rest-api/search/chromecache_60.2.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.212.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  162.210.192.5
                  d124-use-2.algolia.netUnited States
                  30633LEASEWEB-USA-WDCUSfalse
                  149.202.84.123
                  algolia.netFrance
                  16276OVHFRfalse
                  IP
                  192.168.2.6
                  192.168.2.5
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1592532
                  Start date and time:2025-01-16 09:06:26 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 2m 55s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://o28sy4q7wu-dsn.algolia.net
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:7
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@17/8@6/6
                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.181.227, 172.217.18.14, 64.233.184.84, 142.250.186.174, 142.250.184.206, 199.232.214.172, 2.23.77.188, 142.250.74.206, 142.250.186.78, 142.250.181.238, 142.250.185.131, 184.28.90.27, 13.107.253.45, 172.202.163.200, 20.12.23.50
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                  • Not all processes where analyzed, report is missing behavior information
                  • VT rate limit hit for: http://o28sy4q7wu-dsn.algolia.net
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 07:07:25 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2677
                  Entropy (8bit):3.981086296214199
                  Encrypted:false
                  SSDEEP:48:8jdMTw92oHMidAKZdA19ehwiZUklqehLy+3:8iw2vMy
                  MD5:0A1F0575954A9B32EA1A2CD16879EF4C
                  SHA1:3B5E547AE6D7673FAF212507044A7A24ACE1CC07
                  SHA-256:0470BBD9785AEB2347C59A6CA0FDBFB61D5AB995009A39EE27B32567761D9C65
                  SHA-512:E270317A0E23DADF25CE0A350194A64AD914C05CFE30D57C9E33C8BF86A6CDE87DB98255FEBD09E485343AE2CF2A3900012C506F5264C2689D0C25966742E28D
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,........g..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V0Z.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 07:07:25 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2679
                  Entropy (8bit):3.9977605039004143
                  Encrypted:false
                  SSDEEP:48:8NVdMTw92oHMidAKZdA1weh/iZUkAQkqeh8y+2:8Nkw2V9Q5y
                  MD5:84DF4CD07BEE58FE96F66FEA108DDF90
                  SHA1:1FEFB1685279E69BCE6249C2E607C0EDEA9801D4
                  SHA-256:C994CC9CDFB1B1D376BFEEE545CA6197F702D47C8C60A4DE7534C139E4300240
                  SHA-512:1F62A836C3B11EDB52C31C6762A030D6FC68752FE1719D62AF7432C3A351DDA267B91734D0F7729DC2C2D097C5943DCD1E9FD6A5758C51A00983B03A131C063A
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,....$...g..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V0Z.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2693
                  Entropy (8bit):4.008682722632383
                  Encrypted:false
                  SSDEEP:48:8xZdMTw92sHMidAKZdA14tseh7sFiZUkmgqeh7sKy+BX:8xIw2Jnwy
                  MD5:1636F33CE6D1314F243491958C037701
                  SHA1:75C223E4BBD331E413B0E111708AF5DDB162B047
                  SHA-256:7428BDD65113D634BEA7AAB47BCD851994A29E180462738F26CE53DAB139813F
                  SHA-512:723984714841EECF2292F08D2F5B5D542CB9D1D392FFA265C17B62BB84EB3D7E05DFDBE3613EE64DDA8D03233DCD45A664976638269A638BF8A3F290C0013C3D
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 07:07:25 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2681
                  Entropy (8bit):3.9968348980382946
                  Encrypted:false
                  SSDEEP:48:8IdMTw92oHMidAKZdA1vehDiZUkwqehoy+R:8Tw22iy
                  MD5:37254814F1F1BBACA964E263BF506788
                  SHA1:2EF05BAC431D3E8236C4397DA764F8A96A206E37
                  SHA-256:35E0BEA05E6819CB8F55BE50CD734F014EA16A8EAB1C34C940978D0508888A7B
                  SHA-512:349D65506ED41CB8F7D1A61BBC89A6B69EBBAD7F91F5156CAEEC9E2C7B962CDD89044602A24680BAB40165E902964DCC9332B6D1FDEDAD97CAF1ED5DC58DAFE9
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,........g..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V0Z.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 07:07:25 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2681
                  Entropy (8bit):3.9856863840769785
                  Encrypted:false
                  SSDEEP:48:8ldMTw92oHMidAKZdA1hehBiZUk1W1qehuy+C:80w2W9Oy
                  MD5:5BFEA09A890C0E034DF069A8383A9D62
                  SHA1:06B409A5859CBD6C818950C7B7AEBB66C63E540A
                  SHA-256:DD7C9D4DDD19C353031CCAA7D397A884CD51827121A74E4D6339AD51C679AC1A
                  SHA-512:D5BDA2871F8A3BCCDD9E1B335A03C7AB574E2256B172ADC755F6E757473BB33E959A11F5A76009F65A389359E7AA1E4390253935AD78BAAA5490F304258CA3A7
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,........g..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V0Z.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 07:07:25 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2683
                  Entropy (8bit):3.99664135256747
                  Encrypted:false
                  SSDEEP:48:8sodMTw92oHMidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbwy+yT+:8szw2oT/TbxWOvTbwy7T
                  MD5:C13C7408CD51077D8C40D899F31D82ED
                  SHA1:4C32A22D4EFAD4E65F8FF29D253DB3713015866D
                  SHA-256:3FABEBAC5ADF70E90C13DA73AC077B970BD7397A72C27111E85F1B115FFD1117
                  SHA-512:7E14D14266FF03E142DCCD4DE43494D9F63E3FC1BCBCD5852C56B6B2016CCBE2F5AFA3ACAB6D0D23399B799E95C5DB21810D5653AB236CA8B2F0F516923213D3
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,.......g..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I0Z.@....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0Z.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V0Z.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V0Z.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V0Z.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............G.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:JSON data
                  Category:downloaded
                  Size (bytes):164
                  Entropy (8bit):4.765689469062448
                  Encrypted:false
                  SSDEEP:3:YIzVErxKBiAIFkMKJMsMzEWAqA6NurSLHKCELKdXAEiBQST2DqJMzdkgHJ2ybL+n:YIh6LeMSM2WNuGLfEmdXMBQkCigp2cL+
                  MD5:BFED3480E14E9AF6C6921AE50973BC20
                  SHA1:D057F00DD0AA2FFCF743292D7313B665ABC971D9
                  SHA-256:81A1AC294C869F14D7EB4ABB5135E55DAFC98D938BE17536146C469AFE88D18D
                  SHA-512:8C95C435A1C69BA190B22EA0DBEAABA1235A19B083709BABD6A3B824A71340A929D29EA3E35869B10D9BFA6C4799104D4C07725A6C720A0969D47EE5789066F1
                  Malicious:false
                  Reputation:low
                  URL:https://algolia.net/1/404
                  Preview:{"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 16, 2025 09:07:17.619693041 CET49675443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:17.619807005 CET49674443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:17.729032993 CET49673443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:27.235968113 CET49675443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:27.329705000 CET49673443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:27.392249107 CET49674443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:28.982466936 CET4434970323.1.237.91192.168.2.5
                  Jan 16, 2025 09:07:28.982578039 CET49703443192.168.2.523.1.237.91
                  Jan 16, 2025 09:07:29.026527882 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.026588917 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.026721001 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.026936054 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.026964903 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.706000090 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.706476927 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.706515074 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.707958937 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.708038092 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.709319115 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.709409952 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.751374006 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:29.751394987 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:29.798247099 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:30.938848019 CET4971580192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:30.940589905 CET4971680192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:30.943646908 CET8049715162.210.192.5192.168.2.5
                  Jan 16, 2025 09:07:30.943749905 CET4971580192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:30.943905115 CET4971580192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:30.945395947 CET8049716162.210.192.5192.168.2.5
                  Jan 16, 2025 09:07:30.945576906 CET4971680192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:30.948729038 CET8049715162.210.192.5192.168.2.5
                  Jan 16, 2025 09:07:31.405740023 CET8049715162.210.192.5192.168.2.5
                  Jan 16, 2025 09:07:31.418643951 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:31.418706894 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:31.418797016 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:31.419089079 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:31.419116020 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:31.453694105 CET4971580192.168.2.5162.210.192.5
                  Jan 16, 2025 09:07:32.043585062 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.043853998 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.043901920 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.045558929 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.045684099 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.049940109 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.050033092 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.050132036 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.091345072 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.095647097 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.095669985 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.142575979 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.282243967 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.282413960 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.282862902 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.305401087 CET49717443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.305449963 CET44349717149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.380465984 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.380549908 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:32.380985022 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.381311893 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:32.381350040 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.027815104 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.028305054 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.028352976 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.028848886 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.029165030 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.029263020 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.029536009 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.071357965 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.282298088 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.282388926 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.282469988 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.283920050 CET49718443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.283951998 CET44349718149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.286489964 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.286573887 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.286663055 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.286951065 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.286983967 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.911160946 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.911569118 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.911616087 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.912781000 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.913137913 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.913275003 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:33.913316965 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:33.970427036 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:34.162952900 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:34.163139105 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:34.163209915 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:34.163868904 CET49719443192.168.2.5149.202.84.123
                  Jan 16, 2025 09:07:34.163896084 CET44349719149.202.84.123192.168.2.5
                  Jan 16, 2025 09:07:39.591188908 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:39.591372967 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:07:39.591528893 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:41.379369974 CET49712443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:07:41.379439116 CET44349712216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:15.954440117 CET4971680192.168.2.5162.210.192.5
                  Jan 16, 2025 09:08:15.959264040 CET8049716162.210.192.5192.168.2.5
                  Jan 16, 2025 09:08:16.407577038 CET4971580192.168.2.5162.210.192.5
                  Jan 16, 2025 09:08:16.413857937 CET8049715162.210.192.5192.168.2.5
                  Jan 16, 2025 09:08:29.081949949 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:29.082045078 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.082135916 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:29.082552910 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:29.082590103 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.730818987 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.731439114 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:29.731504917 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.732568026 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.733282089 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:29.733386993 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:29.783351898 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:31.378743887 CET4971680192.168.2.5162.210.192.5
                  Jan 16, 2025 09:08:31.383780003 CET8049716162.210.192.5192.168.2.5
                  Jan 16, 2025 09:08:31.383863926 CET4971680192.168.2.5162.210.192.5
                  Jan 16, 2025 09:08:39.642157078 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:39.642249107 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:39.642471075 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:41.378650904 CET49993443192.168.2.5216.58.212.164
                  Jan 16, 2025 09:08:41.378683090 CET44349993216.58.212.164192.168.2.5
                  Jan 16, 2025 09:08:46.407044888 CET8049715162.210.192.5192.168.2.5
                  Jan 16, 2025 09:08:46.407104969 CET4971580192.168.2.5162.210.192.5
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 16, 2025 09:07:25.087097883 CET53531991.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:25.089595079 CET53555971.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:26.264609098 CET53568001.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:29.018531084 CET5141853192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:29.018871069 CET4919453192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:29.025432110 CET53491941.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:29.025549889 CET53514181.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:30.920583010 CET5138453192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:30.920784950 CET5179353192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:30.935401917 CET53517931.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:30.937609911 CET53513841.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:31.408791065 CET6088853192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:31.409369946 CET5014753192.168.2.51.1.1.1
                  Jan 16, 2025 09:07:31.415915012 CET53608881.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:31.418112040 CET53501471.1.1.1192.168.2.5
                  Jan 16, 2025 09:07:43.322885990 CET53517921.1.1.1192.168.2.5
                  Jan 16, 2025 09:08:02.369302988 CET53525381.1.1.1192.168.2.5
                  Jan 16, 2025 09:08:24.667181969 CET53570471.1.1.1192.168.2.5
                  Jan 16, 2025 09:08:25.447617054 CET53503451.1.1.1192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Jan 16, 2025 09:07:29.018531084 CET192.168.2.51.1.1.10x1548Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:29.018871069 CET192.168.2.51.1.1.10x7131Standard query (0)www.google.com65IN (0x0001)false
                  Jan 16, 2025 09:07:30.920583010 CET192.168.2.51.1.1.10xe017Standard query (0)o28sy4q7wu-dsn.algolia.netA (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:30.920784950 CET192.168.2.51.1.1.10x899Standard query (0)o28sy4q7wu-dsn.algolia.net65IN (0x0001)false
                  Jan 16, 2025 09:07:31.408791065 CET192.168.2.51.1.1.10x4b74Standard query (0)algolia.netA (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:31.409369946 CET192.168.2.51.1.1.10xa430Standard query (0)algolia.net65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Jan 16, 2025 09:07:29.025432110 CET1.1.1.1192.168.2.50x7131No error (0)www.google.com65IN (0x0001)false
                  Jan 16, 2025 09:07:29.025549889 CET1.1.1.1192.168.2.50x1548No error (0)www.google.com216.58.212.164A (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:30.935401917 CET1.1.1.1192.168.2.50x899No error (0)o28sy4q7wu-dsn.algolia.netdsn.o28sy4q7wu.api.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Jan 16, 2025 09:07:30.935401917 CET1.1.1.1192.168.2.50x899No error (0)dsn.o28sy4q7wu.api.algolia.netd124-use-1.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Jan 16, 2025 09:07:30.937609911 CET1.1.1.1192.168.2.50xe017No error (0)o28sy4q7wu-dsn.algolia.netdsn.o28sy4q7wu.api.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Jan 16, 2025 09:07:30.937609911 CET1.1.1.1192.168.2.50xe017No error (0)dsn.o28sy4q7wu.api.algolia.netd124-use-2.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Jan 16, 2025 09:07:30.937609911 CET1.1.1.1192.168.2.50xe017No error (0)d124-use-2.algolia.net162.210.192.5A (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:31.415915012 CET1.1.1.1192.168.2.50x4b74No error (0)algolia.net149.202.84.123A (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:31.415915012 CET1.1.1.1192.168.2.50x4b74No error (0)algolia.net103.254.154.6A (IP address)IN (0x0001)false
                  Jan 16, 2025 09:07:31.415915012 CET1.1.1.1192.168.2.50x4b74No error (0)algolia.net91.109.20.242A (IP address)IN (0x0001)false
                  • algolia.net
                  • https:
                  • o28sy4q7wu-dsn.algolia.net
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.549715162.210.192.5803356C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Jan 16, 2025 09:07:30.943905115 CET441OUTGET / HTTP/1.1
                  Host: o28sy4q7wu-dsn.algolia.net
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Jan 16, 2025 09:07:31.405740023 CET517INHTTP/1.1 301 Moved Permanently
                  Server: nginx
                  Date: Thu, 16 Jan 2025 08:07:31 GMT
                  Content-Type: text/html
                  Content-Length: 162
                  Connection: keep-alive
                  Location: https://algolia.net/1/404
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
                  Jan 16, 2025 09:08:16.407577038 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.549716162.210.192.5803356C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Jan 16, 2025 09:08:15.954440117 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.549717149.202.84.1234433356C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-01-16 08:07:32 UTC659OUTGET /1/404 HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-01-16 08:07:32 UTC372INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Thu, 16 Jan 2025 08:07:32 GMT
                  Content-Type: application/json; charset=UTF-8
                  Content-Length: 164
                  Connection: close
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Content-Disposition: inline; filename=a.txt
                  2025-01-16 08:07:32 UTC164INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 50 61 74 68 20 6e 6f 74 20 73 75 70 70 6f 72 74 65 64 20 62 79 20 41 6c 67 6f 6c 69 61 20 52 45 53 54 20 41 50 49 2e 20 50 6c 65 61 73 65 20 68 61 76 65 20 61 20 6c 6f 6f 6b 20 61 74 20 68 74 74 70 73 3a 2f 2f 77 77 77 2e 61 6c 67 6f 6c 69 61 2e 63 6f 6d 2f 64 6f 63 2f 72 65 73 74 2d 61 70 69 2f 73 65 61 72 63 68 2f 20 66 6f 72 20 74 68 65 20 6c 69 73 74 20 6f 66 20 76 61 6c 69 64 20 63 6f 6d 6d 61 6e 64 73 22 2c 22 73 74 61 74 75 73 22 3a 34 30 34 7d
                  Data Ascii: {"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.549718149.202.84.1234433356C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-01-16 08:07:33 UTC583OUTGET /favicon.ico HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://algolia.net/1/404
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-01-16 08:07:33 UTC350INHTTP/1.1 301 Moved Permanently
                  Server: nginx
                  Date: Thu, 16 Jan 2025 08:07:33 GMT
                  Content-Type: text/html
                  Content-Length: 162
                  Connection: close
                  Location: https://algolia.net/1/404
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  2025-01-16 08:07:33 UTC162INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.549719149.202.84.1234433356C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-01-16 08:07:33 UTC577OUTGET /1/404 HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://algolia.net/1/404
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-01-16 08:07:34 UTC372INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Thu, 16 Jan 2025 08:07:34 GMT
                  Content-Type: application/json; charset=UTF-8
                  Content-Length: 164
                  Connection: close
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Content-Disposition: inline; filename=a.txt
                  2025-01-16 08:07:34 UTC164INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 50 61 74 68 20 6e 6f 74 20 73 75 70 70 6f 72 74 65 64 20 62 79 20 41 6c 67 6f 6c 69 61 20 52 45 53 54 20 41 50 49 2e 20 50 6c 65 61 73 65 20 68 61 76 65 20 61 20 6c 6f 6f 6b 20 61 74 20 68 74 74 70 73 3a 2f 2f 77 77 77 2e 61 6c 67 6f 6c 69 61 2e 63 6f 6d 2f 64 6f 63 2f 72 65 73 74 2d 61 70 69 2f 73 65 61 72 63 68 2f 20 66 6f 72 20 74 68 65 20 6c 69 73 74 20 6f 66 20 76 61 6c 69 64 20 63 6f 6d 6d 61 6e 64 73 22 2c 22 73 74 61 74 75 73 22 3a 34 30 34 7d
                  Data Ascii: {"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:03:07:20
                  Start date:16/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:03:07:22
                  Start date:16/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=1984,i,14920574979149296530,234398221182212426,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:03:07:29
                  Start date:16/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net"
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly