https://cyberdefenders.org/blueteam-ctf-challenges/malware-traffic-analysis-3/

in network miner you can see there is only one windows host

Upload to PacketTotal

filter with the victim ip and http we see this weird get requests from qwe.mvdunalterableairreport.net (Ip address: 192.99.198.158) / to make sure export the objects and upload them to virustotal

same filter look at the referrer header