Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://paycustomer-renew.com/

Overview

General Information

Sample URL:https://paycustomer-renew.com/
Analysis ID:1425850
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL

Classification

  • System is w10x64
  • chrome.exe (PID: 3272 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5576 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2268,i,9763288267294396199,6816255141420774538,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://paycustomer-renew.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://paycustomer-renew.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://paycustomer-renew.com/favicon.icoAvira URL Cloud: Label: phishing
Source: paycustomer-renew.comVirustotal: Detection: 8%Perma Link
Source: https://paycustomer-renew.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.150.107:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.150.107:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.150.107
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.234.66
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.234.66
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: paycustomer-renew.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: paycustomer-renew.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://paycustomer-renew.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: paycustomer-renew.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=3p8s3agaf98at55vgbbu5l5p89
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: paycustomer-renew.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.150.107:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.150.107:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal64.win@16/2@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2268,i,9763288267294396199,6816255141420774538,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://paycustomer-renew.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2268,i,9763288267294396199,6816255141420774538,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://paycustomer-renew.com/1%VirustotalBrowse
https://paycustomer-renew.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
paycustomer-renew.com9%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://paycustomer-renew.com/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalseunknown
paycustomer-renew.com
193.143.1.205
truefalseunknown
www.google.com
142.250.68.68
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://paycustomer-renew.com/favicon.icofalse
    • Avira URL Cloud: phishing
    unknown
    https://paycustomer-renew.com/true
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      193.143.1.205
      paycustomer-renew.comunknown
      57271BITWEB-ASRUfalse
      142.250.68.68
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1425850
      Start date and time:2024-04-15 01:12:06 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 22s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://paycustomer-renew.com/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal64.win@16/2@6/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.72.131, 142.250.72.174, 142.250.101.84, 34.104.35.123, 20.114.59.183, 199.232.214.172, 20.3.187.198, 192.229.211.108, 13.85.23.206, 20.166.126.56, 172.217.14.67
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:Unicode text, UTF-8 text, with CRLF, LF line terminators
      Category:downloaded
      Size (bytes):188
      Entropy (8bit):4.828969822101026
      Encrypted:false
      SSDEEP:3:cK3L4AqWuGjQING75CQI3kK7HAUfweGSm9MG5zqWUbIlITUL2INq1NUUN:cm0AqW+IE59IvweGSXG5zgklIg2INq1p
      MD5:81C8D1AF288F36F13B07324FF64D168C
      SHA1:C0F75B4B487638A80766323FE45E6B67434FAF81
      SHA-256:C143C5067C82C46F161D9A4384A3B4B154B2417DC12CCB48258B71B5D00B1935
      SHA-512:099B24E62C65E64AFE30592DDF00984728BA6CA6E4D993EEFA3F092BE12BF3D97BAECB07A51345C09AB6076F6C5ACC733EE88EEDB576AC24D1289089827A27C8
      Malicious:false
      Reputation:low
      URL:https://paycustomer-renew.com/
      Preview: ....<body>.<center><h1>..................................</h1></center>.<hr><center></center>.........</body> la1111111
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Apr 15, 2024 01:12:55.085119009 CEST49675443192.168.2.4173.222.162.32
      Apr 15, 2024 01:13:04.252209902 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.252299070 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.252435923 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.252456903 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.252548933 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.252722025 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.252772093 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.252788067 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.252966881 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.253002882 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.696835041 CEST49675443192.168.2.4173.222.162.32
      Apr 15, 2024 01:13:04.939294100 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.939744949 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.939759016 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.939969063 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.940366983 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.940423965 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.941447973 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.941513062 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.941592932 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.941648006 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.943721056 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.943815947 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.944091082 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.944312096 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.944396973 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.988248110 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.989278078 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.989300013 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:04.989449978 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:04.989471912 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:05.038410902 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:05.038511038 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:05.612020016 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:05.614479065 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:05.614667892 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:05.627295971 CEST49735443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:05.627329111 CEST44349735193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:05.888902903 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:05.932324886 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.242367029 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.242386103 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.242552996 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.242614985 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.243573904 CEST44349736193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.243810892 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.243810892 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.243810892 CEST49736443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.428368092 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.428395033 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:06.428452969 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.429164886 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:06.429183960 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.104769945 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.152101040 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.166537046 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.166544914 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.168795109 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.168812990 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.168864012 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.169558048 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.169573069 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.170427084 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.170500994 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.173239946 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.173459053 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.173624992 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.173630953 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.214591980 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.490725040 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.497770071 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.497800112 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.498819113 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.498944998 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.503153086 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.503242970 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.559803009 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.559859037 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:07.607794046 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:07.666591883 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:07.666667938 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:07.668323994 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:07.670546055 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:07.670624971 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:07.792375088 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.792439938 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.793992996 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:07.794131041 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.795798063 CEST49739443192.168.2.4193.143.1.205
      Apr 15, 2024 01:13:07.795815945 CEST44349739193.143.1.205192.168.2.4
      Apr 15, 2024 01:13:08.018126965 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.018346071 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.021332979 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.021358967 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.021789074 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.056700945 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.100234985 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.333326101 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.333470106 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.333534956 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.333611012 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.333647013 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.333679914 CEST49741443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.333694935 CEST44349741184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.375662088 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.375726938 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.375823021 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.376069069 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.376101017 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.713924885 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.714006901 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.718115091 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.718141079 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.718616962 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:08.721900940 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:08.764281034 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:09.035614967 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:09.035803080 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:09.035866976 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:09.037241936 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:09.037241936 CEST49742443192.168.2.4184.28.150.107
      Apr 15, 2024 01:13:09.037277937 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:09.037302017 CEST44349742184.28.150.107192.168.2.4
      Apr 15, 2024 01:13:17.489164114 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:17.489221096 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:17.489265919 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:19.087388039 CEST49740443192.168.2.4142.250.68.68
      Apr 15, 2024 01:13:19.087403059 CEST44349740142.250.68.68192.168.2.4
      Apr 15, 2024 01:13:19.368200064 CEST4972380192.168.2.423.1.234.66
      Apr 15, 2024 01:13:19.521332026 CEST804972323.1.234.66192.168.2.4
      Apr 15, 2024 01:13:19.521615982 CEST4972380192.168.2.423.1.234.66
      Apr 15, 2024 01:14:07.013158083 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:07.013237000 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.013354063 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:07.013628960 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:07.013657093 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.341952085 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.347441912 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:07.347500086 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.348197937 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.361603975 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:07.362112999 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:07.412704945 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:17.328052998 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:17.328274965 CEST44349751142.250.68.68192.168.2.4
      Apr 15, 2024 01:14:17.328351974 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:19.055244923 CEST49751443192.168.2.4142.250.68.68
      Apr 15, 2024 01:14:19.055308104 CEST44349751142.250.68.68192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Apr 15, 2024 01:13:02.983414888 CEST53560541.1.1.1192.168.2.4
      Apr 15, 2024 01:13:03.845891953 CEST53610351.1.1.1192.168.2.4
      Apr 15, 2024 01:13:04.090570927 CEST6361053192.168.2.41.1.1.1
      Apr 15, 2024 01:13:04.090626955 CEST5234653192.168.2.41.1.1.1
      Apr 15, 2024 01:13:04.249716997 CEST53636101.1.1.1192.168.2.4
      Apr 15, 2024 01:13:04.251533985 CEST53523461.1.1.1192.168.2.4
      Apr 15, 2024 01:13:06.256439924 CEST5809853192.168.2.41.1.1.1
      Apr 15, 2024 01:13:06.256958961 CEST5734453192.168.2.41.1.1.1
      Apr 15, 2024 01:13:06.411194086 CEST53573441.1.1.1192.168.2.4
      Apr 15, 2024 01:13:06.415661097 CEST53580981.1.1.1192.168.2.4
      Apr 15, 2024 01:13:06.964075089 CEST6299753192.168.2.41.1.1.1
      Apr 15, 2024 01:13:06.965270996 CEST5666753192.168.2.41.1.1.1
      Apr 15, 2024 01:13:07.117558002 CEST53629971.1.1.1192.168.2.4
      Apr 15, 2024 01:13:07.118587971 CEST53566671.1.1.1192.168.2.4
      Apr 15, 2024 01:13:19.715396881 CEST138138192.168.2.4192.168.2.255
      Apr 15, 2024 01:13:21.234725952 CEST53561131.1.1.1192.168.2.4
      Apr 15, 2024 01:13:40.285931110 CEST53580791.1.1.1192.168.2.4
      Apr 15, 2024 01:14:02.507226944 CEST53592941.1.1.1192.168.2.4
      Apr 15, 2024 01:14:02.895486116 CEST53530681.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 15, 2024 01:13:04.090570927 CEST192.168.2.41.1.1.10xb032Standard query (0)paycustomer-renew.comA (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:04.090626955 CEST192.168.2.41.1.1.10xbb5cStandard query (0)paycustomer-renew.com65IN (0x0001)false
      Apr 15, 2024 01:13:06.256439924 CEST192.168.2.41.1.1.10xae3aStandard query (0)paycustomer-renew.comA (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:06.256958961 CEST192.168.2.41.1.1.10x3268Standard query (0)paycustomer-renew.com65IN (0x0001)false
      Apr 15, 2024 01:13:06.964075089 CEST192.168.2.41.1.1.10xd07dStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:06.965270996 CEST192.168.2.41.1.1.10x6e27Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 15, 2024 01:13:04.249716997 CEST1.1.1.1192.168.2.40xb032No error (0)paycustomer-renew.com193.143.1.205A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:06.415661097 CEST1.1.1.1192.168.2.40xae3aNo error (0)paycustomer-renew.com193.143.1.205A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:07.117558002 CEST1.1.1.1192.168.2.40xd07dNo error (0)www.google.com142.250.68.68A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:07.118587971 CEST1.1.1.1192.168.2.40x6e27No error (0)www.google.com65IN (0x0001)false
      Apr 15, 2024 01:13:18.912904024 CEST1.1.1.1192.168.2.40xabfeNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:18.912904024 CEST1.1.1.1192.168.2.40xabfeNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:20.573359013 CEST1.1.1.1192.168.2.40xcf50No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 15, 2024 01:13:20.573359013 CEST1.1.1.1192.168.2.40xcf50No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:36.316888094 CEST1.1.1.1192.168.2.40x78ccNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 15, 2024 01:13:36.316888094 CEST1.1.1.1192.168.2.40x78ccNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 15, 2024 01:13:55.394412994 CEST1.1.1.1192.168.2.40xe9f4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 15, 2024 01:13:55.394412994 CEST1.1.1.1192.168.2.40xe9f4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      Apr 15, 2024 01:14:15.571724892 CEST1.1.1.1192.168.2.40xb522No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Apr 15, 2024 01:14:15.571724892 CEST1.1.1.1192.168.2.40xb522No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • paycustomer-renew.com
      • https:
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449735193.143.1.2054435576C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-14 23:13:04 UTC664OUTGET / HTTP/1.1
      Host: paycustomer-renew.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-04-14 23:13:05 UTC204INHTTP/1.1 200 OK
      Date: Sun, 14 Apr 2024 23:13:05 GMT
      Server: Apache
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: text/html; charset=UTF-8
      2024-04-14 23:13:05 UTC199INData Raw: 62 63 0d 0a 20 0d 0a 0d 0a 3c 62 6f 64 79 3e 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e e3 83 8d e3 83 83 e3 83 88 e3 83 af e3 83 bc e3 82 af e3 82 a8 e3 83 a9 e3 83 bc e3 80 82 e3 83 8d e3 83 83 e3 83 88 e3 83 af e3 83 bc e3 82 af e3 82 92 e5 a4 89 e6 9b b4 e3 81 97 e3 81 a6 e5 86 8d e5 ba a6 e3 82 a2 e3 82 af e3 82 bb e3 82 b9 e3 81 97 e3 81 a6 e3 81 8f e3 81 a0 e3 81 95 e3 81 84 e3 80 82 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 3c 2f 63 65 6e 74 65 72 3e 0a 0a 0a 0a 0a 0a 0a 0a 0a 3c 2f 62 6f 64 79 3e 20 6c 61 31 31 31 31 31 31 31 0d 0a 30 0d 0a 0d 0a
      Data Ascii: bc <body><center><h1></h1></center><hr><center></center></body> la11111110


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449736193.143.1.2054435576C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-14 23:13:05 UTC598OUTGET /favicon.ico HTTP/1.1
      Host: paycustomer-renew.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://paycustomer-renew.com/
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-04-14 23:13:06 UTC357INHTTP/1.1 200 OK
      Date: Sun, 14 Apr 2024 23:13:06 GMT
      Server: Apache
      Expires: Thu, 19 Nov 1981 08:52:00 GMT
      Cache-Control: no-store, no-cache, must-revalidate
      Pragma: no-cache
      Set-Cookie: PHPSESSID=3p8s3agaf98at55vgbbu5l5p89; path=/
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: image/gif
      2024-04-14 23:13:06 UTC1656INData Raw: 36 36 63 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 3e 00 00 00 32 08 02 00 00 00 8b 61 ff 68 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 06 01 49 44 41 54 68 81 d5 9a 69 6c 54 55 14 c7 7f 33 d3 d9 a7 b4 50 da d2 96 d2 96 a5 2c 5a 68 d9 51 44 0a a2 21 a2 24 88 01 25 01 e2 46 44 5c be 18 89 82 84 80 68 08 89 91 80 24 4d 41 a2 24 a0 20 42 50 09 2d 4b 51 2a 2d b2 15 68 05 2c 6d a1 74 9b ee ed b4 d3 59 9f 1f 98 ca f6 86 37 6f e6 55 e4 9f fb e9 de 7b e6 fc e6 ce 9b 73 cf b9 f7 a9 04 41 e0 d1 94 fa 61 03 04 af b0 80 66 d9 1d 14 5f 63 f3 6e 72 0b a9 69 c0 eb ed 41 22 bd 8e c1 89 cc c9 e4 f5 d9 c4 47 a3 f5 4b a8 92 7e 60 6a 1b d9 f4
      Data Ascii: 66cPNGIHDR>2ahpHYsttfxtEXtSoftwareSnipaste]IDAThilTU3P,ZhQD!$%FD\h$MA$ BP-KQ*-h,mtY7oU{sAaf_cnriA"GK~`j


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.449739193.143.1.2054435576C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-04-14 23:13:07 UTC402OUTGET /favicon.ico HTTP/1.1
      Host: paycustomer-renew.com
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: */*
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: cors
      Sec-Fetch-Dest: empty
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      Cookie: PHPSESSID=3p8s3agaf98at55vgbbu5l5p89
      2024-04-14 23:13:07 UTC299INHTTP/1.1 200 OK
      Date: Sun, 14 Apr 2024 23:13:07 GMT
      Server: Apache
      Expires: Thu, 19 Nov 1981 08:52:00 GMT
      Cache-Control: no-store, no-cache, must-revalidate
      Pragma: no-cache
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: image/gif
      2024-04-14 23:13:07 UTC1656INData Raw: 36 36 63 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 3e 00 00 00 32 08 02 00 00 00 8b 61 ff 68 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 06 01 49 44 41 54 68 81 d5 9a 69 6c 54 55 14 c7 7f 33 d3 d9 a7 b4 50 da d2 96 d2 96 a5 2c 5a 68 d9 51 44 0a a2 21 a2 24 88 01 25 01 e2 46 44 5c be 18 89 82 84 80 68 08 89 91 80 24 4d 41 a2 24 a0 20 42 50 09 2d 4b 51 2a 2d b2 15 68 05 2c 6d a1 74 9b ee ed b4 d3 59 9f 1f 98 ca f6 86 37 6f e6 55 e4 9f fb e9 de 7b e6 fc e6 ce 9b 73 cf b9 f7 a9 04 41 e0 d1 94 fa 61 03 04 af b0 80 66 d9 1d 14 5f 63 f3 6e 72 0b a9 69 c0 eb ed 41 22 bd 8e c1 89 cc c9 e4 f5 d9 c4 47 a3 f5 4b a8 92 7e 60 6a 1b d9 f4
      Data Ascii: 66cPNGIHDR>2ahpHYsttfxtEXtSoftwareSnipaste]IDAThilTU3P,ZhQD!$%FD\h$MA$ BP-KQ*-h,mtY7oU{sAaf_cnriA"GK~`j


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.449741184.28.150.107443
      TimestampBytes transferredDirectionData
      2024-04-14 23:13:08 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-14 23:13:08 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (sac/250E)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=28240
      Date: Sun, 14 Apr 2024 23:13:08 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.449742184.28.150.107443
      TimestampBytes transferredDirectionData
      2024-04-14 23:13:08 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-04-14 23:13:09 UTC455INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (sac/2578)
      X-CID: 11
      Cache-Control: public, max-age=28240
      Date: Sun, 14 Apr 2024 23:13:08 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-04-14 23:13:09 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:12:58
      Start date:15/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:01:13:00
      Start date:15/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2268,i,9763288267294396199,6816255141420774538,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:01:13:02
      Start date:15/04/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://paycustomer-renew.com/"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly