Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mufg-reserved.com/

Overview

General Information

Sample URL:https://mufg-reserved.com/
Analysis ID:1439894
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 2484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5312 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,18015794224740720881,824853901767135498,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6448 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-reserved.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://mufg-reserved.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://mufg-reserved.com/favicon.icoAvira URL Cloud: Label: phishing
Source: https://mufg-reserved.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: mufg-reserved.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mufg-reserved.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mufg-reserved.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mufg-reserved.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=sr1bqhqhnb71bune8tbbqvkc77
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: mufg-reserved.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal56.win@16/2@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,18015794224740720881,824853901767135498,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-reserved.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,18015794224740720881,824853901767135498,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mufg-reserved.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://mufg-reserved.com/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
mufg-reserved.com
193.143.1.205
truefalse
    unknown
    www.google.com
    142.251.32.100
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://mufg-reserved.com/true
          unknown
          https://mufg-reserved.com/favicon.icofalse
          • Avira URL Cloud: phishing
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.251.32.100
          www.google.comUnited States
          15169GOOGLEUSfalse
          193.143.1.205
          mufg-reserved.comunknown
          57271BITWEB-ASRUfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1439894
          Start date and time:2024-05-11 00:40:17 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 0s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://mufg-reserved.com/
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:12
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal56.win@16/2@6/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, MoUsoCoreWorker.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.40.163, 142.250.80.46, 172.253.122.84, 34.104.35.123, 40.127.169.103, 72.21.81.240, 192.229.211.108, 20.3.187.198, 20.242.39.171, 142.251.32.99
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://mufg-reserved.com/
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with CRLF, LF line terminators
          Category:downloaded
          Size (bytes):104
          Entropy (8bit):4.254249084918579
          Encrypted:false
          SSDEEP:3:cK3L4AqWsMgs0U9ClITULLP61INq1NUUN:cm0AqWDgs01lIgLP8INq1NUG
          MD5:B02B1B2C85BBA6F3849AF6EFAA40AF49
          SHA1:98B19D149A13229F8FFAF5FF8670CFDEC6B33D90
          SHA-256:1B959B84F9691CCB3D6E224AB658A61F8D3D0A875E327AEC01435E38AC506FD9
          SHA-512:D2DF73B28F56256593D61517E7D22361D0BED882CE622B10C66570351240A740225B5FF30601E52F5A1560031716180065CBA37F65AAAFF9E970C09C5674E140
          Malicious:false
          Reputation:low
          URL:https://mufg-reserved.com/
          Preview: ....<body>.<center><h1>403 Forbidden</h1></center>.<hr><center>nginx</center>.........</body> la1111111
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          May 11, 2024 00:40:57.240402937 CEST49675443192.168.2.4173.222.162.32
          May 11, 2024 00:40:59.349771976 CEST49678443192.168.2.4104.46.162.224
          May 11, 2024 00:41:06.840740919 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.840775967 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:06.840856075 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.850212097 CEST49675443192.168.2.4173.222.162.32
          May 11, 2024 00:41:06.891103029 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.891144037 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:06.891215086 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.891515017 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.891546011 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:06.891697884 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:06.891711950 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.293934107 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.294254065 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.294271946 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.295236111 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.295300961 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.296077967 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.296292067 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.296361923 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.296454906 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.296468019 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.296669960 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.296678066 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.297614098 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.297692060 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.298876047 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.298930883 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.346496105 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.351072073 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.351078987 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.395396948 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.722256899 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.724239111 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.724287987 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.755989075 CEST49736443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.756005049 CEST44349736193.143.1.205192.168.2.4
          May 11, 2024 00:41:07.938822985 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:07.984117985 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.170263052 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.170295954 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.170319080 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.170372963 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.170394897 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.171667099 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.171721935 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.172986984 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.173002005 CEST44349735193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.173012972 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.173065901 CEST49735443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.349438906 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.349481106 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.349538088 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.350564003 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.350579023 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.749495983 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.749828100 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.749857903 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.750955105 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.751159906 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.751802921 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.751876116 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.752110958 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.752119064 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:08.805011034 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:08.965023041 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:08.965048075 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:08.969319105 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:08.969319105 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:08.969347000 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.165961027 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.172739983 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.172756910 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.172796011 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.172827959 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:09.172841072 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.172858000 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:09.173855066 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.181008101 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:09.208440065 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.230838060 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.230851889 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.231756926 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.231767893 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.231829882 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.237011909 CEST49739443192.168.2.4193.143.1.205
          May 11, 2024 00:41:09.237032890 CEST44349739193.143.1.205192.168.2.4
          May 11, 2024 00:41:09.245016098 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.245120049 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.286945105 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.286963940 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:09.333442926 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:09.768630028 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:09.768662930 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:09.768733025 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:09.772209883 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:09.772224903 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:09.961368084 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:09.961442947 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:09.992799044 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:09.992815018 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:09.993093014 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.036562920 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.106193066 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.152117014 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.196382046 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.196480036 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.196527958 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.196592093 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.196605921 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.196619034 CEST49741443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.196624994 CEST4434974123.51.58.94192.168.2.4
          May 11, 2024 00:41:10.228883028 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.228912115 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.228996992 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.229358912 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.229368925 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.412159920 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.412250996 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.413713932 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.413718939 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.413942099 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.415219069 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.460119009 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.607168913 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.607314110 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.609041929 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.624913931 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.624913931 CEST49742443192.168.2.423.51.58.94
          May 11, 2024 00:41:10.624927044 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:10.624934912 CEST4434974223.51.58.94192.168.2.4
          May 11, 2024 00:41:19.203531981 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:19.203620911 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:41:19.203728914 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:19.261918068 CEST49740443192.168.2.4142.251.32.100
          May 11, 2024 00:41:19.261931896 CEST44349740142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.267945051 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:09.267988920 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.268377066 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:09.268465996 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:09.268476009 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.461179972 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.485063076 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:09.485083103 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.485409975 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.485891104 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:09.485955000 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:09.536387920 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:18.282541990 CEST4972380192.168.2.4199.232.210.172
          May 11, 2024 00:42:18.282604933 CEST4972480192.168.2.4199.232.210.172
          May 11, 2024 00:42:18.370152950 CEST8049723199.232.210.172192.168.2.4
          May 11, 2024 00:42:18.370170116 CEST8049724199.232.210.172192.168.2.4
          May 11, 2024 00:42:18.370181084 CEST8049723199.232.210.172192.168.2.4
          May 11, 2024 00:42:18.370192051 CEST8049724199.232.210.172192.168.2.4
          May 11, 2024 00:42:18.370225906 CEST4972380192.168.2.4199.232.210.172
          May 11, 2024 00:42:18.370244980 CEST4972480192.168.2.4199.232.210.172
          May 11, 2024 00:42:19.463396072 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:19.463462114 CEST44349751142.251.32.100192.168.2.4
          May 11, 2024 00:42:19.463664055 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:21.237225056 CEST49751443192.168.2.4142.251.32.100
          May 11, 2024 00:42:21.237257957 CEST44349751142.251.32.100192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          May 11, 2024 00:41:04.819492102 CEST53583351.1.1.1192.168.2.4
          May 11, 2024 00:41:04.943747997 CEST53507421.1.1.1192.168.2.4
          May 11, 2024 00:41:05.490901947 CEST53554311.1.1.1192.168.2.4
          May 11, 2024 00:41:06.640738964 CEST5463653192.168.2.41.1.1.1
          May 11, 2024 00:41:06.640908003 CEST5420753192.168.2.41.1.1.1
          May 11, 2024 00:41:06.819231987 CEST53542071.1.1.1192.168.2.4
          May 11, 2024 00:41:06.839627981 CEST53546361.1.1.1192.168.2.4
          May 11, 2024 00:41:08.188674927 CEST6253853192.168.2.41.1.1.1
          May 11, 2024 00:41:08.189425945 CEST6167553192.168.2.41.1.1.1
          May 11, 2024 00:41:08.318487883 CEST53625381.1.1.1192.168.2.4
          May 11, 2024 00:41:08.384385109 CEST53616751.1.1.1192.168.2.4
          May 11, 2024 00:41:08.867345095 CEST4933253192.168.2.41.1.1.1
          May 11, 2024 00:41:08.867816925 CEST5974753192.168.2.41.1.1.1
          May 11, 2024 00:41:08.956553936 CEST53493321.1.1.1192.168.2.4
          May 11, 2024 00:41:08.956614971 CEST53597471.1.1.1192.168.2.4
          May 11, 2024 00:41:22.472698927 CEST53501381.1.1.1192.168.2.4
          May 11, 2024 00:41:29.891716957 CEST138138192.168.2.4192.168.2.255
          May 11, 2024 00:41:41.242232084 CEST53564581.1.1.1192.168.2.4
          May 11, 2024 00:42:03.683557987 CEST53594111.1.1.1192.168.2.4
          May 11, 2024 00:42:04.310584068 CEST53636681.1.1.1192.168.2.4
          TimestampSource IPDest IPChecksumCodeType
          May 11, 2024 00:41:08.385109901 CEST192.168.2.41.1.1.1c224(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          May 11, 2024 00:41:06.640738964 CEST192.168.2.41.1.1.10xf8a7Standard query (0)mufg-reserved.comA (IP address)IN (0x0001)false
          May 11, 2024 00:41:06.640908003 CEST192.168.2.41.1.1.10x88d3Standard query (0)mufg-reserved.com65IN (0x0001)false
          May 11, 2024 00:41:08.188674927 CEST192.168.2.41.1.1.10x6650Standard query (0)mufg-reserved.comA (IP address)IN (0x0001)false
          May 11, 2024 00:41:08.189425945 CEST192.168.2.41.1.1.10x42b5Standard query (0)mufg-reserved.com65IN (0x0001)false
          May 11, 2024 00:41:08.867345095 CEST192.168.2.41.1.1.10xfeabStandard query (0)www.google.comA (IP address)IN (0x0001)false
          May 11, 2024 00:41:08.867816925 CEST192.168.2.41.1.1.10xc03dStandard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          May 11, 2024 00:41:06.839627981 CEST1.1.1.1192.168.2.40xf8a7No error (0)mufg-reserved.com193.143.1.205A (IP address)IN (0x0001)false
          May 11, 2024 00:41:08.318487883 CEST1.1.1.1192.168.2.40x6650No error (0)mufg-reserved.com193.143.1.205A (IP address)IN (0x0001)false
          May 11, 2024 00:41:08.956553936 CEST1.1.1.1192.168.2.40xfeabNo error (0)www.google.com142.251.32.100A (IP address)IN (0x0001)false
          May 11, 2024 00:41:08.956614971 CEST1.1.1.1192.168.2.40xc03dNo error (0)www.google.com65IN (0x0001)false
          May 11, 2024 00:41:20.961616039 CEST1.1.1.1192.168.2.40xf978No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          May 11, 2024 00:41:20.961616039 CEST1.1.1.1192.168.2.40xf978No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          May 11, 2024 00:41:33.485074997 CEST1.1.1.1192.168.2.40xaa11No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          May 11, 2024 00:41:33.485074997 CEST1.1.1.1192.168.2.40xaa11No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          May 11, 2024 00:41:56.315030098 CEST1.1.1.1192.168.2.40x214eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          May 11, 2024 00:41:56.315030098 CEST1.1.1.1192.168.2.40x214eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          May 11, 2024 00:42:16.986042023 CEST1.1.1.1192.168.2.40x61a4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          May 11, 2024 00:42:16.986042023 CEST1.1.1.1192.168.2.40x61a4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • mufg-reserved.com
          • https:
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449736193.143.1.2054435312C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-05-10 22:41:07 UTC660OUTGET / HTTP/1.1
          Host: mufg-reserved.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-05-10 22:41:07 UTC204INHTTP/1.1 200 OK
          Date: Fri, 10 May 2024 22:41:07 GMT
          Server: Apache
          Upgrade: h2
          Connection: Upgrade, close
          Vary: Accept-Encoding
          Transfer-Encoding: chunked
          Content-Type: text/html; charset=UTF-8
          2024-05-10 22:41:07 UTC115INData Raw: 36 38 0d 0a 20 0d 0a 0d 0a 3c 62 6f 64 79 3e 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0a 0a 0a 0a 0a 0a 0a 0a 0a 3c 2f 62 6f 64 79 3e 20 6c 61 31 31 31 31 31 31 31 0d 0a 30 0d 0a 0d 0a
          Data Ascii: 68 <body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body> la11111110


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449735193.143.1.2054435312C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-05-10 22:41:07 UTC590OUTGET /favicon.ico HTTP/1.1
          Host: mufg-reserved.com
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://mufg-reserved.com/
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-05-10 22:41:08 UTC357INHTTP/1.1 200 OK
          Date: Fri, 10 May 2024 22:41:08 GMT
          Server: Apache
          Expires: Thu, 19 Nov 1981 08:52:00 GMT
          Cache-Control: no-store, no-cache, must-revalidate
          Pragma: no-cache
          Set-Cookie: PHPSESSID=sr1bqhqhnb71bune8tbbqvkc77; path=/
          Upgrade: h2
          Connection: Upgrade, close
          Vary: Accept-Encoding
          Transfer-Encoding: chunked
          Content-Type: image/gif
          2024-05-10 22:41:08 UTC5520INData Raw: 31 35 38 33 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 37 08 02 00 00 00 c6 fe 92 05 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 15 18 49 44 41 54 78 9c ed 9d 7b 70 54 d5 19 c0 ef b9 8f bd fb 4c 16 36 c9 36 8f cd 93 cd 93 84 2d 09 a0 a8 04 62 0a 05 04 09 20 4a 1b 3b ce 48 a1 55 64 da 71 3a 5a 3b 94 5a b5 d5 8e d6 6a a7 22 d0 d6 32 2a 52 30 54 05 4c 9a 44 5e 4e 31 40 0c c2 86 10 f2 5e 42 92 25 59 42 76 37 fb b8 7b 1f a7 7f ac c6 cd dd dd b3 bb 79 80 3a fb fb 2f 77 cf e3 bb f7 7e f7 9c ef fb ce 77 4e 00 84 10 8b 12 65 aa c1 6f b7 00 51 be 9b 44 15 2b ca b4 10 55 ac 28 d3 42 54 b1 a2 4c 0b e4 e4 9b 80 2c 8b b9 5c d0
          Data Ascii: 1583PNGIHDR7pHYsttfxtEXtSoftwareSnipaste]IDATx{pTL66-b J;HUdq:Z;Zj"2*R0TLD^N1@^B%YBv7{y:/w~wNeoQD+U(BTL,\


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.449739193.143.1.2054435312C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-05-10 22:41:08 UTC398OUTGET /favicon.ico HTTP/1.1
          Host: mufg-reserved.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: */*
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: cors
          Sec-Fetch-Dest: empty
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          Cookie: PHPSESSID=sr1bqhqhnb71bune8tbbqvkc77
          2024-05-10 22:41:09 UTC299INHTTP/1.1 200 OK
          Date: Fri, 10 May 2024 22:41:09 GMT
          Server: Apache
          Expires: Thu, 19 Nov 1981 08:52:00 GMT
          Cache-Control: no-store, no-cache, must-revalidate
          Pragma: no-cache
          Upgrade: h2
          Connection: Upgrade, close
          Vary: Accept-Encoding
          Transfer-Encoding: chunked
          Content-Type: image/gif
          2024-05-10 22:41:09 UTC5520INData Raw: 31 35 38 33 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 37 08 02 00 00 00 c6 fe 92 05 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 15 18 49 44 41 54 78 9c ed 9d 7b 70 54 d5 19 c0 ef b9 8f bd fb 4c 16 36 c9 36 8f cd 93 cd 93 84 2d 09 a0 a8 04 62 0a 05 04 09 20 4a 1b 3b ce 48 a1 55 64 da 71 3a 5a 3b 94 5a b5 d5 8e d6 6a a7 22 d0 d6 32 2a 52 30 54 05 4c 9a 44 5e 4e 31 40 0c c2 86 10 f2 5e 42 92 25 59 42 76 37 fb b8 7b 1f a7 7f ac c6 cd dd dd b3 bb 79 80 3a fb fb 2f 77 cf e3 bb f7 7e f7 9c ef fb ce 77 4e 00 84 10 8b 12 65 aa c1 6f b7 00 51 be 9b 44 15 2b ca b4 10 55 ac 28 d3 42 54 b1 a2 4c 0b e4 e4 9b 80 2c 8b b9 5c d0
          Data Ascii: 1583PNGIHDR7pHYsttfxtEXtSoftwareSnipaste]IDATx{pTL66-b J;HUdq:Z;Zj"2*R0TLD^N1@^B%YBv7{y:/w~wNeoQD+U(BTL,\


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.44974123.51.58.94443
          TimestampBytes transferredDirectionData
          2024-05-10 22:41:10 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-05-10 22:41:10 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/079C)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=105046
          Date: Fri, 10 May 2024 22:41:10 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          4192.168.2.44974223.51.58.94443
          TimestampBytes transferredDirectionData
          2024-05-10 22:41:10 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-05-10 22:41:10 UTC456INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0778)
          X-CID: 11
          Cache-Control: public, max-age=105017
          Date: Fri, 10 May 2024 22:41:10 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-05-10 22:41:10 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:00:40:58
          Start date:11/05/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:00:41:02
          Start date:11/05/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,18015794224740720881,824853901767135498,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:00:41:05
          Start date:11/05/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-reserved.com/"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly