Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mufg-contact.com/

Overview

General Information

Sample URL:https://mufg-contact.com/
Analysis ID:1440279
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=2028,i,11857948907024574845,14295304275935289621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-contact.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://mufg-contact.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://mufg-contact.com/favicon.icoAvira URL Cloud: Label: phishing
Source: mufg-contact.comVirustotal: Detection: 13%Perma Link
Source: https://mufg-contact.com/Virustotal: Detection: 9%Perma Link
Source: https://mufg-contact.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.61.214.98:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.61.214.98:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownTCP traffic detected without corresponding DNS query: 23.61.214.98
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: mufg-contact.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mufg-contact.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mufg-contact.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mufg-contact.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=p0d2b9tjfookdn1d9ve7j86t71
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: mufg-contact.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.61.214.98:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.61.214.98:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal72.win@16/2@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=2028,i,11857948907024574845,14295304275935289621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-contact.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=2028,i,11857948907024574845,14295304275935289621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mufg-contact.com/100%Avira URL Cloudphishing
https://mufg-contact.com/10%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
mufg-contact.com13%VirustotalBrowse
SourceDetectionScannerLabelLink
https://mufg-contact.com/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalseunknown
www.google.com
142.250.141.103
truefalse
    high
    mufg-contact.com
    193.143.1.205
    truefalseunknown
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://mufg-contact.com/true
      unknown
      https://mufg-contact.com/favicon.icofalse
      • Avira URL Cloud: phishing
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      193.143.1.205
      mufg-contact.comunknown
      57271BITWEB-ASRUfalse
      142.250.141.103
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1440279
      Start date and time:2024-05-13 01:50:25 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 4s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://mufg-contact.com/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:9
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal72.win@16/2@6/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.102, 142.251.2.101, 142.251.2.138, 142.251.2.100, 142.251.2.139, 142.251.2.113, 142.251.2.84, 34.104.35.123, 13.85.23.86, 199.232.214.172, 192.229.211.108, 13.85.23.206, 20.3.187.198, 142.250.101.94
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:ASCII text, with CRLF, LF line terminators
      Category:downloaded
      Size (bytes):104
      Entropy (8bit):4.254249084918579
      Encrypted:false
      SSDEEP:3:cK3L4AqWsMgs0U9ClITULLP61INq1NUUN:cm0AqWDgs01lIgLP8INq1NUG
      MD5:B02B1B2C85BBA6F3849AF6EFAA40AF49
      SHA1:98B19D149A13229F8FFAF5FF8670CFDEC6B33D90
      SHA-256:1B959B84F9691CCB3D6E224AB658A61F8D3D0A875E327AEC01435E38AC506FD9
      SHA-512:D2DF73B28F56256593D61517E7D22361D0BED882CE622B10C66570351240A740225B5FF30601E52F5A1560031716180065CBA37F65AAAFF9E970C09C5674E140
      Malicious:false
      Reputation:low
      URL:https://mufg-contact.com/
      Preview: ....<body>.<center><h1>403 Forbidden</h1></center>.<hr><center>nginx</center>.........</body> la1111111
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      May 13, 2024 01:51:07.473314047 CEST49678443192.168.2.4104.46.162.224
      May 13, 2024 01:51:08.723268032 CEST49675443192.168.2.4173.222.162.32
      May 13, 2024 01:51:18.330976963 CEST49675443192.168.2.4173.222.162.32
      May 13, 2024 01:51:18.597502947 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.597533941 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:18.597604036 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.597831964 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.597872972 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:18.597927094 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.598005056 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.598018885 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:18.598221064 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:18.598236084 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.271059036 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.271370888 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.271409988 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.272281885 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.272346973 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.273425102 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.273483038 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.273752928 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.273761034 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.277349949 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.277528048 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.277542114 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.278532982 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.278589964 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.278934002 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.278994083 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.315973997 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.331875086 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.331883907 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.389169931 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.966526031 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.968199968 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:19.968261957 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.968497038 CEST49736443192.168.2.4193.143.1.205
      May 13, 2024 01:51:19.968524933 CEST44349736193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.065479994 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.108122110 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.429373026 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.429393053 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.429399967 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.429451942 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.429464102 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.430260897 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.430310965 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.433068037 CEST49735443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.433078051 CEST44349735193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.606395960 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.606436968 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.606498957 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.606981993 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:20.606997013 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:20.636405945 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:20.636426926 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:20.636607885 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:20.636974096 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:20.636995077 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:20.997147083 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:20.997386932 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:20.997400999 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:20.998245001 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:20.998303890 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:21.271639109 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:21.271722078 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:21.286114931 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.286530972 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.286550999 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.287540913 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.287606001 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.288069010 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.288137913 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.288214922 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.288222075 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.315828085 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:21.315836906 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:21.328496933 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.362718105 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:21.994982958 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.995012045 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.995076895 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.995098114 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.996705055 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.996815920 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.996937037 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.996953964 CEST44349739193.143.1.205192.168.2.4
      May 13, 2024 01:51:21.996963978 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:21.997070074 CEST49739443192.168.2.4193.143.1.205
      May 13, 2024 01:51:22.024786949 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.024830103 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.024898052 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.026987076 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.027000904 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.355423927 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.355492115 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.359564066 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.359575033 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.359818935 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.409593105 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.420207024 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.468128920 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.669960022 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.670027971 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.670078039 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.670214891 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.670236111 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.670247078 CEST49741443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.670257092 CEST4434974123.61.214.98192.168.2.4
      May 13, 2024 01:51:22.710602999 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.710630894 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:22.710745096 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.711007118 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:22.711019039 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.036566019 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.036700010 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.069003105 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.069014072 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.069539070 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.093858957 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.136118889 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.366082907 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.366154909 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.366228104 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.367460966 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.367460966 CEST49742443192.168.2.423.61.214.98
      May 13, 2024 01:51:23.367480040 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:23.367487907 CEST4434974223.61.214.98192.168.2.4
      May 13, 2024 01:51:30.991667986 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:30.991729975 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:51:30.991854906 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:31.370244026 CEST49740443192.168.2.4142.250.141.103
      May 13, 2024 01:51:31.370265007 CEST44349740142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.559926033 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:20.559954882 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.563987970 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:20.564299107 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:20.564307928 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.919445038 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.920169115 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:20.920181036 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.920501947 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.921283007 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:20.921345949 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:20.972337961 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:30.947309017 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:30.947380066 CEST44349751142.250.141.103192.168.2.4
      May 13, 2024 01:52:30.947443962 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:31.335246086 CEST49751443192.168.2.4142.250.141.103
      May 13, 2024 01:52:31.335263968 CEST44349751142.250.141.103192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      May 13, 2024 01:51:17.036581039 CEST53640401.1.1.1192.168.2.4
      May 13, 2024 01:51:17.073673010 CEST53565731.1.1.1192.168.2.4
      May 13, 2024 01:51:18.022638083 CEST53631191.1.1.1192.168.2.4
      May 13, 2024 01:51:18.401366949 CEST5777153192.168.2.41.1.1.1
      May 13, 2024 01:51:18.401503086 CEST5654953192.168.2.41.1.1.1
      May 13, 2024 01:51:18.596376896 CEST53577711.1.1.1192.168.2.4
      May 13, 2024 01:51:18.596986055 CEST53565491.1.1.1192.168.2.4
      May 13, 2024 01:51:20.448410988 CEST6055653192.168.2.41.1.1.1
      May 13, 2024 01:51:20.449295998 CEST6545153192.168.2.41.1.1.1
      May 13, 2024 01:51:20.471394062 CEST5278653192.168.2.41.1.1.1
      May 13, 2024 01:51:20.471776962 CEST6279553192.168.2.41.1.1.1
      May 13, 2024 01:51:20.603065968 CEST53605561.1.1.1192.168.2.4
      May 13, 2024 01:51:20.603363037 CEST53654511.1.1.1192.168.2.4
      May 13, 2024 01:51:20.625314951 CEST53627951.1.1.1192.168.2.4
      May 13, 2024 01:51:20.625330925 CEST53527861.1.1.1192.168.2.4
      May 13, 2024 01:51:35.019273043 CEST53638741.1.1.1192.168.2.4
      May 13, 2024 01:51:38.002110004 CEST138138192.168.2.4192.168.2.255
      May 13, 2024 01:51:53.846724033 CEST53563511.1.1.1192.168.2.4
      May 13, 2024 01:52:16.365452051 CEST53610961.1.1.1192.168.2.4
      May 13, 2024 01:52:16.367096901 CEST53524801.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      May 13, 2024 01:51:18.401366949 CEST192.168.2.41.1.1.10x86a3Standard query (0)mufg-contact.comA (IP address)IN (0x0001)false
      May 13, 2024 01:51:18.401503086 CEST192.168.2.41.1.1.10x37c7Standard query (0)mufg-contact.com65IN (0x0001)false
      May 13, 2024 01:51:20.448410988 CEST192.168.2.41.1.1.10x197bStandard query (0)mufg-contact.comA (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.449295998 CEST192.168.2.41.1.1.10x28d4Standard query (0)mufg-contact.com65IN (0x0001)false
      May 13, 2024 01:51:20.471394062 CEST192.168.2.41.1.1.10xa3e6Standard query (0)www.google.comA (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.471776962 CEST192.168.2.41.1.1.10x5587Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      May 13, 2024 01:51:18.596376896 CEST1.1.1.1192.168.2.40x86a3No error (0)mufg-contact.com193.143.1.205A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.603065968 CEST1.1.1.1192.168.2.40x197bNo error (0)mufg-contact.com193.143.1.205A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625314951 CEST1.1.1.1192.168.2.40x5587No error (0)www.google.com65IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
      May 13, 2024 01:51:20.625330925 CEST1.1.1.1192.168.2.40xa3e6No error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
      May 13, 2024 01:51:31.091692924 CEST1.1.1.1192.168.2.40x9f02No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      May 13, 2024 01:51:31.091692924 CEST1.1.1.1192.168.2.40x9f02No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      May 13, 2024 01:51:31.629856110 CEST1.1.1.1192.168.2.40x564No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      May 13, 2024 01:51:31.629856110 CEST1.1.1.1192.168.2.40x564No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      May 13, 2024 01:51:44.643310070 CEST1.1.1.1192.168.2.40x6000No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      May 13, 2024 01:51:44.643310070 CEST1.1.1.1192.168.2.40x6000No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      May 13, 2024 01:52:08.909044027 CEST1.1.1.1192.168.2.40x745eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      May 13, 2024 01:52:08.909044027 CEST1.1.1.1192.168.2.40x745eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      May 13, 2024 01:52:29.346684933 CEST1.1.1.1192.168.2.40xd464No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      May 13, 2024 01:52:29.346684933 CEST1.1.1.1192.168.2.40xd464No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
      • mufg-contact.com
      • https:
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449736193.143.1.205443744C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-05-12 23:51:19 UTC659OUTGET / HTTP/1.1
      Host: mufg-contact.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-05-12 23:51:19 UTC204INHTTP/1.1 200 OK
      Date: Sun, 12 May 2024 23:51:19 GMT
      Server: Apache
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: text/html; charset=UTF-8
      2024-05-12 23:51:19 UTC115INData Raw: 36 38 0d 0a 20 0d 0a 0d 0a 3c 62 6f 64 79 3e 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0a 0a 0a 0a 0a 0a 0a 0a 0a 3c 2f 62 6f 64 79 3e 20 6c 61 31 31 31 31 31 31 31 0d 0a 30 0d 0a 0d 0a
      Data Ascii: 68 <body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body> la11111110


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449735193.143.1.205443744C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-05-12 23:51:20 UTC588OUTGET /favicon.ico HTTP/1.1
      Host: mufg-contact.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://mufg-contact.com/
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-05-12 23:51:20 UTC357INHTTP/1.1 200 OK
      Date: Sun, 12 May 2024 23:51:20 GMT
      Server: Apache
      Expires: Thu, 19 Nov 1981 08:52:00 GMT
      Cache-Control: no-store, no-cache, must-revalidate
      Pragma: no-cache
      Set-Cookie: PHPSESSID=p0d2b9tjfookdn1d9ve7j86t71; path=/
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: image/gif
      2024-05-12 23:51:20 UTC5520INData Raw: 31 35 38 33 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 37 08 02 00 00 00 c6 fe 92 05 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 15 18 49 44 41 54 78 9c ed 9d 7b 70 54 d5 19 c0 ef b9 8f bd fb 4c 16 36 c9 36 8f cd 93 cd 93 84 2d 09 a0 a8 04 62 0a 05 04 09 20 4a 1b 3b ce 48 a1 55 64 da 71 3a 5a 3b 94 5a b5 d5 8e d6 6a a7 22 d0 d6 32 2a 52 30 54 05 4c 9a 44 5e 4e 31 40 0c c2 86 10 f2 5e 42 92 25 59 42 76 37 fb b8 7b 1f a7 7f ac c6 cd dd dd b3 bb 79 80 3a fb fb 2f 77 cf e3 bb f7 7e f7 9c ef fb ce 77 4e 00 84 10 8b 12 65 aa c1 6f b7 00 51 be 9b 44 15 2b ca b4 10 55 ac 28 d3 42 54 b1 a2 4c 0b e4 e4 9b 80 2c 8b b9 5c d0
      Data Ascii: 1583PNGIHDR7pHYsttfxtEXtSoftwareSnipaste]IDATx{pTL66-b J;HUdq:Z;Zj"2*R0TLD^N1@^B%YBv7{y:/w~wNeoQD+U(BTL,\


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.449739193.143.1.205443744C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-05-12 23:51:21 UTC397OUTGET /favicon.ico HTTP/1.1
      Host: mufg-contact.com
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: */*
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: cors
      Sec-Fetch-Dest: empty
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      Cookie: PHPSESSID=p0d2b9tjfookdn1d9ve7j86t71
      2024-05-12 23:51:21 UTC299INHTTP/1.1 200 OK
      Date: Sun, 12 May 2024 23:51:21 GMT
      Server: Apache
      Expires: Thu, 19 Nov 1981 08:52:00 GMT
      Cache-Control: no-store, no-cache, must-revalidate
      Pragma: no-cache
      Upgrade: h2
      Connection: Upgrade, close
      Vary: Accept-Encoding
      Transfer-Encoding: chunked
      Content-Type: image/gif
      2024-05-12 23:51:21 UTC5520INData Raw: 31 35 38 33 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 37 08 02 00 00 00 c6 fe 92 05 00 00 00 09 70 48 59 73 00 00 12 74 00 00 12 74 01 de 66 1f 78 00 00 00 11 74 45 58 74 53 6f 66 74 77 61 72 65 00 53 6e 69 70 61 73 74 65 5d 17 ce dd 00 00 15 18 49 44 41 54 78 9c ed 9d 7b 70 54 d5 19 c0 ef b9 8f bd fb 4c 16 36 c9 36 8f cd 93 cd 93 84 2d 09 a0 a8 04 62 0a 05 04 09 20 4a 1b 3b ce 48 a1 55 64 da 71 3a 5a 3b 94 5a b5 d5 8e d6 6a a7 22 d0 d6 32 2a 52 30 54 05 4c 9a 44 5e 4e 31 40 0c c2 86 10 f2 5e 42 92 25 59 42 76 37 fb b8 7b 1f a7 7f ac c6 cd dd dd b3 bb 79 80 3a fb fb 2f 77 cf e3 bb f7 7e f7 9c ef fb ce 77 4e 00 84 10 8b 12 65 aa c1 6f b7 00 51 be 9b 44 15 2b ca b4 10 55 ac 28 d3 42 54 b1 a2 4c 0b e4 e4 9b 80 2c 8b b9 5c d0
      Data Ascii: 1583PNGIHDR7pHYsttfxtEXtSoftwareSnipaste]IDATx{pTL66-b J;HUdq:Z;Zj"2*R0TLD^N1@^B%YBv7{y:/w~wNeoQD+U(BTL,\


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.44974123.61.214.98443
      TimestampBytes transferredDirectionData
      2024-05-12 23:51:22 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-05-12 23:51:22 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (sac/2518)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus-z1
      Cache-Control: public, max-age=198796
      Date: Sun, 12 May 2024 23:51:22 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.44974223.61.214.98443
      TimestampBytes transferredDirectionData
      2024-05-12 23:51:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-05-12 23:51:23 UTC456INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (sac/2578)
      X-CID: 11
      Cache-Control: public, max-age=198682
      Date: Sun, 12 May 2024 23:51:23 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-05-12 23:51:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:51:10
      Start date:13/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:01:51:15
      Start date:13/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=2028,i,11857948907024574845,14295304275935289621,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:01:51:17
      Start date:13/05/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mufg-contact.com/"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly