Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://fiveradio-newbam.com

Overview

General Information

Sample URL:https://fiveradio-newbam.com
Analysis ID:1441864
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1872 --field-trial-handle=2276,i,1627501498718459115,18429416811188974202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fiveradio-newbam.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://fiveradio-newbam.comAvira URL Cloud: detection malicious, Label: phishing
Source: fiveradio-newbam.comVirustotal: Detection: 9%Perma Link
Source: https://fiveradio-newbam.comVirustotal: Detection: 13%Perma Link
Source: https://fiveradio-newbam.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.202.106.101:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.106.101
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fiveradio-newbam.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: fiveradio-newbam.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /report/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 391Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 15 May 2024 09:29:26 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeX-Powered-By: ExpressAccess-Control-Allow-Origin: *Content-Security-Policy: default-src 'none'X-Content-Type-Options: nosniffCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 88421a871c957441-MIAalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 23.202.106.101:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal64.win@16/2@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1872 --field-trial-handle=2276,i,1627501498718459115,18429416811188974202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fiveradio-newbam.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1872 --field-trial-handle=2276,i,1627501498718459115,18429416811188974202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://fiveradio-newbam.com13%VirustotalBrowse
https://fiveradio-newbam.com100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fiveradio-newbam.com10%VirustotalBrowse
www.google.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
a.nel.cloudflare.com0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://a.nel.cloudflare.com/report/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
a.nel.cloudflare.com
35.190.80.1
truefalseunknown
fiveradio-newbam.com
172.67.196.150
truefalseunknown
www.google.com
142.250.189.132
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.211.108
truefalseunknown
NameMaliciousAntivirus DetectionReputation
https://a.nel.cloudflare.com/report/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3Dfalse
  • Avira URL Cloud: safe
unknown
https://fiveradio-newbam.com/false
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    172.67.196.150
    fiveradio-newbam.comUnited States
    13335CLOUDFLARENETUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    142.250.189.132
    www.google.comUnited States
    15169GOOGLEUSfalse
    35.190.80.1
    a.nel.cloudflare.comUnited States
    15169GOOGLEUSfalse
    IP
    192.168.2.4
    192.168.2.5
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1441864
    Start date and time:2024-05-15 11:28:35 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 8s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:https://fiveradio-newbam.com
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:8
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal64.win@16/2@6/6
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.250.64.227, 192.178.50.78, 142.251.162.84, 34.104.35.123, 40.127.169.103, 199.232.210.172, 192.229.211.108, 20.3.187.198, 20.166.126.56, 192.178.50.35
    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
    File Type:HTML document, ASCII text
    Category:downloaded
    Size (bytes):139
    Entropy (8bit):4.717826995152233
    Encrypted:false
    SSDEEP:3:PouV7uJzhquHbtt6vYk2ZRMRJfHKERSAEtvxLrXZiLKY8K09AbBK6c4NGL:hxuJzhqIzyYk+qRU4zEdxXZiqsbBK34A
    MD5:DA7DA7D630292E7A2A7DDA8CA87B3D39
    SHA1:A4CB76424DC44433A2DF01FE8B0BBD836D15E970
    SHA-256:52C1E7A2C36BE28C42455FE1572D7D7918C3180CAD99A2B82DAA2A38A7E7BB23
    SHA-512:9E717F9C6699B280436CA9BE7107BA6301430D4DEF8311B963A266A5B3B91B2719687B04860509B6142FA24D629A3217BD450696559FE6D9DC8C60BCCFD740AD
    Malicious:false
    Reputation:low
    URL:https://fiveradio-newbam.com/
    Preview:<!DOCTYPE html>.<html lang="en">.<head>.<meta charset="utf-8">.<title>Error</title>.</head>.<body>.<pre>Cannot GET /</pre>.</body>.</html>.
    No static file info
    TimestampSource PortDest PortSource IPDest IP
    May 15, 2024 11:29:17.800266027 CEST49675443192.168.2.4173.222.162.32
    May 15, 2024 11:29:18.144002914 CEST49678443192.168.2.4104.46.162.224
    May 15, 2024 11:29:26.470324993 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.470369101 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.470443964 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.470588923 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.470607996 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.470669985 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.473351955 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.473370075 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.473637104 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.473650932 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.703356981 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.704952955 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.707871914 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.707885981 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.707906008 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.707931042 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.709070921 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.709153891 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.709170103 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.709223986 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.710176945 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.710251093 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.710952044 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.711076021 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.711147070 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.752456903 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.752468109 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.800900936 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:26.916125059 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:26.916311026 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:27.050396919 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:27.050503016 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:27.050586939 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:27.053019047 CEST49735443192.168.2.4172.67.196.150
    May 15, 2024 11:29:27.053035021 CEST44349735172.67.196.150192.168.2.4
    May 15, 2024 11:29:27.162554026 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.162585974 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.162656069 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.162884951 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.162899971 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.395700932 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.398083925 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.398138046 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.399168015 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.399240017 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.400151014 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.400214911 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.400321007 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.400329113 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.412569046 CEST49675443192.168.2.4173.222.162.32
    May 15, 2024 11:29:27.455138922 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.651213884 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.651289940 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.651338100 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.651520967 CEST49738443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.651540995 CEST4434973835.190.80.1192.168.2.4
    May 15, 2024 11:29:27.652189970 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.652230024 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.652288914 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.652551889 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.652563095 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.876064062 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.877521038 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.877551079 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.877851009 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.879201889 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.879268885 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:27.879709005 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:27.924114943 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:28.136653900 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:28.136771917 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:28.136831045 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:28.137120008 CEST49740443192.168.2.435.190.80.1
    May 15, 2024 11:29:28.137136936 CEST4434974035.190.80.1192.168.2.4
    May 15, 2024 11:29:29.813853025 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:29.813905954 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:29.814038992 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:29.814879894 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:29.814896107 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.008086920 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.008131027 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.008215904 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.011403084 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.011420012 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.053670883 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.053963900 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:30.053978920 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.055025101 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.055099964 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:30.056602955 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:30.056665897 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.111509085 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:30.111521006 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:30.158400059 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:30.240206003 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.240277052 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.245418072 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.245425940 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.245683908 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.299036980 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.338311911 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.384119987 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.458444118 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.458514929 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.460207939 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.461601019 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.461632967 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.461647034 CEST49742443192.168.2.423.202.106.101
    May 15, 2024 11:29:30.461656094 CEST4434974223.202.106.101192.168.2.4
    May 15, 2024 11:29:30.602324009 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.602355003 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:30.602508068 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.603004932 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.603018045 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:30.826210976 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:30.826287031 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.827704906 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.827718019 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:30.827948093 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:30.859086990 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:30.904124975 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:31.046983004 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:31.047055006 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:31.047120094 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:31.052015066 CEST49743443192.168.2.423.196.177.159
    May 15, 2024 11:29:31.052035093 CEST4434974323.196.177.159192.168.2.4
    May 15, 2024 11:29:40.035259962 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:40.035331011 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:40.035463095 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:41.510507107 CEST49741443192.168.2.4142.250.189.132
    May 15, 2024 11:29:41.510530949 CEST44349741142.250.189.132192.168.2.4
    May 15, 2024 11:29:41.694044113 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:41.694111109 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:29:41.694426060 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:43.489439011 CEST49736443192.168.2.4172.67.196.150
    May 15, 2024 11:29:43.489451885 CEST44349736172.67.196.150192.168.2.4
    May 15, 2024 11:30:29.753299952 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:29.753321886 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:29.753422022 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:29.754024029 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:29.754039049 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:29.987791061 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:29.988531113 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:29.988553047 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:29.988851070 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:29.989550114 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:29.989605904 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:30.033615112 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:39.978996992 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:39.979052067 CEST44349752142.250.189.132192.168.2.4
    May 15, 2024 11:30:39.979100943 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:41.488511086 CEST49752443192.168.2.4142.250.189.132
    May 15, 2024 11:30:41.488522053 CEST44349752142.250.189.132192.168.2.4
    TimestampSource PortDest PortSource IPDest IP
    May 15, 2024 11:29:25.390181065 CEST53512241.1.1.1192.168.2.4
    May 15, 2024 11:29:25.398361921 CEST53552931.1.1.1192.168.2.4
    May 15, 2024 11:29:26.054553986 CEST53600121.1.1.1192.168.2.4
    May 15, 2024 11:29:26.357558012 CEST5864753192.168.2.41.1.1.1
    May 15, 2024 11:29:26.357693911 CEST5798553192.168.2.41.1.1.1
    May 15, 2024 11:29:26.469326973 CEST53579851.1.1.1192.168.2.4
    May 15, 2024 11:29:26.469515085 CEST53586471.1.1.1192.168.2.4
    May 15, 2024 11:29:27.052325010 CEST5594653192.168.2.41.1.1.1
    May 15, 2024 11:29:27.052483082 CEST5227353192.168.2.41.1.1.1
    May 15, 2024 11:29:27.161756039 CEST53522731.1.1.1192.168.2.4
    May 15, 2024 11:29:27.162046909 CEST53559461.1.1.1192.168.2.4
    May 15, 2024 11:29:29.702219009 CEST4935853192.168.2.41.1.1.1
    May 15, 2024 11:29:29.702918053 CEST6295353192.168.2.41.1.1.1
    May 15, 2024 11:29:29.812459946 CEST53493581.1.1.1192.168.2.4
    May 15, 2024 11:29:29.812830925 CEST53629531.1.1.1192.168.2.4
    May 15, 2024 11:29:44.254046917 CEST53643831.1.1.1192.168.2.4
    May 15, 2024 11:29:48.664719105 CEST138138192.168.2.4192.168.2.255
    May 15, 2024 11:30:03.198148966 CEST53604451.1.1.1192.168.2.4
    May 15, 2024 11:30:25.131124020 CEST53583791.1.1.1192.168.2.4
    May 15, 2024 11:30:25.729718924 CEST53613111.1.1.1192.168.2.4
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    May 15, 2024 11:29:26.357558012 CEST192.168.2.41.1.1.10xc7f0Standard query (0)fiveradio-newbam.comA (IP address)IN (0x0001)false
    May 15, 2024 11:29:26.357693911 CEST192.168.2.41.1.1.10x6a51Standard query (0)fiveradio-newbam.com65IN (0x0001)false
    May 15, 2024 11:29:27.052325010 CEST192.168.2.41.1.1.10x7c59Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
    May 15, 2024 11:29:27.052483082 CEST192.168.2.41.1.1.10xc55fStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
    May 15, 2024 11:29:29.702219009 CEST192.168.2.41.1.1.10xb802Standard query (0)www.google.comA (IP address)IN (0x0001)false
    May 15, 2024 11:29:29.702918053 CEST192.168.2.41.1.1.10xd9a8Standard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    May 15, 2024 11:29:26.469326973 CEST1.1.1.1192.168.2.40x6a51No error (0)fiveradio-newbam.com65IN (0x0001)false
    May 15, 2024 11:29:26.469515085 CEST1.1.1.1192.168.2.40xc7f0No error (0)fiveradio-newbam.com172.67.196.150A (IP address)IN (0x0001)false
    May 15, 2024 11:29:26.469515085 CEST1.1.1.1192.168.2.40xc7f0No error (0)fiveradio-newbam.com104.21.84.200A (IP address)IN (0x0001)false
    May 15, 2024 11:29:27.162046909 CEST1.1.1.1192.168.2.40x7c59No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
    May 15, 2024 11:29:29.812459946 CEST1.1.1.1192.168.2.40xb802No error (0)www.google.com142.250.189.132A (IP address)IN (0x0001)false
    May 15, 2024 11:29:29.812830925 CEST1.1.1.1192.168.2.40xd9a8No error (0)www.google.com65IN (0x0001)false
    May 15, 2024 11:29:41.413851023 CEST1.1.1.1192.168.2.40x7855No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
    May 15, 2024 11:29:41.413851023 CEST1.1.1.1192.168.2.40x7855No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
    May 15, 2024 11:29:41.815237045 CEST1.1.1.1192.168.2.40x22a0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    May 15, 2024 11:29:41.815237045 CEST1.1.1.1192.168.2.40x22a0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    May 15, 2024 11:29:55.113734007 CEST1.1.1.1192.168.2.40xa3d8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    May 15, 2024 11:29:55.113734007 CEST1.1.1.1192.168.2.40xa3d8No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    May 15, 2024 11:30:18.317938089 CEST1.1.1.1192.168.2.40x38bdNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    May 15, 2024 11:30:18.317938089 CEST1.1.1.1192.168.2.40x38bdNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    May 15, 2024 11:30:37.910201073 CEST1.1.1.1192.168.2.40x5da5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    May 15, 2024 11:30:37.910201073 CEST1.1.1.1192.168.2.40x5da5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
    • fiveradio-newbam.com
    • a.nel.cloudflare.com
    • fs.microsoft.com
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.449735172.67.196.1504431720C:\Program Files\Google\Chrome\Application\chrome.exe
    TimestampBytes transferredDirectionData
    2024-05-15 09:29:26 UTC663OUTGET / HTTP/1.1
    Host: fiveradio-newbam.com
    Connection: keep-alive
    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
    sec-ch-ua-mobile: ?0
    sec-ch-ua-platform: "Windows"
    Upgrade-Insecure-Requests: 1
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
    Sec-Fetch-Site: none
    Sec-Fetch-Mode: navigate
    Sec-Fetch-User: ?1
    Sec-Fetch-Dest: document
    Accept-Encoding: gzip, deflate, br
    Accept-Language: en-US,en;q=0.9
    2024-05-15 09:29:27 UTC724INHTTP/1.1 404 Not Found
    Date: Wed, 15 May 2024 09:29:26 GMT
    Content-Type: text/html; charset=utf-8
    Transfer-Encoding: chunked
    Connection: close
    X-Powered-By: Express
    Access-Control-Allow-Origin: *
    Content-Security-Policy: default-src 'none'
    X-Content-Type-Options: nosniff
    CF-Cache-Status: DYNAMIC
    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D"}],"group":"cf-nel","max_age":604800}
    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
    Server: cloudflare
    CF-RAY: 88421a871c957441-MIA
    alt-svc: h3=":443"; ma=86400
    2024-05-15 09:29:27 UTC145INData Raw: 38 62 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 70 72 65 3e 43 61 6e 6e 6f 74 20 47 45 54 20 2f 3c 2f 70 72 65 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 0d 0a
    Data Ascii: 8b<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><title>Error</title></head><body><pre>Cannot GET /</pre></body></html>
    2024-05-15 09:29:27 UTC5INData Raw: 30 0d 0a 0d 0a
    Data Ascii: 0


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    1192.168.2.44973835.190.80.14431720C:\Program Files\Google\Chrome\Application\chrome.exe
    TimestampBytes transferredDirectionData
    2024-05-15 09:29:27 UTC551OUTOPTIONS /report/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D HTTP/1.1
    Host: a.nel.cloudflare.com
    Connection: keep-alive
    Origin: https://fiveradio-newbam.com
    Access-Control-Request-Method: POST
    Access-Control-Request-Headers: content-type
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
    Accept-Encoding: gzip, deflate, br
    Accept-Language: en-US,en;q=0.9
    2024-05-15 09:29:27 UTC336INHTTP/1.1 200 OK
    content-length: 0
    access-control-max-age: 86400
    access-control-allow-methods: POST, OPTIONS
    access-control-allow-origin: *
    access-control-allow-headers: content-length, content-type
    date: Wed, 15 May 2024 09:29:27 GMT
    Via: 1.1 google
    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
    Connection: close


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    2192.168.2.44974035.190.80.14431720C:\Program Files\Google\Chrome\Application\chrome.exe
    TimestampBytes transferredDirectionData
    2024-05-15 09:29:27 UTC488OUTPOST /report/v4?s=5L%2BK2fbcFGBy5JKXyLcpFllNaNT5K%2F1IYxxKWNw0HQQ7FZvvtd9VgKMqXhd3ZsxhHwJAI5esLdP7Lb88RltNSwC1U1yaMDoUB9LHdRmegyAD2j10%2BSqSfLh2qrJQHwAGZSHwJfhmJQ%3D%3D HTTP/1.1
    Host: a.nel.cloudflare.com
    Connection: keep-alive
    Content-Length: 391
    Content-Type: application/reports+json
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
    Accept-Encoding: gzip, deflate, br
    Accept-Language: en-US,en;q=0.9
    2024-05-15 09:29:27 UTC391OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 36 38 37 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 39 36 2e 31 35 30 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 66 69 76 65 72 61 64 69 6f 2d 6e 65 77 62 61
    Data Ascii: [{"age":0,"body":{"elapsed_time":687,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"172.67.196.150","status_code":404,"type":"http.error"},"type":"network-error","url":"https://fiveradio-newba
    2024-05-15 09:29:28 UTC168INHTTP/1.1 200 OK
    content-length: 0
    date: Wed, 15 May 2024 09:29:27 GMT
    Via: 1.1 google
    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
    Connection: close


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    3192.168.2.44974223.202.106.101443
    TimestampBytes transferredDirectionData
    2024-05-15 09:29:30 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-05-15 09:29:30 UTC468INHTTP/1.1 200 OK
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    Content-Type: application/octet-stream
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    Server: ECAcc (chd/0790)
    X-CID: 11
    X-Ms-ApiVersion: Distribute 1.2
    X-Ms-Region: prod-eus2-z1
    Cache-Control: public, max-age=250458
    Date: Wed, 15 May 2024 09:29:30 GMT
    Connection: close
    X-CID: 2


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    4192.168.2.44974323.196.177.159443
    TimestampBytes transferredDirectionData
    2024-05-15 09:29:30 UTC239OUTGET /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
    Range: bytes=0-2147483646
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-05-15 09:29:31 UTC531INHTTP/1.1 200 OK
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Content-Type: application/octet-stream
    ApiVersion: Distribute 1.1
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
    Cache-Control: public, max-age=250432
    Date: Wed, 15 May 2024 09:29:30 GMT
    Content-Length: 55
    Connection: close
    X-CID: 2
    2024-05-15 09:29:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:11:29:21
    Start date:15/05/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:2
    Start time:11:29:24
    Start date:15/05/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1872 --field-trial-handle=2276,i,1627501498718459115,18429416811188974202,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:3
    Start time:11:29:25
    Start date:15/05/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fiveradio-newbam.com"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    No disassembly