Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://fiveradio-newbam.com

Overview

General Information

Sample URL:http://fiveradio-newbam.com
Analysis ID:1442472
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 3628 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2208,i,7082945577606897378,2019628484602091693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4768 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fiveradio-newbam.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://fiveradio-newbam.comAvira URL Cloud: detection malicious, Label: phishing
Source: http://fiveradio-newbam.comVirustotal: Detection: 13%Perma Link
Source: https://fiveradio-newbam.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.213.224.106:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.213.224.106:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fiveradio-newbam.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: fiveradio-newbam.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /report/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 391Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 16 May 2024 07:43:35 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeX-Powered-By: ExpressAccess-Control-Allow-Origin: *Content-Security-Policy: default-src 'none'X-Content-Type-Options: nosniffCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8849bcd46eb9b3d7-MIAalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 23.213.224.106:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.213.224.106:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: mal56.win@17/8@8/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2208,i,7082945577606897378,2019628484602091693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fiveradio-newbam.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2208,i,7082945577606897378,2019628484602091693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://fiveradio-newbam.com100%Avira URL Cloudphishing
http://fiveradio-newbam.com13%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://a.nel.cloudflare.com/report/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      unknown
      fiveradio-newbam.com
      104.21.84.200
      truefalse
        unknown
        www.google.com
        192.178.50.68
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://a.nel.cloudflare.com/report/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3Dfalse
            • Avira URL Cloud: safe
            unknown
            https://fiveradio-newbam.com/false
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              172.67.196.150
              unknownUnited States
              13335CLOUDFLARENETUSfalse
              192.178.50.68
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.5
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1442472
              Start date and time:2024-05-16 09:42:45 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 7s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://fiveradio-newbam.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal56.win@17/8@8/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.165.195, 142.250.189.142, 173.194.217.84, 34.104.35.123, 40.127.169.103, 199.232.210.172, 72.21.81.240, 192.229.211.108, 20.242.39.171, 52.165.164.15, 142.250.189.131
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu May 16 06:43:34 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.9694083520293564
              Encrypted:false
              SSDEEP:48:8Fd3TvbZwHsidAKZdA19ehwiZUklqeh2y+3:8vPZXBy
              MD5:73EEF6F192B76477FE5C8180995CAC56
              SHA1:E6F3612A2B19032D4F49E30BA3387A4E25700970
              SHA-256:4B3B717053ADD05E772AC6F1AC7DBF68B188BF179BBB350EA826158C8E8A0068
              SHA-512:833685EF0817824AF9C57F6E27992C4CD15B4FD7EE5BC0CC7BD5E2D4D09DD4147D6B00103A5619FB8847FC841CB0E06AB68EA0EFA75383CEB094B2425B1E0B1B
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....%p..d...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xr=...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu May 16 06:43:34 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2679
              Entropy (8bit):3.9869407323439146
              Encrypted:false
              SSDEEP:48:8HQd3TvbZwHsidAKZdA1weh/iZUkAQkqehxy+2:8HgPZd9QEy
              MD5:5E0F9841170E393E9956EFB31DA84513
              SHA1:7BD2BBDEFC4D7933E3D6334B2A0538292822B640
              SHA-256:7A5D6E2A8C50A4DDC2363B5FB3BA9479E0224820984B609D816D5DD96DCA8403
              SHA-512:B33E1826112954D813823D0C56F582BDEFC2CBB132882C001FF2452C7830896CEF3D069A122F30F86841E64DA060D7B9610D0671ADDC39CEBB66FFA7129BB48E
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....F..d...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xr=...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2693
              Entropy (8bit):3.9998184722588803
              Encrypted:false
              SSDEEP:48:8xcd3TvbsHsidAKZdA14tseh7sFiZUkmgqeh7sny+BX:8x8PRndy
              MD5:096439EE3EEDD63C4DC67B64824D9275
              SHA1:782949CB4BBB111A05FA6F85F75A5F37C79FADC9
              SHA-256:3BE71ABDD036402E09AC3130B5B9BF2A8EE2A4DB4D58BD7071886B1DB5399601
              SHA-512:9AB75D9958D190384E2B84E33EB7DA76CB36B586B0DA70C7BE3F670CE926354B14ACD8C94FBA9C21814525B1CDF0E632926548E1353DAB17F1572589AFFA3D58
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu May 16 06:43:34 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.9844443661225633
              Encrypted:false
              SSDEEP:48:8Md3TvbZwHsidAKZdA1vehDiZUkwqehFy+R:8MPZevy
              MD5:9EA9EB270479444A0122BBB4E0FE2EF9
              SHA1:A602E638038730FBD96594D12A5D8D2E3025110F
              SHA-256:512F0D03FE3B096C087BDE00FE6B64B2B8F262EEFBA6A0F4A16FB32C52C7831D
              SHA-512:1956218F6A47D3DDB7A7FF8DFA3F38E678E797A398D31C7BAEF34EA6DF5160B95B97A80C5D132BC3AF423E3A2236E112F25F87D82C980DC06B00BE86CDE104BC
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....gz.d...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xr=...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu May 16 06:43:34 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.973840979483613
              Encrypted:false
              SSDEEP:48:8fd3TvbZwHsidAKZdA1hehBiZUk1W1qehTy+C:8VPZu9zy
              MD5:B1CA0193219BE5B0CC7AFC1F1BE14BF1
              SHA1:420AB41301D2674A4FD78DFA36C1DE9F3470F286
              SHA-256:B68009681BBBDF2F0674ACC0059D4A1A299CF158A462EFC93443AA5FA5CA388B
              SHA-512:DCCADDA8C8BE8AB5AAD73574576A77901EBD378F3B2DE3A1110AF0D5FF27AF87F4B5C7E685C4F395610BDA755A00A12CC794CCA1CAFC6A48C8B1C4DD08EF9D63
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....i...d...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xr=...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu May 16 06:43:34 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2683
              Entropy (8bit):3.9848233411744705
              Encrypted:false
              SSDEEP:48:8id3TvbZwHsidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbdy+yT+:8ePZQT/TbxWOvTbdy7T
              MD5:37A1C92D171AD1A7F382CFB8F1868A28
              SHA1:2067D91C3E2A3DAB4EBD18770D020FF0CD4A59E3
              SHA-256:456C2826C52FB603BA38F56F2E521533B09F1C6DB989685664F38B9E38B59708
              SHA-512:FF893AD288033B4F21943BAAC47976610105598C669CF5E8A06AFA514D53CA450527759017544773A954A20D32555146D2700E2A74FD2D018276CD3CA44B2C7A
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....Lq.d...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Xo=....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xo=....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xo=....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xo=..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xr=...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........9.Z......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):139
              Entropy (8bit):4.717826995152233
              Encrypted:false
              SSDEEP:3:PouV7uJzhquHbtt6vYk2ZRMRJfHKERSAEtvxLrXZiLKY8K09AbBK6c4NGL:hxuJzhqIzyYk+qRU4zEdxXZiqsbBK34A
              MD5:DA7DA7D630292E7A2A7DDA8CA87B3D39
              SHA1:A4CB76424DC44433A2DF01FE8B0BBD836D15E970
              SHA-256:52C1E7A2C36BE28C42455FE1572D7D7918C3180CAD99A2B82DAA2A38A7E7BB23
              SHA-512:9E717F9C6699B280436CA9BE7107BA6301430D4DEF8311B963A266A5B3B91B2719687B04860509B6142FA24D629A3217BD450696559FE6D9DC8C60BCCFD740AD
              Malicious:false
              Reputation:low
              URL:https://fiveradio-newbam.com/
              Preview:<!DOCTYPE html>.<html lang="en">.<head>.<meta charset="utf-8">.<title>Error</title>.</head>.<body>.<pre>Cannot GET /</pre>.</body>.</html>.
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              May 16, 2024 09:43:27.987204075 CEST49675443192.168.2.523.1.237.91
              May 16, 2024 09:43:27.987210035 CEST49674443192.168.2.523.1.237.91
              May 16, 2024 09:43:28.096486092 CEST49673443192.168.2.523.1.237.91
              May 16, 2024 09:43:34.665687084 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.665731907 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.665807962 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.666013956 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.666027069 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.901734114 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.903896093 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.903917074 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.904978037 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.905168056 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.906126022 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.906199932 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.906325102 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:34.906337023 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:34.963779926 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:35.264015913 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:35.264156103 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:35.264210939 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:35.337507010 CEST49709443192.168.2.5172.67.196.150
              May 16, 2024 09:43:35.337546110 CEST44349709172.67.196.150192.168.2.5
              May 16, 2024 09:43:35.390614033 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.390657902 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.390743017 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.391114950 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.391127110 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.626328945 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.626645088 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.626676083 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.627702951 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.627772093 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.628861904 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.628927946 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.629014015 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.629025936 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.676640034 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.896219015 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.896310091 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.896384954 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.976677895 CEST49710443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.976720095 CEST4434971035.190.80.1192.168.2.5
              May 16, 2024 09:43:35.977359056 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.977386951 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:35.977453947 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.977686882 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:35.977699041 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.207556009 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.220817089 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:36.220856905 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.221427917 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.224744081 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:36.224847078 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.225605011 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:36.272115946 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.481712103 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.481813908 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:36.481861115 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:36.493185043 CEST49713443192.168.2.535.190.80.1
              May 16, 2024 09:43:36.493216991 CEST4434971335.190.80.1192.168.2.5
              May 16, 2024 09:43:37.015976906 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.016015053 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.016084909 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.016652107 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.016669989 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.262833118 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.263504028 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.263526917 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.264842033 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.264916897 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.277863026 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.277950048 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.323146105 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.323167086 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:37.370044947 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:37.698179007 CEST49673443192.168.2.523.1.237.91
              May 16, 2024 09:43:37.887751102 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:37.887785912 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:37.892128944 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:37.914608955 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:37.914624929 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.150789976 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.150942087 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.154898882 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.154918909 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.155230999 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.198154926 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.227751970 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.268121958 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.379856110 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.379920959 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.380065918 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.380326986 CEST49715443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.380342960 CEST4434971523.213.224.106192.168.2.5
              May 16, 2024 09:43:38.447098017 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.447144985 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.447560072 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.447747946 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.447758913 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.678631067 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.678718090 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.685916901 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.685930014 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.686228037 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.689562082 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.732130051 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.908698082 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.908768892 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.908826113 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.909626961 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.909646988 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:38.909660101 CEST49716443192.168.2.523.213.224.106
              May 16, 2024 09:43:38.909666061 CEST4434971623.213.224.106192.168.2.5
              May 16, 2024 09:43:39.112917900 CEST4434970323.1.237.91192.168.2.5
              May 16, 2024 09:43:39.113020897 CEST49703443192.168.2.523.1.237.91
              May 16, 2024 09:43:47.243422031 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:47.243491888 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:47.243741989 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:47.452275038 CEST49714443192.168.2.5192.178.50.68
              May 16, 2024 09:43:47.452306032 CEST44349714192.178.50.68192.168.2.5
              May 16, 2024 09:43:49.535181999 CEST49703443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.535434008 CEST49703443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.557246923 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.557286024 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.557418108 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.561917067 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.561937094 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.708672047 CEST4434970323.1.237.91192.168.2.5
              May 16, 2024 09:43:49.708846092 CEST4434970323.1.237.91192.168.2.5
              May 16, 2024 09:43:49.919445038 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.919532061 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.979536057 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.979553938 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.980087042 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.980138063 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.981591940 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.981630087 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:49.982043982 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:49.982048988 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:50.370994091 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:50.371058941 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:50.371496916 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:50.371541977 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:50.371553898 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:43:50.371592045 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:50.415376902 CEST49721443192.168.2.523.1.237.91
              May 16, 2024 09:43:50.415396929 CEST4434972123.1.237.91192.168.2.5
              May 16, 2024 09:44:36.952306986 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:36.952347994 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:36.952425003 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:36.953847885 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:36.953857899 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:37.194650888 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:37.207668066 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:37.207691908 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:37.208117008 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:37.209609985 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:37.209676027 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:37.260868073 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:47.183537960 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:47.183612108 CEST44349727192.178.50.68192.168.2.5
              May 16, 2024 09:44:47.183680058 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:47.818403006 CEST49727443192.168.2.5192.178.50.68
              May 16, 2024 09:44:47.818442106 CEST44349727192.178.50.68192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              May 16, 2024 09:43:33.084367990 CEST53587011.1.1.1192.168.2.5
              May 16, 2024 09:43:33.211919069 CEST53552241.1.1.1192.168.2.5
              May 16, 2024 09:43:33.862843990 CEST53563471.1.1.1192.168.2.5
              May 16, 2024 09:43:34.432528019 CEST5374953192.168.2.51.1.1.1
              May 16, 2024 09:43:34.432687998 CEST6092153192.168.2.51.1.1.1
              May 16, 2024 09:43:34.546977043 CEST53537491.1.1.1192.168.2.5
              May 16, 2024 09:43:34.547251940 CEST53609211.1.1.1192.168.2.5
              May 16, 2024 09:43:34.549833059 CEST5897153192.168.2.51.1.1.1
              May 16, 2024 09:43:34.549973011 CEST5141253192.168.2.51.1.1.1
              May 16, 2024 09:43:34.664192915 CEST53589711.1.1.1192.168.2.5
              May 16, 2024 09:43:34.665035009 CEST53514121.1.1.1192.168.2.5
              May 16, 2024 09:43:35.267138958 CEST5429253192.168.2.51.1.1.1
              May 16, 2024 09:43:35.267349958 CEST5307553192.168.2.51.1.1.1
              May 16, 2024 09:43:35.381431103 CEST53542921.1.1.1192.168.2.5
              May 16, 2024 09:43:35.381855011 CEST53530751.1.1.1192.168.2.5
              May 16, 2024 09:43:36.900510073 CEST5986153192.168.2.51.1.1.1
              May 16, 2024 09:43:36.900911093 CEST6272853192.168.2.51.1.1.1
              May 16, 2024 09:43:37.013609886 CEST53598611.1.1.1192.168.2.5
              May 16, 2024 09:43:37.013978004 CEST53627281.1.1.1192.168.2.5
              May 16, 2024 09:43:51.159066916 CEST53599801.1.1.1192.168.2.5
              May 16, 2024 09:44:10.438487053 CEST53500781.1.1.1192.168.2.5
              May 16, 2024 09:44:32.737087965 CEST53627981.1.1.1192.168.2.5
              May 16, 2024 09:44:33.344934940 CEST53510261.1.1.1192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              May 16, 2024 09:43:34.432528019 CEST192.168.2.51.1.1.10xe69dStandard query (0)fiveradio-newbam.comA (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.432687998 CEST192.168.2.51.1.1.10xf2f2Standard query (0)fiveradio-newbam.com65IN (0x0001)false
              May 16, 2024 09:43:34.549833059 CEST192.168.2.51.1.1.10x35afStandard query (0)fiveradio-newbam.comA (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.549973011 CEST192.168.2.51.1.1.10x1563Standard query (0)fiveradio-newbam.com65IN (0x0001)false
              May 16, 2024 09:43:35.267138958 CEST192.168.2.51.1.1.10x6cb2Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              May 16, 2024 09:43:35.267349958 CEST192.168.2.51.1.1.10x4c8fStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
              May 16, 2024 09:43:36.900510073 CEST192.168.2.51.1.1.10x99b2Standard query (0)www.google.comA (IP address)IN (0x0001)false
              May 16, 2024 09:43:36.900911093 CEST192.168.2.51.1.1.10xa8efStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              May 16, 2024 09:43:34.546977043 CEST1.1.1.1192.168.2.50xe69dNo error (0)fiveradio-newbam.com104.21.84.200A (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.546977043 CEST1.1.1.1192.168.2.50xe69dNo error (0)fiveradio-newbam.com172.67.196.150A (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.547251940 CEST1.1.1.1192.168.2.50xf2f2No error (0)fiveradio-newbam.com65IN (0x0001)false
              May 16, 2024 09:43:34.664192915 CEST1.1.1.1192.168.2.50x35afNo error (0)fiveradio-newbam.com172.67.196.150A (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.664192915 CEST1.1.1.1192.168.2.50x35afNo error (0)fiveradio-newbam.com104.21.84.200A (IP address)IN (0x0001)false
              May 16, 2024 09:43:34.665035009 CEST1.1.1.1192.168.2.50x1563No error (0)fiveradio-newbam.com65IN (0x0001)false
              May 16, 2024 09:43:35.381431103 CEST1.1.1.1192.168.2.50x6cb2No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              May 16, 2024 09:43:37.013609886 CEST1.1.1.1192.168.2.50x99b2No error (0)www.google.com192.178.50.68A (IP address)IN (0x0001)false
              May 16, 2024 09:43:37.013978004 CEST1.1.1.1192.168.2.50xa8efNo error (0)www.google.com65IN (0x0001)false
              May 16, 2024 09:43:49.261014938 CEST1.1.1.1192.168.2.50x67e2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              May 16, 2024 09:43:49.261014938 CEST1.1.1.1192.168.2.50x67e2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              May 16, 2024 09:44:02.831412077 CEST1.1.1.1192.168.2.50x45ecNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              May 16, 2024 09:44:02.831412077 CEST1.1.1.1192.168.2.50x45ecNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              May 16, 2024 09:44:25.515676975 CEST1.1.1.1192.168.2.50x77e4No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              May 16, 2024 09:44:25.515676975 CEST1.1.1.1192.168.2.50x77e4No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              May 16, 2024 09:44:45.612292051 CEST1.1.1.1192.168.2.50x207eNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              May 16, 2024 09:44:45.612292051 CEST1.1.1.1192.168.2.50x207eNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              • fiveradio-newbam.com
              • a.nel.cloudflare.com
              • fs.microsoft.com
              • https:
                • www.bing.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.549709172.67.196.1504434464C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:34 UTC663OUTGET / HTTP/1.1
              Host: fiveradio-newbam.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-05-16 07:43:35 UTC724INHTTP/1.1 404 Not Found
              Date: Thu, 16 May 2024 07:43:35 GMT
              Content-Type: text/html; charset=utf-8
              Transfer-Encoding: chunked
              Connection: close
              X-Powered-By: Express
              Access-Control-Allow-Origin: *
              Content-Security-Policy: default-src 'none'
              X-Content-Type-Options: nosniff
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8849bcd46eb9b3d7-MIA
              alt-svc: h3=":443"; ma=86400
              2024-05-16 07:43:35 UTC145INData Raw: 38 62 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 70 72 65 3e 43 61 6e 6e 6f 74 20 47 45 54 20 2f 3c 2f 70 72 65 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 0d 0a
              Data Ascii: 8b<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><title>Error</title></head><body><pre>Cannot GET /</pre></body></html>
              2024-05-16 07:43:35 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.54971035.190.80.14434464C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:35 UTC551OUTOPTIONS /report/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://fiveradio-newbam.com
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-05-16 07:43:35 UTC336INHTTP/1.1 200 OK
              content-length: 0
              access-control-max-age: 86400
              access-control-allow-methods: OPTIONS, POST
              access-control-allow-origin: *
              access-control-allow-headers: content-length, content-type
              date: Thu, 16 May 2024 07:43:35 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.54971335.190.80.14434464C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:36 UTC488OUTPOST /report/v4?s=HFgbnoQsvs4WWFLDbrdoMOt16fCrUsB4Hjdc0kRtMufZR0189tw2oW9081MBm9%2FaXAhYVXYSWTvxuB%2BGKtULdh4l2YPzN6za3Iahi0vZ6hKy%2F8JPeo2xE5XxVxdmRFfz8MCIQvRPeA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 391
              Content-Type: application/reports+json
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-05-16 07:43:36 UTC391OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 37 31 35 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 39 36 2e 31 35 30 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 66 69 76 65 72 61 64 69 6f 2d 6e 65 77 62 61
              Data Ascii: [{"age":0,"body":{"elapsed_time":715,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"172.67.196.150","status_code":404,"type":"http.error"},"type":"network-error","url":"https://fiveradio-newba
              2024-05-16 07:43:36 UTC168INHTTP/1.1 200 OK
              content-length: 0
              date: Thu, 16 May 2024 07:43:36 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.54971523.213.224.106443
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:38 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-05-16 07:43:38 UTC468INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/073D)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=170388
              Date: Thu, 16 May 2024 07:43:38 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.54971623.213.224.106443
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:38 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-05-16 07:43:38 UTC531INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=170448
              Date: Thu, 16 May 2024 07:43:38 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-05-16 07:43:38 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination Port
              5192.168.2.54972123.1.237.91443
              TimestampBytes transferredDirectionData
              2024-05-16 07:43:49 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
              Origin: https://www.bing.com
              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
              Accept: */*
              Accept-Language: en-CH
              Content-type: text/xml
              X-Agent-DeviceId: 01000A410900D492
              X-BM-CBT: 1696428841
              X-BM-DateFormat: dd/MM/yyyy
              X-BM-DeviceDimensions: 784x984
              X-BM-DeviceDimensionsLogical: 784x984
              X-BM-DeviceScale: 100
              X-BM-DTZ: 120
              X-BM-Market: CH
              X-BM-Theme: 000000;0078d7
              X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
              X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
              X-Device-isOptin: false
              X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
              X-Device-OSSKU: 48
              X-Device-Touch: false
              X-DeviceID: 01000A410900D492
              X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
              X-MSEdge-ExternalExpType: JointCoord
              X-PositionerType: Desktop
              X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
              X-Search-CortanaAvailableCapabilities: None
              X-Search-SafeSearch: Moderate
              X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
              X-UserAgeClass: Unknown
              Accept-Encoding: gzip, deflate, br
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
              Host: www.bing.com
              Content-Length: 2484
              Connection: Keep-Alive
              Cache-Control: no-cache
              Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1715845398007&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
              2024-05-16 07:43:49 UTC1OUTData Raw: 3c
              Data Ascii: <
              2024-05-16 07:43:49 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
              Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
              2024-05-16 07:43:50 UTC479INHTTP/1.1 204 No Content
              Access-Control-Allow-Origin: *
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              X-MSEdge-Ref: Ref A: AFA042146550458D84A66F152A4931BD Ref B: LAX311000111019 Ref C: 2024-05-16T07:43:50Z
              Date: Thu, 16 May 2024 07:43:50 GMT
              Connection: close
              Alt-Svc: h3=":443"; ma=93600
              X-CDN-TraceID: 0.57ed0117.1715845430.40ff44e


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:03:43:28
              Start date:16/05/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:03:43:31
              Start date:16/05/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2208,i,7082945577606897378,2019628484602091693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:03:43:33
              Start date:16/05/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fiveradio-newbam.com"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly