Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417

Overview

General Information

Sample URL:https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417
Analysis ID:1447096
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3788 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2796 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1996,i,150052660401543626,14398589916102317024,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6984 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/bco/1/fs07dfl97seXBmJiE417 HTTP/1.1Host: ok9static.oktacdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ok9static.oktacdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ok9static.oktacdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: ok9static.oktacdn.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/11@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1996,i,150052660401543626,14398589916102317024,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1996,i,150052660401543626,14398589916102317024,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE4170%VirustotalBrowse
https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE4170%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://ok9static.oktacdn.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
d2im6frcz4axtj.cloudfront.net
13.225.78.59
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        ok9static.oktacdn.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417false
            unknown
            https://ok9static.oktacdn.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            13.225.78.98
            unknownUnited States
            16509AMAZON-02USfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            13.225.78.59
            d2im6frcz4axtj.cloudfront.netUnited States
            16509AMAZON-02USfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.7
            192.168.2.5
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1447096
            Start date and time:2024-05-24 11:26:56 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 9s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/11@6/6
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.163, 172.217.16.142, 74.125.71.84, 34.104.35.123, 20.114.59.183, 93.184.221.240, 192.229.221.95, 52.165.164.15, 13.95.31.18, 142.250.185.131
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 08:27:45 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9794112388753735
            Encrypted:false
            SSDEEP:48:8ud0T48jHOidAKZdA19ehwiZUklqehay+3:8xfQZy
            MD5:CE889B668903650FD07121B96DB62891
            SHA1:2B9A073094B47DA66D9294B78E90DFBF228E2D33
            SHA-256:E4644B3E80CAD8796CFAB422823D7E2AFD938FFC1B0096D3E2F8783CE111463D
            SHA-512:CA85ECDCF19EF8940C8513EAF2945E82FD6F0EA2854009EE4C73401BFE9ABF9A7801ED468D7C2A8D42A331D53425553F2AD091FC7764FBB2BE74D15E1D1C141C
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....{......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XwK...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 08:27:45 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.991401220360949
            Encrypted:false
            SSDEEP:48:8dd0T48jHOidAKZdA1weh/iZUkAQkqehJy+2:8kfq9QYy
            MD5:3971C884F935D53D7C8BD444A55E4BE4
            SHA1:FCA6F51EA65003A1412A1AA3DB91E24E5CF3F4F6
            SHA-256:60C54FB23D643FA9A4291312EC432C55E0705D4EC4DB0B39359773F18445BEC1
            SHA-512:B0F9009C1C80C1E096B0F66D7560411A90D53C0382B894662B3196746B82A351C2B800BE7474EFF0F6F9917F0186AB5D0A4B077973BF6C79EBD92CD970C1CCED
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....P,......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XwK...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2693
            Entropy (8bit):4.002959009748685
            Encrypted:false
            SSDEEP:48:8xdd0T48sHOidAKZdA14tseh7sFiZUkmgqeh7sfy+BX:8xkfjnFy
            MD5:B3156744952A32C8DC34AB58DB54FE67
            SHA1:14EB592B6DA47F832CBF630C3DAE037604BB005F
            SHA-256:9289C0A01F12E8B6A0B8151E7A17D78E1B75ADEBAAF7C8904C997D27498F6632
            SHA-512:A3E6BDB8639E074F31FF1C566558178E78F1F9DA8C5D030D4F04E234F374A4BB4EDE0EC5D4DB9A8FB222B7FBA3C2FD474A7708F7C422F7A80F666A35ADB2E720
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 08:27:45 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.9910126721989228
            Encrypted:false
            SSDEEP:48:8Ud0T48jHOidAKZdA1vehDiZUkwqehty+R:8bfxHy
            MD5:7A84D693EF637C423B94426A0879B26A
            SHA1:BDC2B857A61FE27243C48702141939D92C1CC308
            SHA-256:5A409EAA75579D4117ECCB0841A91B586B0F9B1C31671C2A73FB495185D462B7
            SHA-512:3C19E88C871B860BBFC2DFD4B2743AC37721A925343B9CD8A796DD32E592209D988199BEEAB291B985135628F2ABFA3090A1D00C111B7E3205DDF7FD990092D1
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....=_......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XwK...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 08:27:45 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.9808410405772725
            Encrypted:false
            SSDEEP:48:8ld0T48jHOidAKZdA1hehBiZUk1W1qeh7y+C:8MfR9by
            MD5:594A562AD2339C936FEA8877CDD221DB
            SHA1:6B8A20ED57F58A36FF2C87F6EF71065CE596BC15
            SHA-256:06F60AA7C271391A12A181746A8C7F96DD1C6F4843C8CF83918398037C499411
            SHA-512:215C52A2F5B0253D8D46FB8543D295E60226E8932BD8D295A20A366D548162ECB035191BE45CBF9B320DB886F68EE4EB48D3833E1672FEEC0091517770721DD7
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....~.......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XwK...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 08:27:45 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2683
            Entropy (8bit):3.991122228886816
            Encrypted:false
            SSDEEP:48:8cd0T48jHOidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbFy+yT+:8jfNT/TbxWOvTbFy7T
            MD5:17FBCBEC285F418949AEBCE6375A0199
            SHA1:BFA893D04340F90BC0F68E2A1FDBEFCEF547D80A
            SHA-256:3BF17DEE79A24656D1B0DC61D1C655B874E4EF2A22A901D015BB7F964BC1C657
            SHA-512:2322CFBBE6C94ED56BD6634D09AE0923ED1F39BC724D13624F1074863EBDD72806E1BB8F947C1D4B41E6E362CA4CBF9CA1C6484B3A56071703840B605F5CE2E3
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....MI......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.XtK....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XtK....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.XtK....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.XtK..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.XwK...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H.~......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 420 x 105, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):5941
            Entropy (8bit):7.880463140917738
            Encrypted:false
            SSDEEP:96:taRuLdAdOIorpNefF4yG/AZsyGIyGbmvXpoLwvTNUq6ByiPWLvAwIC5cwOdoGbH:88LdATExyG6sd0kDUB7KAwIycwYB
            MD5:A717A8BD0DE6C0D92C79DE048E78862A
            SHA1:8A26A28F367DB3A77D334AFD397901EEE7095241
            SHA-256:CFF3521A4A08E79903537748E872A0A3ADAC826D6C17D600DA72F4F544B687C2
            SHA-512:F8D7232FA948FFB01A84743F67FC00FDEAA79021DBC836F621257DFBF716D9E9F2E9C02D66A9E14B3DC3396DE379083EA05FD31D02922E6207A40380C8D67848
            Malicious:false
            Reputation:low
            URL:https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417
            Preview:.PNG........IHDR.......i.....uMW.....IDATx..y.T.......6....P.7.... .BD.........FGH4.D..!h.~...T> ...j@A.ib..;.b.......L....N.u..y..s...{oU..V..:E....................................................(.....L..h...f....f........i....m..*...9dgl.95x...P.*o[TU.I.Rj2b3.-..A........................A....A....A. .... .... A....@....@. H... H... H.$.....V.p....Z......-. ....zFq....e#k2bKG.....G.j2z...........~../..h.......h....E..cK.hn..YP..*[.lu..L..e.QyA.R...4..%e.QD...Yd.......f....,q..Ye...$..oi.U..(;.........g..QD ...Q...Y"H?..Z&l..CQ.@..R*. ..R....Fe.uZ...$. H... J......&K..... ..A......Y.....).....XY.......nP.F....f.].....). ......4...@... E%H.GO7[.."e.Q......RT....B.z............. ]...j.. ..A.R....s...........H.i...(./.3x?.!.Qv2..V$.w.....:.sN....J...hem....h.pe=S..._'eM.8Mmu9.N.&v.vUvP..R;]o...c...h.Mq.wS..Z.:Y......(Hs. u.....&..>@....V..e...Y.....+.VD.e..Y.a[..4.. )=......F(;.....kjH..1nL[.h./Wv....K.V..W..Y..].....\...eOR<B.....ri.#......'*{F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:dropped
            Size (bytes):5430
            Entropy (8bit):2.7209270279774733
            Encrypted:false
            SSDEEP:24:E+As6X5OjYp4bEZVJkeZvwnDK4lBit6ubJdhlcolwptQutJt9LSWtF4alXlAXmBQ:Gs6XwjHbqkeKVlA9/zv3urGVu1gmykQ
            MD5:449C9DD651DB589388B721EB2496F5B0
            SHA1:64F3B213A89A00F7B0940271576ECC72280236F7
            SHA-256:F9E86FB363A05F75AB3B525439D46BF4911D4CD4AE94C656C0198206374002AA
            SHA-512:410C701B5050A6D039EE82C6D1B1B596983622E35256A2628A108B20E03D8B0CC85D2033292D5E13ACE0199FFFBB34DBFE9DF82EA4161285082837056A06F2DC
            Malicious:false
            Reputation:low
            Preview:............ .h...&... .... .........(....... ..... .................................y)..y)..y).Lz)..z)..z)..z)..z)..z)..y(.Vx)..x)..........z+..y)..y)..y)..z)..z)..z)..z)..z)..z)..z)..z)..y)..y)..y)..z+..z*..z*..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..y)..{*..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..y(..y).Vz)..z)..z)..z)..z)..z(.Py)..x(..y).Pz)..z)..z)..z)..z)..z).Lz)..z)..z)..z)..z)..y)..v+..|'..s'..|*..y). z)..z)..z)..z)..z)..z)..z)..z)..z)..y).Pz)..s'..........z'..z*..z).Qz)..z)..z)..z)..z)..z)..z)..z)..y(..y)..................z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..................z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z(.Lz)..y'..........s&..{)..y).Pz)..z)..z)..z)..z)..z)..z)..z)..z)..y)..|*..s'..w'..},..y)..z)..z)..z)..z)..z)..y).Lz)..z)..z)..z)..z)..y(.Px(..y)..y).Lz)..z)..z)..z)..z)..y).Vx)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..w)..{*..y)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..x(..y(..z+..z)..z)..z)..z)..z)..z)
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:downloaded
            Size (bytes):5430
            Entropy (8bit):2.7209270279774733
            Encrypted:false
            SSDEEP:24:E+As6X5OjYp4bEZVJkeZvwnDK4lBit6ubJdhlcolwptQutJt9LSWtF4alXlAXmBQ:Gs6XwjHbqkeKVlA9/zv3urGVu1gmykQ
            MD5:449C9DD651DB589388B721EB2496F5B0
            SHA1:64F3B213A89A00F7B0940271576ECC72280236F7
            SHA-256:F9E86FB363A05F75AB3B525439D46BF4911D4CD4AE94C656C0198206374002AA
            SHA-512:410C701B5050A6D039EE82C6D1B1B596983622E35256A2628A108B20E03D8B0CC85D2033292D5E13ACE0199FFFBB34DBFE9DF82EA4161285082837056A06F2DC
            Malicious:false
            Reputation:low
            URL:https://ok9static.oktacdn.com/favicon.ico
            Preview:............ .h...&... .... .........(....... ..... .................................y)..y)..y).Lz)..z)..z)..z)..z)..z)..y(.Vx)..x)..........z+..y)..y)..y)..z)..z)..z)..z)..z)..z)..z)..z)..y)..y)..y)..z+..z*..z*..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..y)..{*..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..y(..y).Vz)..z)..z)..z)..z)..z(.Py)..x(..y).Pz)..z)..z)..z)..z)..z).Lz)..z)..z)..z)..z)..y)..v+..|'..s'..|*..y). z)..z)..z)..z)..z)..z)..z)..z)..z)..y).Pz)..s'..........z'..z*..z).Qz)..z)..z)..z)..z)..z)..z)..z)..y(..y)..................z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..................z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z(.Lz)..y'..........s&..{)..y).Pz)..z)..z)..z)..z)..z)..z)..z)..z)..y)..|*..s'..w'..},..y)..z)..z)..z)..z)..z)..y).Lz)..z)..z)..z)..z)..y(.Px(..y)..y).Lz)..z)..z)..z)..z)..y).Vx)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..w)..{*..y)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..z)..x(..y(..z+..z)..z)..z)..z)..z)..z)
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            May 24, 2024 11:27:39.295067072 CEST49675443192.168.2.523.1.237.91
            May 24, 2024 11:27:39.295067072 CEST49674443192.168.2.523.1.237.91
            May 24, 2024 11:27:39.420212030 CEST49673443192.168.2.523.1.237.91
            May 24, 2024 11:27:45.619034052 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.619069099 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:45.619132042 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.619771004 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.619784117 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:45.619832039 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.620590925 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.620604038 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:45.620920897 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:45.620934010 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.367993116 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.370944977 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.370966911 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.372602940 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.372700930 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.374022961 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.374108076 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.374492884 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.374504089 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.380901098 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:46.381380081 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.381390095 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:46.382258892 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:46.382332087 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.384176016 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.384495020 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:46.432223082 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.432259083 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:46.478296041 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.559235096 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.650657892 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.650852919 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.650893927 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.650943995 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.651014090 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.651082993 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.651082993 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.651104927 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.651207924 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.651272058 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.731277943 CEST49709443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.731342077 CEST4434970913.225.78.59192.168.2.5
            May 24, 2024 11:27:46.800376892 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:46.842509031 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.111464977 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.111512899 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.111552000 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.111574888 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:47.111587048 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.111645937 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:47.142725945 CEST49710443192.168.2.513.225.78.59
            May 24, 2024 11:27:47.142745972 CEST4434971013.225.78.59192.168.2.5
            May 24, 2024 11:27:47.449973106 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:47.450037956 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:47.450117111 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:47.450402021 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:47.450419903 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.184564114 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:48.184608936 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:48.184695959 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:48.185828924 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:48.185857058 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:48.194600105 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.195067883 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.195100069 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.196536064 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.196608067 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.197536945 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.197621107 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.198870897 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.198880911 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.251785994 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.473627090 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.481605053 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.481631041 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.481744051 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.481782913 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.481817961 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.481887102 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.496651888 CEST49713443192.168.2.513.225.78.98
            May 24, 2024 11:27:48.496685028 CEST4434971313.225.78.98192.168.2.5
            May 24, 2024 11:27:48.875371933 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:48.876657009 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:48.876720905 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:48.877620935 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:48.877705097 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:48.901499033 CEST49675443192.168.2.523.1.237.91
            May 24, 2024 11:27:48.901499033 CEST49674443192.168.2.523.1.237.91
            May 24, 2024 11:27:49.026494026 CEST49673443192.168.2.523.1.237.91
            May 24, 2024 11:27:49.088556051 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.088648081 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:49.088771105 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.093822956 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.093862057 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:49.295136929 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:49.295397997 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:49.342269897 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:49.342330933 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:49.390281916 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:27:49.765402079 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:49.765554905 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.782785892 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.782864094 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:49.783365965 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:49.839200020 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.860193968 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:49.906498909 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:50.070945978 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:50.071106911 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:50.071295977 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.071296930 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.071386099 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:50.071484089 CEST49715443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.071502924 CEST443497152.19.244.127192.168.2.5
            May 24, 2024 11:27:50.143079996 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.143142939 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:50.143600941 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.143600941 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.143671989 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:50.714294910 CEST4434970323.1.237.91192.168.2.5
            May 24, 2024 11:27:50.714396000 CEST49703443192.168.2.523.1.237.91
            May 24, 2024 11:27:50.808024883 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:50.808119059 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.837393999 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.837424994 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:50.838337898 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:50.842961073 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:50.890496969 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:51.128127098 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:51.128300905 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:51.128355026 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:51.130219936 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:51.130219936 CEST49716443192.168.2.52.19.244.127
            May 24, 2024 11:27:51.130239964 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:51.130253077 CEST443497162.19.244.127192.168.2.5
            May 24, 2024 11:27:58.775791883 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:58.775880098 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:27:58.775950909 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:28:00.693025112 CEST49714443192.168.2.5142.250.186.100
            May 24, 2024 11:28:00.693099022 CEST44349714142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.183048964 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:48.183082104 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.183479071 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:48.186549902 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:48.186564922 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.856470108 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.856877089 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:48.856909037 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.857368946 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.857822895 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:48.857899904 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:48.901848078 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:28:58.745379925 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:58.745547056 CEST44349726142.250.186.100192.168.2.5
            May 24, 2024 11:28:58.750422955 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:29:00.576340914 CEST49726443192.168.2.5142.250.186.100
            May 24, 2024 11:29:00.576356888 CEST44349726142.250.186.100192.168.2.5
            TimestampSource PortDest PortSource IPDest IP
            May 24, 2024 11:27:44.150175095 CEST53651561.1.1.1192.168.2.5
            May 24, 2024 11:27:44.291568041 CEST53626491.1.1.1192.168.2.5
            May 24, 2024 11:27:45.467603922 CEST53648941.1.1.1192.168.2.5
            May 24, 2024 11:27:45.599435091 CEST5658953192.168.2.51.1.1.1
            May 24, 2024 11:27:45.599647045 CEST5607553192.168.2.51.1.1.1
            May 24, 2024 11:27:45.607992887 CEST53565891.1.1.1192.168.2.5
            May 24, 2024 11:27:45.618268013 CEST53560751.1.1.1192.168.2.5
            May 24, 2024 11:27:47.415896893 CEST5476553192.168.2.51.1.1.1
            May 24, 2024 11:27:47.416115046 CEST5035453192.168.2.51.1.1.1
            May 24, 2024 11:27:47.441173077 CEST53547651.1.1.1192.168.2.5
            May 24, 2024 11:27:47.449318886 CEST53503541.1.1.1192.168.2.5
            May 24, 2024 11:27:48.132853031 CEST5257553192.168.2.51.1.1.1
            May 24, 2024 11:27:48.133562088 CEST5742953192.168.2.51.1.1.1
            May 24, 2024 11:27:48.172442913 CEST53525751.1.1.1192.168.2.5
            May 24, 2024 11:27:48.192420959 CEST53574291.1.1.1192.168.2.5
            May 24, 2024 11:28:02.648880959 CEST53532681.1.1.1192.168.2.5
            May 24, 2024 11:28:21.550291061 CEST53580621.1.1.1192.168.2.5
            May 24, 2024 11:28:43.917804956 CEST53628421.1.1.1192.168.2.5
            May 24, 2024 11:28:44.011974096 CEST53598371.1.1.1192.168.2.5
            TimestampSource IPDest IPChecksumCodeType
            May 24, 2024 11:27:48.192497015 CEST192.168.2.51.1.1.1c1fe(Port unreachable)Destination Unreachable
            May 24, 2024 11:28:43.917932034 CEST192.168.2.51.1.1.1c225(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            May 24, 2024 11:27:45.599435091 CEST192.168.2.51.1.1.10x81e0Standard query (0)ok9static.oktacdn.comA (IP address)IN (0x0001)false
            May 24, 2024 11:27:45.599647045 CEST192.168.2.51.1.1.10x7ea0Standard query (0)ok9static.oktacdn.com65IN (0x0001)false
            May 24, 2024 11:27:47.415896893 CEST192.168.2.51.1.1.10x3320Standard query (0)ok9static.oktacdn.comA (IP address)IN (0x0001)false
            May 24, 2024 11:27:47.416115046 CEST192.168.2.51.1.1.10xd3f7Standard query (0)ok9static.oktacdn.com65IN (0x0001)false
            May 24, 2024 11:27:48.132853031 CEST192.168.2.51.1.1.10xa21dStandard query (0)www.google.comA (IP address)IN (0x0001)false
            May 24, 2024 11:27:48.133562088 CEST192.168.2.51.1.1.10x26c5Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            May 24, 2024 11:27:45.607992887 CEST1.1.1.1192.168.2.50x81e0No error (0)ok9static.oktacdn.comd2im6frcz4axtj.cloudfront.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:27:45.607992887 CEST1.1.1.1192.168.2.50x81e0No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.59A (IP address)IN (0x0001)false
            May 24, 2024 11:27:45.607992887 CEST1.1.1.1192.168.2.50x81e0No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.88A (IP address)IN (0x0001)false
            May 24, 2024 11:27:45.607992887 CEST1.1.1.1192.168.2.50x81e0No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.122A (IP address)IN (0x0001)false
            May 24, 2024 11:27:45.607992887 CEST1.1.1.1192.168.2.50x81e0No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.98A (IP address)IN (0x0001)false
            May 24, 2024 11:27:45.618268013 CEST1.1.1.1192.168.2.50x7ea0No error (0)ok9static.oktacdn.comd2im6frcz4axtj.cloudfront.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:27:47.441173077 CEST1.1.1.1192.168.2.50x3320No error (0)ok9static.oktacdn.comd2im6frcz4axtj.cloudfront.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:27:47.441173077 CEST1.1.1.1192.168.2.50x3320No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.98A (IP address)IN (0x0001)false
            May 24, 2024 11:27:47.441173077 CEST1.1.1.1192.168.2.50x3320No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.122A (IP address)IN (0x0001)false
            May 24, 2024 11:27:47.441173077 CEST1.1.1.1192.168.2.50x3320No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.88A (IP address)IN (0x0001)false
            May 24, 2024 11:27:47.441173077 CEST1.1.1.1192.168.2.50x3320No error (0)d2im6frcz4axtj.cloudfront.net13.225.78.59A (IP address)IN (0x0001)false
            May 24, 2024 11:27:47.449318886 CEST1.1.1.1192.168.2.50xd3f7No error (0)ok9static.oktacdn.comd2im6frcz4axtj.cloudfront.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:27:48.172442913 CEST1.1.1.1192.168.2.50xa21dNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
            May 24, 2024 11:27:48.192420959 CEST1.1.1.1192.168.2.50x26c5No error (0)www.google.com65IN (0x0001)false
            May 24, 2024 11:28:01.051872969 CEST1.1.1.1192.168.2.50x391fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:28:01.051872969 CEST1.1.1.1192.168.2.50x391fNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 24, 2024 11:28:15.433309078 CEST1.1.1.1192.168.2.50xf6e8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:28:15.433309078 CEST1.1.1.1192.168.2.50xf6e8No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 24, 2024 11:28:36.629578114 CEST1.1.1.1192.168.2.50xe8d5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:28:36.629578114 CEST1.1.1.1192.168.2.50xe8d5No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 24, 2024 11:28:57.023274899 CEST1.1.1.1192.168.2.50xff3aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 24, 2024 11:28:57.023274899 CEST1.1.1.1192.168.2.50xff3aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • ok9static.oktacdn.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.54970913.225.78.594432796C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-24 09:27:46 UTC693OUTGET /fs/bco/1/fs07dfl97seXBmJiE417 HTTP/1.1
            Host: ok9static.oktacdn.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-24 09:27:46 UTC682INHTTP/1.1 200 OK
            Content-Type: image/png
            Content-Length: 5941
            Connection: close
            Date: Wed, 22 May 2024 18:51:24 GMT
            Server: nginx
            Last-Modified: Wed, 03 May 2023 14:48:37 GMT
            ETag: "a717a8bd0de6c0d92c79de048e78862a"
            Expires: Thu, 22 May 2025 18:51:24 GMT
            Cache-Control: max-age=31536000
            Cache-Control: public,max-age=31536000,s-maxage=1814400
            Strict-Transport-Security: max-age=315360000; includeSubDomains
            Access-Control-Allow-Origin: *
            Accept-Ranges: bytes
            X-Cache: Hit from cloudfront
            Via: 1.1 21a3da42c823b5a4a2d9c4c63248bbd6.cloudfront.net (CloudFront)
            X-Amz-Cf-Pop: FRA2-C2
            X-Amz-Cf-Id: pYVOuIlIH8yEqUOk1d76Q2xV4NpkrWfuf5isP6hoP6ZFBH-xXxM4tQ==
            Age: 138982
            2024-05-24 09:27:46 UTC5941INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 a4 00 00 00 69 08 06 00 00 00 75 4d 57 eb 00 00 16 fc 49 44 41 54 78 da ed 9d 79 98 54 c5 d5 c6 cf 00 d3 83 12 36 11 11 c1 11 50 10 37 0c 8a 10 c4 20 a2 42 44 98 19 06 07 90 b8 05 97 88 46 47 48 34 91 44 a3 89 21 68 a2 7e 89 1a 17 54 3e 20 ec 8c cb c7 6a 40 41 f3 69 62 8c 8a 3b 02 62 14 05 15 15 a2 ec cb 4c ea a4 ab 1f db b1 bb 4e dd ba 75 a7 97 79 7f cf 73 fe 80 e9 7b 6f 55 dd ba f5 56 9d aa 3a 45 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e4 07 05 28 02 00 00 a8 cf 4c 1d d0 a4 68 c6 90 ab 8a 66 95 8c cb 94 c5 66 96 dc 80 17 01 00 00 f5 9d 69 03 db c6 e6 95 6d 88 cd 2a d9 99 11 9b 39 64 67 6c fe
            Data Ascii: PNGIHDRiuMWIDATxyT6P7 BDFGH4D!h~T> j@Aib;bLNuys{oUV:E(Lhffim*9dgl


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.54971013.225.78.594432796C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-24 09:27:46 UTC627OUTGET /favicon.ico HTTP/1.1
            Host: ok9static.oktacdn.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-24 09:27:47 UTC570INHTTP/1.1 200 OK
            Content-Type: image/x-icon
            Content-Length: 5430
            Connection: close
            Server: nginx
            Accept-Ranges: bytes
            Last-Modified: Mon, 13 May 2024 21:22:32 GMT
            x-content-type-options: nosniff
            Strict-Transport-Security: max-age=315360000; includeSubDomains
            X-Robots-Tag: noindex,nofollow
            Date: Fri, 24 May 2024 09:27:46 GMT
            ETag: W/"5430-1715635352000"
            X-Cache: RefreshHit from cloudfront
            Via: 1.1 ec9e3bc729d9c6d55ed32446408ad62e.cloudfront.net (CloudFront)
            X-Amz-Cf-Pop: FRA2-C2
            X-Amz-Cf-Id: Z_UVDcdtwD_ofeOWpL5xVPkxV98Sp3AJd2yC_Yyw2aFAW8NyXrdeyw==
            2024-05-24 09:27:47 UTC5430INData Raw: 00 00 01 00 02 00 10 10 00 00 01 00 20 00 68 04 00 00 26 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 8e 04 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 20 00 00 00 00 00 00 04 00 00 13 0b 00 00 13 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 79 29 00 00 79 29 00 0a 79 29 00 4c 7a 29 00 a9 7a 29 00 df 7a 29 00 fb 7a 29 00 fb 7a 29 00 df 7a 29 00 a8 79 28 00 56 78 29 00 0b 78 29 00 00 00 00 00 00 00 00 00 00 7a 2b 00 00 79 29 00 00 79 29 00 1c 79 29 00 99 7a 29 00 ec 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ee 79 29 00 95 79 29 00 1d 79 29 00 00 7a 2b 00 00 7a 2a 00 00 7a 2a 00 1e 7a 29 00 b0 7a 29 00 fe 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a
            Data Ascii: h& ( y)y)y)Lz)z)z)z)z)z)y(Vx)x)z+y)y)y)z)z)z)z)z)z)z)z)y)y)y)z+z*z*z)z)z)z)z)z)z)z)z)z)z


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.54971313.225.78.984432796C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-24 09:27:48 UTC356OUTGET /favicon.ico HTTP/1.1
            Host: ok9static.oktacdn.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-24 09:27:48 UTC571INHTTP/1.1 200 OK
            Content-Type: image/x-icon
            Content-Length: 5430
            Connection: close
            Server: nginx
            Accept-Ranges: bytes
            Last-Modified: Mon, 13 May 2024 21:22:32 GMT
            x-content-type-options: nosniff
            Strict-Transport-Security: max-age=315360000; includeSubDomains
            X-Robots-Tag: noindex,nofollow
            Date: Fri, 24 May 2024 09:27:46 GMT
            ETag: W/"5430-1715635352000"
            X-Cache: Hit from cloudfront
            Via: 1.1 58b222ebbb6cc6c8c8c9a46127ae3a3e.cloudfront.net (CloudFront)
            X-Amz-Cf-Pop: FRA2-C2
            X-Amz-Cf-Id: hM3Q9JmSaaGC6cN4P1upuwHXf-s10dInwx7d0210bEt2hcjjsT1h3w==
            Age: 1
            2024-05-24 09:27:48 UTC5430INData Raw: 00 00 01 00 02 00 10 10 00 00 01 00 20 00 68 04 00 00 26 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 8e 04 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 20 00 00 00 00 00 00 04 00 00 13 0b 00 00 13 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 79 29 00 00 79 29 00 0a 79 29 00 4c 7a 29 00 a9 7a 29 00 df 7a 29 00 fb 7a 29 00 fb 7a 29 00 df 7a 29 00 a8 79 28 00 56 78 29 00 0b 78 29 00 00 00 00 00 00 00 00 00 00 7a 2b 00 00 79 29 00 00 79 29 00 1c 79 29 00 99 7a 29 00 ec 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ee 79 29 00 95 79 29 00 1d 79 29 00 00 7a 2b 00 00 7a 2a 00 00 7a 2a 00 1e 7a 29 00 b0 7a 29 00 fe 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a 29 00 ff 7a
            Data Ascii: h& ( y)y)y)Lz)z)z)z)z)z)y(Vx)x)z+y)y)y)z)z)z)z)z)z)z)z)y)y)y)z+z*z*z)z)z)z)z)z)z)z)z)z)z


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.5497152.19.244.127443
            TimestampBytes transferredDirectionData
            2024-05-24 09:27:49 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-24 09:27:50 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=196865
            Date: Fri, 24 May 2024 09:27:49 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.5497162.19.244.127443
            TimestampBytes transferredDirectionData
            2024-05-24 09:27:50 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-24 09:27:51 UTC535INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=196909
            Date: Fri, 24 May 2024 09:27:51 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-05-24 09:27:51 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:05:27:39
            Start date:24/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:05:27:42
            Start date:24/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1996,i,150052660401543626,14398589916102317024,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:05:27:44
            Start date:24/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ok9static.oktacdn.com/fs/bco/1/fs07dfl97seXBmJiE417"
            Imagebase:0x7ff715980000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly