Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://165.225.115.136

Overview

General Information

Sample URL:http://165.225.115.136
Analysis ID:1465769
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML title does not match URL

Classification

  • System is w10x64
  • chrome.exe (PID: 4228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1696 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1856,i,4093924628700597556,1019391488178839724,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://165.225.115.136" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjHTTP Parser: Number of links: 0
Source: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjHTTP Parser: Title: Welcome To Zscaler Directory Authentication does not match URL
Source: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjHTTP Parser: No favicon
Source: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjHTTP Parser: No <meta name="author".. found
Source: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:60692 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownTCP traffic detected without corresponding DNS query: 165.225.115.136
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /auD?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj HTTP/1.1Host: gateway.zscloud.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj HTTP/1.1Host: gateway.zscloud.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _sm_au_d=1
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: gateway.zscloud.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _sm_au_d=1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 165.225.115.136Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: gateway.zscloud.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/htmlServer: Zscaler/6.2Cache-Control: no-cacheAccess-Control-Allow-Origin: *Content-length: 13679<!--# bq6ZFW7rpStTMbq6ZFW7rpStTMbq6ZFW7rpStTMd--><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd"><html><head><meta name="description" content="Zscaler makes the internet safe for businesses by protecting their employees from malware, viruses, and other security threats."><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Internet Security by Zscaler</title><script language="JavaScript">var defLang = 'en_US'</script><!--<img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png">--><style type="text/css">body {background-color:#e3e3e3;font-family:Arial, sans-serif;font-size:12px;color:#4B4F54;}a {cursor:pointer;text-decoration:none;color:#009dd0;}table {margin-top:10px;}td table {margin-top:0;text-align:center;}img {max-height:75px;max-width:430px;}.pg {position:absolute;top:0;bottom:0;left:0;right:0;overflow-x:hidden;white-space:nowrap;}.pg:before {content:"";display:inline-block;height:100%;vertical-align:middle;}.pg_cont {display:inline-block;vertical-align:middle;width:100%;position:relative;}.a_i {width:19px;height:19px;margin-right:10px;background-size: 19px 19px;display:inline-block;}.m_tbl {width:100%;max-width:758px;background:#e3e3e3;min-width:600px;}.pg.red .eu_h {color:#fd4239;border-top:3px solid #fd4239;}.pg.red .eu_h .a_i {background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAABoElEQVR4nK3Uz2vIYRzA8dcMzWGJdjSZKZLCDphfB7XVHBAXF2XFpJxd+BvUbtY20m4KxVExtbWkUYQLByU3OVhpy8zh+Tzr2dN3t30un1/P834+z/N8noc1lBZYPNVbx3twDQPYFuN+4RUm8ARL5YTWFzPWVZA2jGIWQ+jMC2ILzuERZrCjrmB9YW/CcxwLfwFTAf6J3TiPzTiMNziJz02wkQL0DpfwsVp8OCAb0IFnOIA5LG/zeEwWgN4GUBeeBihLN25mJ8NuhF7CIOYbQJPYHv59fAv7OlpL2OnQH2IbpexsAF3BePgdOFTC2kO/bQC9LED3AvTPymPoYuUFkHqprqizAF0NECwWY9vKynJi1yqg8QoEBwv7ewmbCt2HIw2goQrUgv6wF6QmXoY9KMqdLkBjDSDSueU3+Bi/S9gE3oedY2PS+6xBF3En7Hnczol8AX9xAa+xNWJHpXOajXwPzuBsAR7E1xoGX3BC6vJu7MVdzfIHl/GwDNa/xifsxy1xQ5XMSS2ypwax+n+Wc/ukr2YjfkhNXT81pP9sTeU/6YpejkX0NUMAAAAASUVORK5CYII=');}.pg.red .eu_h, .pg.red .eu_co, .pg.red .hr {border-left:3px solid #fd4239;border-right:3px solid #fd4239;}.pg.red .fo {border-bottom-color:#fd4239;}.pg.red .eu_co.st{border:0;}.pg.yl .eu_h .a_i {background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGQAAABkCAYAAABw4pVUAAAFgUlEQVR4nO2dOWxcVRSGP0+wWWKSiC1WMAV7SAI0bBLBLBI0bEUSyiSAFCOgYLMpEBA3JCEUCISQEBIIKtIgpaCho6KhAglkCQlRRBAhKBIQW4Di5iHH+M28c+85955h7leO5y6eb972v/PuQKVSqQwNY5+8V3oKYi4C3gXuaPn7x8Bu4Eim+agxsxN6pSch5GrgM9plANx58j0bs8xImWESsho4BJzf4b1TwAfAGaYzMmCYhDyH7Ft/DTBvNBczhkXINPBkRLs54ALluZgyLEIWiNv9TAIvKM/FlGEQsoVw1hTLLHCFzlTsGQYh+0mb52nAS0pzMce7kNuBuxX62QbcpNCPOZ6F9ICXFfs7CI
Source: chromecache_107.1.drString found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd
Source: chromecache_107.1.drString found in binary or memory: https://gateway.zscloud.net/favicon.ico
Source: chromecache_107.1.drString found in binary or memory: https://login.zscloud.net/img_logo_new1.png
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60696
Source: unknownNetwork traffic detected: HTTP traffic on port 60696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean1.win@22/6@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1856,i,4093924628700597556,1019391488178839724,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://165.225.115.136"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1856,i,4093924628700597556,1019391488178839724,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://165.225.115.1360%Avira URL Cloudsafe
http://165.225.115.1360%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://165.225.115.136/0%Avira URL Cloudsafe
https://gateway.zscloud.net/favicon.ico0%Avira URL Cloudsafe
https://login.zscloud.net/img_logo_new1.png0%Avira URL Cloudsafe
http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd0%Avira URL Cloudsafe
https://gateway.zscloud.net/auD?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj0%Avira URL Cloudsafe
http://165.225.115.136/0%VirustotalBrowse
http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd0%VirustotalBrowse
https://login.zscloud.net/img_logo_new1.png0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    172.217.16.196
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        gateway.zscloud.net
        165.225.72.46
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://gateway.zscloud.net/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjfalse
            unknown
            https://gateway.zscloud.net/auD?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWjfalse
            • Avira URL Cloud: safe
            unknown
            http://165.225.115.136/false
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtdchromecache_107.1.drfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://login.zscloud.net/img_logo_new1.pngchromecache_107.1.drfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            165.225.115.136
            unknownUnited States
            53813ZSCALER-INCUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            165.225.72.46
            gateway.zscloud.netUnited States
            62044ZSCALER-EMEACHfalse
            172.217.16.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1465769
            Start date and time:2024-07-02 02:58:32 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 25s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://165.225.115.136
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:9
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean1.win@22/6@4/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 216.58.206.67, 64.233.166.84, 216.58.206.78, 34.104.35.123, 216.58.206.42, 172.217.18.106, 216.58.212.138, 142.250.185.138, 142.250.186.74, 172.217.23.106, 216.58.206.74, 142.250.185.74, 142.250.185.170, 142.250.184.234, 172.217.16.202, 142.250.186.106, 172.217.18.10, 142.250.185.202, 142.250.186.138, 216.58.212.170, 20.12.23.50, 199.232.210.172, 192.229.221.95, 20.242.39.171, 52.165.164.15, 142.250.186.163
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            InputOutput
            URL: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj Model: Perplexity: mixtral-8x7b-instruct
            {"loginform": true,"urgency": false,"captcha": false,"reasons": ["The webpage contains a 'Sign In' button which is a part of the login form.","The text explicitly requests the user to sign in to keep safe from internet threats.","The webpage contains a User Name field as a part of the login form."]}
            Title: Welcome To Zscaler Directory Authentication OCR: a Sign In To keep you safe from internet threats, please sign in to your company's security service. User Name Enter your User Name... Sign In Need help? Contact your IT support 
            URL: https://gateway.zscloud.net Model: gpt-4o
            ```json{  "phishing_score": 2,  "brands": "Zscaler",  "phishing": false,  "suspicious_domain": false,  "has_prominent_loginform": true,  "has_captcha": false,  "setechniques": false,  "has_suspicious_link": false,  "legitmate_domain": "zscloud.net",  "reasons": "The URL 'https://gateway.zscloud.net' appears to be legitimate as it belongs to the domain 'zscloud.net', which is associated with Zscaler, a known cybersecurity company. The login form is prominent, but there are no other suspicious elements such as social engineering techniques or suspicious links. The absence of a CAPTCHA is noted but not necessarily indicative of phishing. Overall, the site appears to be legitimate."}
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with very long lines (2391)
            Category:downloaded
            Size (bytes):13679
            Entropy (8bit):6.097063121023857
            Encrypted:false
            SSDEEP:384:DEH/lcYokdVDfchV495iu5j0A8VDjkh1QB6Efhc:DoNcYoUchVnCj0Ao4SB6H
            MD5:3F56CD9610AE035373ABDEBC3DC7916E
            SHA1:959AA5F26CF34B4110DDD46D21DF6FB3B23C9E39
            SHA-256:0C74CACD7650A6EAD3495CB7EF20EDC7D4DA037B060DDD665E8970A6A36CEABA
            SHA-512:2D7C3DC78B786297C6EB80B0912C47E7D696081D7C06B2B776947A36CA94875DC07980A262CA0E2B3655DFA8B62E2FC7663BFD984486CE282EE367D7C0C3B96B
            Malicious:false
            Reputation:low
            URL:https://gateway.zscloud.net/favicon.ico
            Preview: # bq6ZFW7rpStTMbq6ZFW7rpStTMbq6ZFW7rpStTMd-->.<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd">.<html>.<head>.<meta name="description" content="Zscaler makes the internet safe for businesses by protecting their employees from malware, viruses, and other security threats.">.<meta http-equiv="Content-Type" content="text/html; charset=utf-8">.<meta name="viewport" content="width=device-width, initial-scale=1">.<title>Internet Security by Zscaler</title>.<script language="JavaScript">var defLang = 'en_US'</script>. <img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png">-->.<style type="text/css">.body {.background-color:#e3e3e3;.font-family:Arial, sans-serif;.font-size:12px;.color:#4B4F54;.}.a {.cursor:pointer;.text-decoration:none;.color:#009dd0;.}.table {.margin-top:10px;.}.td table {.margin-top:0;.text-align:center;.}.img {.max-height:75px;.max-width:430px;.}..pg {.position:absolute;.top:0;.bo
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):20
            Entropy (8bit):3.5086949695628418
            Encrypted:false
            SSDEEP:3:cX3Pm:cX/m
            MD5:F3246E2E7C03B8102872CFD9AB4870A8
            SHA1:DD24ED1077C3ADBF4C396AC5D39AF394B14A7764
            SHA-256:2ED11ED8A93AD0818D20C853683FB4B11FFBB29245CC00E43C713433B69A734C
            SHA-512:38D39CA5E44CE88864F93D14EC0F2A45255153BDC6A17E369492BCB6D6D5684D3A4CECFF5569A84A529DCE90394B6B0842E0227DA4CC7ABB21A88083E56958BA
            Malicious:false
            Reputation:low
            URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAknWClbi3s4yxIFDTQizjc=?alt=proto
            Preview:Cg0KCw00Is43GgQIZBgC
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with very long lines (22035), with no line terminators
            Category:downloaded
            Size (bytes):22035
            Entropy (8bit):5.419647881196598
            Encrypted:false
            SSDEEP:384:wlK5SIcZ2VDjkh1QCXMoiJaxbVe1i5qNiO3ixnQp9ul:SkGg4SCZlVd5q8Oy+9ul
            MD5:7CF107A017D320D8AA4FDED7DFCFEAFD
            SHA1:F21FB49B034CA545AFF079EBB21F4A0F7B637919
            SHA-256:483EEA05F43092A5813DB579A24B8B9F450D2EB67E19E68F1DDC5CBBEC261D08
            SHA-512:F5AEA75C91825C12AA2E259684D0EDA4217607EF76AFA653139B05C46D16DC7D15D13CA0D25DBEB5425B9A205E2B41701B06FC0229DFF4AD43286CFC52271779
            Malicious:false
            Reputation:low
            URL:https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj
            Preview: username.html--><!DOCTYPE html><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Welcome To Zscaler Directory Authentication</title><style type="text/css">body { background-color: #FFF; font-family: Arial, sans-serif; font-size: 12px; text-align: center; color: #4B4F54; overflow: hidden; margin: 0;}a { color: #009dd0; cursor: pointer; text-decoration: none;}form { width: 100%; height: 100%; margin: 0; padding: 0;}input { font-family: Arial; font-size: 100%; margin: 0; width: 100%; vertical-align: top; color: #424242; display: inline-block; border: none; padding: 0; text-align: left; height: 100%; width: calc(100% -35px);}table { margin-top: 10px; text-align: center; background-color: white;}table.table-company-logo { background-color: #e3e3e3;}table.table-upper { border-radius: 10px;}tab
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Jul 2, 2024 02:59:14.552865028 CEST49678443192.168.2.4104.46.162.224
            Jul 2, 2024 02:59:15.615243912 CEST49675443192.168.2.4173.222.162.32
            Jul 2, 2024 02:59:24.575839996 CEST4973580192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:24.576184034 CEST4973680192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:24.580585003 CEST8049735165.225.115.136192.168.2.4
            Jul 2, 2024 02:59:24.580641031 CEST4973580192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:24.580867052 CEST8049736165.225.115.136192.168.2.4
            Jul 2, 2024 02:59:24.580914974 CEST4973680192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:24.587721109 CEST4973580192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:24.592437983 CEST8049735165.225.115.136192.168.2.4
            Jul 2, 2024 02:59:25.223664045 CEST49675443192.168.2.4173.222.162.32
            Jul 2, 2024 02:59:25.494612932 CEST8049735165.225.115.136192.168.2.4
            Jul 2, 2024 02:59:25.516587019 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:25.516618967 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:25.516674042 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:25.516860962 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:25.516876936 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:25.535559893 CEST4973580192.168.2.4165.225.115.136
            Jul 2, 2024 02:59:26.375530958 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.376161098 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.376184940 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.377856970 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.377917051 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.380702019 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.380793095 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.381273031 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.381283998 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.428683043 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.726058006 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:26.730473995 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:26.772505045 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012826920 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012852907 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012907028 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.012912035 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012942076 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.012944937 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012969017 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.012970924 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.012981892 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.013583899 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.013668060 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.013679981 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.013729095 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.420557022 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:27.420593023 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:27.420665026 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:27.420824051 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:27.420835972 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:27.689258099 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.689282894 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880063057 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880095005 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880132914 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.880152941 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880176067 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.880187988 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880199909 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.880224943 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.880255938 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880395889 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:27.880444050 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.904864073 CEST49737443192.168.2.4165.225.72.46
            Jul 2, 2024 02:59:27.904877901 CEST44349737165.225.72.46192.168.2.4
            Jul 2, 2024 02:59:28.153436899 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:28.158874035 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:28.158893108 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:28.159769058 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:28.159826040 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:28.163980007 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:28.164032936 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:28.207360983 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:28.207367897 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:28.216082096 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:28.216108084 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:28.216181040 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:28.218352079 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:28.218367100 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:28.254280090 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:28.876936913 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:28.877017975 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:28.886503935 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:28.886518002 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:28.886909962 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:28.942342043 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.090140104 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.132503033 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:29.277539968 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:29.277821064 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:29.277887106 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.322406054 CEST49742443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.322424889 CEST44349742184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:29.413207054 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.413237095 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:29.413388014 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.414252043 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:29.414267063 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.090714931 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.090789080 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.091967106 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.091974974 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.092458963 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.093338013 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.136544943 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.375843048 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.375993013 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.376045942 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.376688004 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.376698971 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:30.376707077 CEST49743443192.168.2.4184.28.90.27
            Jul 2, 2024 02:59:30.376712084 CEST44349743184.28.90.27192.168.2.4
            Jul 2, 2024 02:59:38.012204885 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:38.012262106 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 02:59:38.012317896 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:39.694014072 CEST49740443192.168.2.4172.217.16.196
            Jul 2, 2024 02:59:39.694030046 CEST44349740172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:04.669383049 CEST6069253192.168.2.41.1.1.1
            Jul 2, 2024 03:00:04.674485922 CEST53606921.1.1.1192.168.2.4
            Jul 2, 2024 03:00:04.674571991 CEST6069253192.168.2.41.1.1.1
            Jul 2, 2024 03:00:04.674604893 CEST6069253192.168.2.41.1.1.1
            Jul 2, 2024 03:00:04.679388046 CEST53606921.1.1.1192.168.2.4
            Jul 2, 2024 03:00:05.143789053 CEST53606921.1.1.1192.168.2.4
            Jul 2, 2024 03:00:05.144593000 CEST6069253192.168.2.41.1.1.1
            Jul 2, 2024 03:00:05.149689913 CEST53606921.1.1.1192.168.2.4
            Jul 2, 2024 03:00:05.149740934 CEST6069253192.168.2.41.1.1.1
            Jul 2, 2024 03:00:09.583535910 CEST4973680192.168.2.4165.225.115.136
            Jul 2, 2024 03:00:09.588311911 CEST8049736165.225.115.136192.168.2.4
            Jul 2, 2024 03:00:10.505433083 CEST4973580192.168.2.4165.225.115.136
            Jul 2, 2024 03:00:10.510266066 CEST8049735165.225.115.136192.168.2.4
            Jul 2, 2024 03:00:25.696353912 CEST4973680192.168.2.4165.225.115.136
            Jul 2, 2024 03:00:25.703970909 CEST8049736165.225.115.136192.168.2.4
            Jul 2, 2024 03:00:25.704041958 CEST4973680192.168.2.4165.225.115.136
            Jul 2, 2024 03:00:27.811887980 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:27.811916113 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:27.811984062 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:27.812318087 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:27.812333107 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:28.590361118 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:28.590733051 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:28.590747118 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:28.591203928 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:28.591897964 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:28.591978073 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:28.646070004 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:33.490466118 CEST4972380192.168.2.4199.232.214.172
            Jul 2, 2024 03:00:33.490864038 CEST4972480192.168.2.4199.232.214.172
            Jul 2, 2024 03:00:33.495786905 CEST8049723199.232.214.172192.168.2.4
            Jul 2, 2024 03:00:33.495846987 CEST4972380192.168.2.4199.232.214.172
            Jul 2, 2024 03:00:33.496202946 CEST8049724199.232.214.172192.168.2.4
            Jul 2, 2024 03:00:33.496264935 CEST4972480192.168.2.4199.232.214.172
            Jul 2, 2024 03:00:38.391036034 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:38.391192913 CEST44360696172.217.16.196192.168.2.4
            Jul 2, 2024 03:00:38.391287088 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:39.700249910 CEST60696443192.168.2.4172.217.16.196
            Jul 2, 2024 03:00:39.700280905 CEST44360696172.217.16.196192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Jul 2, 2024 02:59:23.446532965 CEST53552881.1.1.1192.168.2.4
            Jul 2, 2024 02:59:23.454725027 CEST53633641.1.1.1192.168.2.4
            Jul 2, 2024 02:59:24.453130960 CEST53599341.1.1.1192.168.2.4
            Jul 2, 2024 02:59:25.499316931 CEST6283853192.168.2.41.1.1.1
            Jul 2, 2024 02:59:25.499444962 CEST5933553192.168.2.41.1.1.1
            Jul 2, 2024 02:59:25.506684065 CEST53628381.1.1.1192.168.2.4
            Jul 2, 2024 02:59:25.513642073 CEST53593351.1.1.1192.168.2.4
            Jul 2, 2024 02:59:27.411417007 CEST6520253192.168.2.41.1.1.1
            Jul 2, 2024 02:59:27.411673069 CEST6257053192.168.2.41.1.1.1
            Jul 2, 2024 02:59:27.417829990 CEST53652021.1.1.1192.168.2.4
            Jul 2, 2024 02:59:27.418227911 CEST53625701.1.1.1192.168.2.4
            Jul 2, 2024 02:59:27.695663929 CEST53548691.1.1.1192.168.2.4
            Jul 2, 2024 02:59:41.497402906 CEST53523821.1.1.1192.168.2.4
            Jul 2, 2024 02:59:45.074882030 CEST138138192.168.2.4192.168.2.255
            Jul 2, 2024 03:00:00.551398993 CEST53579521.1.1.1192.168.2.4
            Jul 2, 2024 03:00:04.669028997 CEST53621271.1.1.1192.168.2.4
            Jul 2, 2024 03:00:22.812256098 CEST53625311.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jul 2, 2024 02:59:25.499316931 CEST192.168.2.41.1.1.10xf202Standard query (0)gateway.zscloud.netA (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:25.499444962 CEST192.168.2.41.1.1.10xff12Standard query (0)gateway.zscloud.net65IN (0x0001)false
            Jul 2, 2024 02:59:27.411417007 CEST192.168.2.41.1.1.10xb935Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:27.411673069 CEST192.168.2.41.1.1.10x32e0Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jul 2, 2024 02:59:25.506684065 CEST1.1.1.1192.168.2.40xf202No error (0)gateway.zscloud.net165.225.72.46A (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:27.417829990 CEST1.1.1.1192.168.2.40xb935No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:27.418227911 CEST1.1.1.1192.168.2.40x32e0No error (0)www.google.com65IN (0x0001)false
            Jul 2, 2024 02:59:39.086437941 CEST1.1.1.1192.168.2.40x8a39No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:39.086437941 CEST1.1.1.1192.168.2.40x8a39No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:39.582370996 CEST1.1.1.1192.168.2.40xccbfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 2, 2024 02:59:39.582370996 CEST1.1.1.1192.168.2.40xccbfNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Jul 2, 2024 02:59:52.520539045 CEST1.1.1.1192.168.2.40xb8f4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 2, 2024 02:59:52.520539045 CEST1.1.1.1192.168.2.40xb8f4No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Jul 2, 2024 03:00:47.997090101 CEST1.1.1.1192.168.2.40x8e99No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 2, 2024 03:00:47.997090101 CEST1.1.1.1192.168.2.40x8e99No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • gateway.zscloud.net
            • https:
            • fs.microsoft.com
            • 165.225.115.136
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735165.225.115.136801696C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Jul 2, 2024 02:59:24.587721109 CEST430OUTGET / HTTP/1.1
            Host: 165.225.115.136
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Jul 2, 2024 02:59:25.494612932 CEST362INHTTP/1.1 307 Temporary Redirect
            Content-Length: 0
            Access-Control-Allow-Origin: *
            Location: https://gateway.zscloud.net:443/auD?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj
            Content-Type: text/html
            P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
            Set-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=165.225.115.136
            Jul 2, 2024 03:00:10.505433083 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736165.225.115.136801696C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Jul 2, 2024 03:00:09.583535910 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449737165.225.72.464431696C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-07-02 00:59:26 UTC746OUTGET /auD?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj HTTP/1.1
            Host: gateway.zscloud.net
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-07-02 00:59:26 UTC377INHTTP/1.1 307 Temporary Redirect
            Content-Length: 0
            Access-Control-Allow-Origin: *
            Location: https://gateway.zscloud.net:443/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj
            Content-Type: text/html
            Set-Cookie: _sm_au_d=1;path=/;domain=.zscloud.net;SameSite=None;Secure;HttpOnly;
            P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
            2024-07-02 00:59:26 UTC766OUTGET /auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj HTTP/1.1
            Host: gateway.zscloud.net
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: _sm_au_d=1
            2024-07-02 00:59:27 UTC15360INHTTP/1.1 200 OK
            Content-Type: text/html
            Server: Zscaler/6.2
            Cache-Control: no-cache
            P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
            Content-length: 22035
            Set-Cookie: _sm__fch=S053fkZSrQNR7
            ... username.html--><!DOCTYPE html><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Welcome To Zscaler Directory Authentication</title><style type="text/css">body { background-color: #FFF; font-family: Arial, sans-serif; font-size: 12px; text-align: center; color: #4B4F54; overflow: hidden; margin: 0;}a { color: #009dd0; cursor: pointer; text-decoration: none;}form { width: 100%; height: 100%; margin: 0; padding: 0;}input { font-family: Arial; font-size: 100%; margin: 0; width: 100%; vertical-align: top; color: #424242; display: inline-block; border: none; padding: 0; text-align: left; height: 100%; width: calc(100% -35px);}table { margin-top: 10px; text-align: center; background-color: white;}table.table-company-logo { background-color: #e3e3e3;}table.table-upper { border-radius: 10px;}table.table-lower { bord [TRUNCATED]
            2024-07-02 00:59:27 UTC6885INData Raw: 20 31 30 30 25 3b 64 69 73 70 6c 61 79 3a 20 62 6c 6f 63 6b 3b 7d 2e 74 61 62 6c 65 2d 6c 65 66 74 2d 63 6f 6c 75 6d 6e 20 74 61 62 6c 65 2c 20 2e 74 61 62 6c 65 2d 72 69 67 68 74 2d 63 6f 6c 75 6d 6e 20 74 61 62 6c 65 20 7b 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 30 3b 70 61 64 64 69 6e 67 2d 72 69 67 68 74 3a 20 30 3b 7d 2e 61 72 72 6f 77 2d 62 6f 78 20 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 20 77 68 69 74 65 3b 62 6f 72 64 65 72 3a 20 31 70 78 20 73 6f 6c 69 64 20 23 63 32 61 32 30 30 3b 77 69 64 74 68 3a 20 39 35 25 3b 7a 2d 69 6e 64 65 78 3a 20 31 30 30 3b 7d 2e 61 72 72 6f 77 2d 62 6f 78 2d 72 69 67 68 74 20 7b 74 6f 70 3a 20 2d 31 34 30 70 78 3b 6c 65 66 74 3a 20 2d 31 70 78 3b 7d 2e 61 72 72 6f 77 2d 62 6f 78 2d 6c 65 66 74 20 7b 74 6f 70 3a 20 2d
            Data Ascii: 100%;display: block;}.table-left-column table, .table-right-column table {padding-left: 0;padding-right: 0;}.arrow-box {background: white;border: 1px solid #c2a200;width: 95%;z-index: 100;}.arrow-box-right {top: -140px;left: -1px;}.arrow-box-left {top: -
            2024-07-02 00:59:27 UTC698OUTGET /favicon.ico HTTP/1.1
            Host: gateway.zscloud.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://gateway.zscloud.net/auT?origurl=http%3A%2F%2F165%2e225%2e115%2e136%2f&_ordtok=Z2k3WVZsk4ZBPkZTV5kkknFMWj
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: _sm_au_d=1
            2024-07-02 00:59:27 UTC13831INHTTP/1.1 403 Forbidden
            Content-Type: text/html
            Server: Zscaler/6.2
            Cache-Control: no-cache
            Access-Control-Allow-Origin: *
            Content-length: 13679
            ...# bq6ZFW7rpStTMbq6ZFW7rpStTMbq6ZFW7rpStTMd-->
            <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd">
            <html>
            <head>
            <meta name="description" content="Zscaler makes the internet safe for businesses by protecting their employees from malware, viruses, and other security threats.">
            <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
            <meta name="viewport" content="width=device-width, initial-scale=1">
            <title>Internet Security by Zscaler</title>
            <script language="JavaScript">var defLang = 'en_US'</script>
            ...<img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png">-->
            <style type="text/css">
            body {
            background-color:#e3e3e3;
            font-family:Arial, sans-serif;
            font-size:12px;
            color:#4B4F54;
            }
            a {
            cursor:pointer;
            text-decoration:none;
            color:#009dd0;
            }
            table {
            margin-top:10px;
            }
            td table {
            margin-top:0;
            text-align:center;
            }
            img {
            max-height:75px;
            max-width:430px;
            }
            .pg {
            position:absolute;
            top:0;
            bottom:0;
            left:0;
            right:0;
            overflow-x:hidden;
            white-space:nowrap;
            }
            .pg:before {
            content:"";
            display:inline-block;
            height:100%;
            vertical-align:middle;
            }
            .pg_cont {
            display:inline-block;
            vertical-align:middle;
            width:100%;
            position:relative;
            }
            .a_i {
            width:19px;
            height:19px;
            margin-right:10px;
            background-size: 19px 19px;
            display:inline-block;
            }
            .m_tbl {
            width:100%;
            max-width:758px;
            background:#e3e3e3;
            min-width:600px;
            }
            .pg.red .eu_h {
            color:#fd4239;
            border-top:3px solid #fd4239;
            }
            .pg.red .eu_h .a_i {
            background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAABoElEQVR4nK3Uz2vIYRzA8dcMzWGJdjSZKZLCDphfB7XVHBAXF2XFpJxd+BvUbtY20m4KxVExtbWkUYQLByU3OVhpy8zh+Tzr2dN3t30un1/P834+z/N8noc1lBZYPNVbx3twDQPYFuN+4RUm8ARL5YTWFzPWVZA2jGIWQ+jMC2ILzuERZrCjrmB9YW/CcxwLfwFTAf6J3TiPzTiMNziJz02wkQL0DpfwsVp8OCAb0IFnOIA5LG/zeEwWgN4GUBeeBihLN25mJ8NuhF7CIOYbQJPYHv59fAv7OlpL2OnQH2IbpexsAF3BePgdOFTC2kO/bQC9LED3AvTPymPoYuUFkHqprqizAF0NECwWY9vKynJi1yqg8QoEBwv7ewmbCt2HIw2goQrUgv6wF6QmXoY9KMqdLkBjDSDSueU3+Bi/S9gE3oedY2PS+6xBF3En7Hnczol8AX9xAa+xNWJHpXOajXwPzuBsAR7E1xoGX3BC6vJu7MVdzfIHl/GwDNa/xifsxy1xQ5XMSS2ypwax+n+Wc/ukr2YjfkhNXT81pP9sTeU/6YpejkX0NUMAAAAASUVORK5CYII=');
            }
            .pg.red .eu_h, .pg.red .eu_co, .pg.red .hr {
            border-left:3px solid #fd4239;
            border-right:3px solid #fd4239;
            }
            .pg.red .fo {
            border-bottom-color:#fd4239;
            }
            .pg.red .eu_co.st{
            border:0;
            }
            .pg.yl .eu_h .a_i {
            background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGQAAABkCAYAAABw4pVUAAAFgUlEQVR4nO2dOWxcVRSGP0+wWWKSiC1WMAV7SAI0bBLBLBI0bEUSyiSAFCOgYLMpEBA3JCEUCISQEBIIKtIgpaCho6KhAglkCQlRRBAhKBIQW4Di5iHH+M28c+85955h7leO5y6eb972v/PuQKVSqQwNY5+8V3oKYi4C3gXuaPn7x8Bu4Eim+agxsxN6pSch5GrgM9plANx58j0bs8xImWESsho4BJzf4b1TwAfAGaYzMmCYhDyH7Ft/DTBvNBczhkXINPBkRLs54ALluZgyLEIWiNv9TAIvKM/FlGEQsoVw1hTLLHCFzlTsGQYh+0mb52nAS0pzMce7kNuBuxX62QbcpNCPOZ6F9ICXFfs7CIwp9meCZyE7gOsU+9sK3KfYnwlehUxgs9/fTzimuMWrkEeASwz63Qg8ZNCvGh6FrMX22mGBEMO4xKOQZ4FzDfufAp4y7D8Jb0KmgScyjDOP00jFm5AF4MwM47iNVDwJSY1IpLiMVDwJSY1IpLiMVLwIuQ2diESKu0jFgxDtiESKq0jFg5AdwPUFx3cVqZQWYhWRSHETqZQWYhWRSHETqZQUshZ4vuD4y3ERqZQUMg+cV3D85biIVEoJuZC4KhJrikcqpQ5kMRHJMeCosM16QkzSlSZSeVw4jholhGwGHhS2eR14Bvhd2O504BVkH/As8BqwKBxLhRK7LGlEcoI4GQC/AU8DfwvaFI1Ucgu5Fbgnol2MjIYTyK/Ei0UqOYWMEWIKKauA8YRxY+P8IpFKTiEpEclZCePGXltsBe5NGDeKXEJSI5KUm1YpMg+Q+cQnl5BZ4NKE9ikfakrb7JFKDiFrSL9dWkoIZI5UcgjRiEhK7bIgc6RiLWQDOv9MyS0EMkYq1kK0qkhKbiGQsUrFUshm9A6IJU57l5OlSsVSiGYVSektBDJFKlZCYiO [TRUNCATED]
            }
            .pg.yl .eu_h {
            color:#c2a200;
            border-top:3px solid #c2a200;
            }
            .pg.yl .eu_h, .pg.yl .eu_co, .pg.yl .hr {
            border-left:3px solid #c2a200;
            border-right:3px solid #c2a200;
            }
            .pg.yl .fo {
            border-bottom-color:#c2a200;
            }
            .pg.yl .eu_co.st{
            border:0;
            }
            .pg.or .eu_h {
            color:#e39e00;
            border-top:3px solid #e39e00;
            }
            .pg.or .eu_h .a_i {
            background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAASCAYAAAC5DOVpAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyhpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuNi1jMTExIDc5LjE1ODMyNSwgMjAxNS8wOS8xMC0wMToxMDoyMCAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvIiB4bWxuczp4bXBNTT0iaHR0cDovL25zLmFkb2JlLmNvbS94YXAvMS4wL21tLyIgeG1sbnM6c3RSZWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9zVHlwZS9SZXNvdXJjZVJlZiMiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENDIDIwMTUgKE1hY2ludG9zaCkiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6QjIzMTRDODNCQ0ExMTFFNUFBNTY5RTA4NDFEMEU0QTAiIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6QjIzMTRDODRCQ0ExMTFFNUFBNTY5RTA4NDFEMEU0QTAiPiA8eG1wTU06RGVyaXZlZEZyb20gc3RSZWY6aW5zdGFuY2VJRD0ieG1wLmlpZDpCMjMxNEM [TRUNCATED]
            }
            .pg.or .eu_h, .pg.or .eu_co, .pg.or .hr {
            border-left:3px solid #e39e00;
            border-right:3px solid #e39e00;
            }
            .pg.or .fo {
            border-bottom-color:#e39e00;
            }
            .pg.or .eu_co.st{
            border:0;
            }
            .m_tbl table td {
            padding:0 20px 16px 20px;
            text-align:left;
            background-color:white;
            }
            .m_tbl table td.bh {
            text-align:center;
            background-color:#e3e3e3;
            z-index:100;
            }
            .m_tbl table td.eu_h {
            padding-top: 20px;
            }
            .eu_h {
            vertical-align:middle;
            font-weight:normal;
            white-space:normal;
            font-size: 24px;
            background-color:white;
            border-left:3px solid;
            border-right:3px solid;
            border-top-left-radius: 10px;
            border-top-right-radius: 10px;
            }
            .pg .eu_h.sm {
            font-size:16px;
            color:#929496;
            border-top-left-radius:0;
            border-top-right-radius:0;
            border-top:0;
            padding-top:0;
            }
            hr {
            margin:0;
            border-top:0.5px solid #cfd0d1;
            }
            .eu_co {
            font-size:16px;
            color:#2a2c30;
            border-left:3px solid;
            border-right:3px solid;
            white-space: normal;
            word-wrap: break-word;
            }
            .eu_co.rsn{
            color:#000000;
            }
            .eu_l {
            display:inline;
            padding-left:5px;
            }
            .bh {
            min-height:35px;
            display:block;
            max-height:75px;
            color:#0076A9;
            font-size:16px;
            overflow:hidden;
            padding-bottom:15px;
            padding-top:5px;
            background-color:#e3e3e3;
            text-align:center;
            max-width:758px;
            text-overflow: ellipsis;
            }
            .btn {
            background:#009dd0;
            color:#FFFFFF;
            border-radius:5px;
            border:2px solid #009dd0;
            cursor:pointer;
            display:inline-block;
            height:30px;
            margin:10px 0 15px;
            font-size:18px;
            line-height:26px;
            width:auto;
            padding:0 20px;
            }
            .btn:focus {
            outline:none;
            }
            .btn:hover {
            background:#fff;
            color:#0076A9;
            }
            .eu_co.fo {
            height:32px;
            color:#696A6D;
            background-color:#f3f3f3;
            line-height:32px;
            font-size:11px;
            padding-bottom:0px;
            border-bottom:3px solid;
            border-bottom-left-radius:10px;
            border-bottom-right-radius:10px;
            }
            .eu_co.fo.pb35 {
            background-color: white;
            color: #2a2c30;
            font-size: 16px;
            padding-bottom: 20px;
            }
            .eu_co.st {
            font-size: 12px;
            padding: 10px 0;
            line-height: 20px;
            position: relative;
            color: #939393;
            background:#e3e3e3;
            border:0;
            text-align: center;
            }
            .s_img {
            vertical-align:top;
            padding-right:5px;
            background:url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADoAAAAMCAYAAAAzmK6YAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyhpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuNi1jMTExIDc5LjE1ODMyNSwgMjAxNS8wOS8xMC0wMToxMDoyMCAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvIiB4bWxuczp4bXBNTT0iaHR0cDovL25zLmFkb2JlLmNvbS94YXAvMS4wL21tLyIgeG1sbnM6c3RSZWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9zVHlwZS9SZXNvdXJjZVJlZiMiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENDIDIwMTUgKE1hY2ludG9zaCkiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6MDg4M0FBNkZBODFFMTFFNUI3RkJGMDcxMjM1MjFGQjUiIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6MDg4M0FBNzBBODFFMTFFNUI3RkJGMDcxMjM1MjFGQjUiPiA8eG1wTU06RGVyaXZlZEZyb20gc3RSZWY6aW5zdGFuY2VJRD0ieG1wLmlpZDowODgzQUE2REE4MU [TRUNCATED]
            width:55px;
            height:17px;
            position:relative;
            top:3px;
            display:inline-block;
            }
            .f_btn {
            display:inline-block;
            }
            .uq_cd {
            position:absolute;
            bottom:54px;
            right:25px;
            font-size:10px;
            color:#696A6D;
            }
            .s_l td {
            font-size: 13px;
            color: #77797c;
            text-align:right;
            }
            .s_l a {
            padding:4px;
            cursor:pointer;
            font-size:13px;
            }
            .s_l .sprt {
            margin-left: 6px;
            margin-right: 4px;
            padding-right: 0;
            cursor: default;
            height: 14px;
            border-left: 1px #cfd0d1 solid;
            }
            .langSelector{
            width:200px;
            }
            .langSelector td{
            text-align:right;
            }
            .logo_container{
            position:relative;
            max-width:758px;
            margin:0px auto;
            }
            .err_cd {
            font-size:16px;
            color:#2a2c30;
            text-align: left;
            background-color:white;
            padding-bottom:16px;
            }
            @media only screen and (max-width:700px) {
            td.bh{
            padding-bottom:35px;
            }
            .eu_h{
            font-size:18px;
            }
            .eu_h,.eu_co,.st{
            word-wrap:break-word;
            white-space:normal;
            }
            .sm{
            font-size:14px;
            }
            .fo{
            padding:2px 0;
            height:20px;
            line-height:20px;
            }
            .m_tbl {
            min-width: 300px;
            width: 95%;
            position:relative;
            left:-3px;
            }
            .uq_cd {
            bottom: 77px;
            }
            .a_i {
            position: relative;
            top: 4px;
            }
            .s_l {
            position: absolute;
            top:85px;
            width:100%;
            z-index:100;
            }
            .s_l a {
            padding: 0;
            }
            .m_tbl table .s_l td {
            text-align: center;
            }
            .pg{
            overflow-y:auto;
            }
            .langSelector{
            width:100%;
            }
            .langSelector td{
            text-align:center;
            }
            }
            </style>
            </head>
            <body>
            <div class="pg red">
            <div class="pg_cont">
            <div id="logo_container" class="logo_container">
            <table id="logo" width="50%" cellspacing="0" cellpadding="0" border="0" align="center">
            <tbody>
            <tr align="center">
            <td align="center" class="bh">
            <img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png"></td></tr>
            </tbody></table></div>
            <table class="m_tbl" cellpadding="0" cellspacing="0" align="center">
            <tbody><tr>
            <td height="100" valign="top" style="position:relative;">
            <div class="uq_cd">D09</div>
            ...locale en_US-->
            <table id="en_US" width="100%" border="0" cellspacing="0" cellpadding="0">
            <tbody><tr><td class="eu_h">
            <i class="a_i"></i>
            Sorry, we couldn't load the page.
            </td></tr>
            <tr><td class="hr"><hr></td></tr>
            <tr><td class="eu_co rsn">
            </td></tr>
            <tr><td class="eu_co err_cd">
            Error Code: 081000
            </td></tr>
            <tr><td class="eu_co fo">
            </td></tr>
            <tr><td class="eu_co st red">
            <span class="s_img"></span>
            Your organization has selected Zscaler to protect you from internet threats.
            </td></tr>
            </tbody></table>
            .../locale en_US-->
            </td></tr>
            </tbody></table>
            </div>
            </div>
            </body></html>
            ... 0 0 0 0 1719881967 4 https://gateway.zscloud.net/favicon.ico -->


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449742184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-07-02 00:59:29 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-07-02 00:59:29 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=227375
            Date: Tue, 02 Jul 2024 00:59:29 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449743184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-07-02 00:59:30 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-07-02 00:59:30 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=227384
            Date: Tue, 02 Jul 2024 00:59:30 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-07-02 00:59:30 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:20:59:18
            Start date:01/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:1
            Start time:20:59:21
            Start date:01/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1856,i,4093924628700597556,1019391488178839724,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:20:59:23
            Start date:01/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://165.225.115.136"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly