Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://lodgesonvashon.us11.list-manage.com

Overview

General Information

Sample URL:https://lodgesonvashon.us11.list-manage.com
Analysis ID:1467259
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3844 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4296 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1996,i,6320455061481165711,4465343319517655028,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6516 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lodgesonvashon.us11.list-manage.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://mailchimp.com/about/mcsv-staticHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /about/mcsv-static HTTP/1.1Host: mailchimp.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mailchimp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mailchimp.com/about/mcsv-staticAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _abck=9B8C05219FF12A52C26F129C89D069D2~-1~YAAQrLEPF/K7E1SQAQAA29Z4egy77LFR0/lfM3tqRcxfrb8CiQmlxI257cfbQgtokVzwg06TUDvovLVOJbNDX8VztU4k+HPugdkFDScRMZpbdsrARBhR5mH7giUEmUJww81VbAYHX4C5MTqkUl9uOp41a4JlzmTsmMlpSu0tNZJQjkmuE8P4o3x+FZtmUJyorTDNBPzQGWKYnDDB1Xl0lnnX1rEJu27SpLq8xysra3IyafMUtrrDC5tfUEoUu1ry3DCfnG4nQqNd8gXcBFNSR59hQuWbSmPv8a5KIB1URlcoBC+yNSaKX5/T+AOM/fikBctp4deoPli19EhVD0f3OLdl0x8efKtn3CnN8HIlrDLlV4HEQlfLuf/r6M/1Cx4=~-1~-1~-1; bm_sz=E89BCAAF16F8E04A0E8560308FCDB31B~YAAQrLEPF/O7E1SQAQAA29Z4ehgdE19We3S1jhyVGywiJRMbDEuxAkzsR91Th5QeIsw/0A+EgiZdN+y1a1Cc6eAAV0xfM9l3LOMJi23iF8QAEqYAd75hOl4cR9dclTHH1o3PQOCK+z1rRzpEPUlYM2xAzcdeuUzFx4rhJzm2u4jso+11dqm3ORSNMG17xFQts+S5/3BxUIUdabdukCA8SW7W3iistzSQkoa5wQHMFKnjvXRQSB8OhxMLLJI+UTRfB6Q0+X2Uj7QxKt2eRk0ghZRzKUF2GlCIMJga9PZzhaHUySXCqnqUHrRHwEjqM0NF8Pnul2q8xhKR9GT1otRCTcHLq30043BhC6PAstn0DpF87YyYKg1c7SXXfECDBPQjhY13vBuL~4405559~3617093
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mailchimp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _abck=9B8C05219FF12A52C26F129C89D069D2~-1~YAAQrLEPF/K7E1SQAQAA29Z4egy77LFR0/lfM3tqRcxfrb8CiQmlxI257cfbQgtokVzwg06TUDvovLVOJbNDX8VztU4k+HPugdkFDScRMZpbdsrARBhR5mH7giUEmUJww81VbAYHX4C5MTqkUl9uOp41a4JlzmTsmMlpSu0tNZJQjkmuE8P4o3x+FZtmUJyorTDNBPzQGWKYnDDB1Xl0lnnX1rEJu27SpLq8xysra3IyafMUtrrDC5tfUEoUu1ry3DCfnG4nQqNd8gXcBFNSR59hQuWbSmPv8a5KIB1URlcoBC+yNSaKX5/T+AOM/fikBctp4deoPli19EhVD0f3OLdl0x8efKtn3CnN8HIlrDLlV4HEQlfLuf/r6M/1Cx4=~-1~-1~-1; bm_sz=E89BCAAF16F8E04A0E8560308FCDB31B~YAAQrLEPF/O7E1SQAQAA29Z4ehgdE19We3S1jhyVGywiJRMbDEuxAkzsR91Th5QeIsw/0A+EgiZdN+y1a1Cc6eAAV0xfM9l3LOMJi23iF8QAEqYAd75hOl4cR9dclTHH1o3PQOCK+z1rRzpEPUlYM2xAzcdeuUzFx4rhJzm2u4jso+11dqm3ORSNMG17xFQts+S5/3BxUIUdabdukCA8SW7W3iistzSQkoa5wQHMFKnjvXRQSB8OhxMLLJI+UTRfB6Q0+X2Uj7QxKt2eRk0ghZRzKUF2GlCIMJga9PZzhaHUySXCqnqUHrRHwEjqM0NF8Pnul2q8xhKR9GT1otRCTcHLq30043BhC6PAstn0DpF87YyYKg1c7SXXfECDBPQjhY13vBuL~4405559~3617093
Source: global trafficDNS traffic detected: DNS query: lodgesonvashon.us11.list-manage.com
Source: global trafficDNS traffic detected: DNS query: mailchimp.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@18/5@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1996,i,6320455061481165711,4465343319517655028,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lodgesonvashon.us11.list-manage.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1996,i,6320455061481165711,4465343319517655028,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lodgesonvashon.us11.list-manage.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://mailchimp.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
mailchimp.com
23.197.52.224
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      142.250.184.196
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          lodgesonvashon.us11.list-manage.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://mailchimp.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://mailchimp.com/about/mcsv-staticfalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.184.196
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              23.197.52.224
              mailchimp.comUnited States
              20940AKAMAI-ASN1EUfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1467259
              Start date and time:2024-07-03 23:20:05 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 57s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://lodgesonvashon.us11.list-manage.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@18/5@8/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.74.195, 142.250.110.84, 142.250.186.78, 34.104.35.123, 104.102.49.40, 13.85.23.86, 199.232.210.172, 192.229.221.95, 20.166.126.56, 142.250.181.227
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, e13829.x.akamaiedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, swc.list-manage.com.edgekey.net, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://lodgesonvashon.us11.list-manage.com
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
              Category:dropped
              Size (bytes):8348
              Entropy (8bit):3.0391873746902416
              Encrypted:false
              SSDEEP:48:e4Xvcmak0HMJRo1x2ITXOzbVoa2WwYSsdx4PRAVArrnfHDYu:e2gsJRoH3H/WwYjanrrfDY
              MD5:8969A0A66F67FB12242F39AD1AD79D1F
              SHA1:0A7E5013C3D971BC789A0F7EF61AB1DA57639071
              SHA-256:1E9840287DECB8799F6DA96F04ED4393A7380D5236F4DFC42947174550B25C92
              SHA-512:36D69C1F3FEFBC23E7A59278D511DC724E3BCA8D17F3AFEAB42AB1A6764D5D9AAF05A78D52BC429ABADDFBA78045D665B529779DEAF88D9F62C8A421072B092E
              Malicious:false
              Reputation:low
              Preview:...... .... .(...&......... .(...N...(... ...@..... ............................I...........................................................................................................................I.............................................................................................................................................................................................................................................................................................................................................................................................................................................................OZ..+2..........(...DN...................................................................................................!......................................................................................................................n~..........................[h......y...Ua..........`n.......................................................
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
              Category:downloaded
              Size (bytes):8348
              Entropy (8bit):3.0391873746902416
              Encrypted:false
              SSDEEP:48:e4Xvcmak0HMJRo1x2ITXOzbVoa2WwYSsdx4PRAVArrnfHDYu:e2gsJRoH3H/WwYjanrrfDY
              MD5:8969A0A66F67FB12242F39AD1AD79D1F
              SHA1:0A7E5013C3D971BC789A0F7EF61AB1DA57639071
              SHA-256:1E9840287DECB8799F6DA96F04ED4393A7380D5236F4DFC42947174550B25C92
              SHA-512:36D69C1F3FEFBC23E7A59278D511DC724E3BCA8D17F3AFEAB42AB1A6764D5D9AAF05A78D52BC429ABADDFBA78045D665B529779DEAF88D9F62C8A421072B092E
              Malicious:false
              Reputation:low
              URL:https://mailchimp.com/favicon.ico
              Preview:...... .... .(...&......... .(...N...(... ...@..... ............................I...........................................................................................................................I.............................................................................................................................................................................................................................................................................................................................................................................................................................................................OZ..+2..........(...DN...................................................................................................!......................................................................................................................n~..........................[h......y...Ua..........`n.......................................................
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:Unicode text, UTF-8 text, with very long lines (461)
              Category:downloaded
              Size (bytes):628
              Entropy (8bit):4.555380483012446
              Encrypted:false
              SSDEEP:12:qIKK5LD33M74SXthEGbtGJJ/nwP6nX7cSj2wCdCKvcp0rwTuv:qRK5LD33Y176nrcY2waPrKg
              MD5:2B26537FB34225C5347E9BE27B8BC327
              SHA1:0227DFFA3D3A7191591B0284FD5F419E23C18001
              SHA-256:8E8B54C1B72C125A9244C491D3596DFA097FCCFC1F07B8DBDF4646798D2F6088
              SHA-512:D2F452F72F113A10A9D0DE0DF5E94A2455EE5D929EB9E83AB1FEAA10D90B872B71B4F4F98738B13E1CB04EFB64DF6FD7FEA4A5B74668EF7A0B03240D0C69A13E
              Malicious:false
              Reputation:low
              URL:https://mailchimp.com/about/mcsv-static
              Preview: ____. / ___M ]__.C{ ( o o )}. { ... \___. ........You probably found this page because one of our subscribers used Mailchimp to send you an email campaign and you traced a link in the email back here to investigate. Mailchimp is a marketing platform that serves millions of companies of all shapes and sizes, from all over the world. We send more than 1 billion emails every day, and we help our customers comply with spam laws and best practices so they can get their campaigns into their subscribers' inboxes....|\/| _ .| _|_ . _ _.| |(_|||(_| )|||||_). |. Love What You Do.
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Jul 3, 2024 23:20:47.419147968 CEST49675443192.168.2.4173.222.162.32
              Jul 3, 2024 23:20:47.450411081 CEST49678443192.168.2.4104.46.162.224
              Jul 3, 2024 23:20:56.922353983 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:56.922378063 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:56.922435045 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:56.923051119 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:56.923063993 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.028450966 CEST49675443192.168.2.4173.222.162.32
              Jul 3, 2024 23:20:57.590426922 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.590658903 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:57.590671062 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.592082977 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.592166901 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:57.867749929 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:57.867888927 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.869987011 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:57.870003939 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:57.911990881 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:57.986772060 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:57.986798048 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:57.986861944 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:57.987704992 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:57.987719059 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.178102970 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:58.178205013 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:58.178280115 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:58.188810110 CEST49739443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:58.188822985 CEST4434973923.197.52.224192.168.2.4
              Jul 3, 2024 23:20:58.444396019 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:58.444418907 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:58.444483995 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:58.445349932 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:58.445363998 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:58.545372963 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:58.545392990 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:58.545474052 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:58.548419952 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:58.548434973 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:58.646766901 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.647042990 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:58.647053957 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.648014069 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.648094893 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:58.649229050 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:58.649292946 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.697329998 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:58.697336912 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:20:58.745635033 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:20:59.133403063 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.133831024 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.133848906 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.134224892 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.134752989 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.134830952 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.135093927 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.135107994 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.202708960 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.202780008 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.205033064 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.205041885 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.205269098 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.243604898 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.284507990 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.464158058 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.464190960 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.464257956 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.464272976 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.464329958 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.468663931 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.468700886 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.468763113 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.469522953 CEST49742443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.469541073 CEST443497422.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.500226021 CEST49741443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.500247002 CEST4434974123.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.604438066 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.604495049 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.604569912 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.605698109 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:20:59.605715990 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:20:59.663350105 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.663388014 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:20:59.663480043 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.665435076 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:20:59.665452003 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.248619080 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.248711109 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.280395031 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.280453920 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.280689955 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.283796072 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.316169024 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.317286015 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.317308903 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.318154097 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.318211079 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.325356007 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.325411081 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.326163054 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.326172113 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.328500986 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.373105049 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.520327091 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.520370007 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.520437002 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.521380901 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.521419048 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.521447897 CEST49743443192.168.2.42.18.97.153
              Jul 3, 2024 23:21:00.521465063 CEST443497432.18.97.153192.168.2.4
              Jul 3, 2024 23:21:00.607836962 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.607855082 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.607861996 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.607889891 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:00.607908010 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.607949972 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.608944893 CEST49744443192.168.2.423.197.52.224
              Jul 3, 2024 23:21:00.608963013 CEST4434974423.197.52.224192.168.2.4
              Jul 3, 2024 23:21:08.548428059 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:08.548497915 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:08.548557997 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:09.977174997 CEST49740443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:09.977202892 CEST44349740142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:58.352577925 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:58.352607012 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:58.353471994 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:58.354640007 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:58.354651928 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:59.018454075 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:59.019131899 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:59.019145012 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:59.019423962 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:59.020587921 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:21:59.020648003 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:21:59.074911118 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:22:06.387692928 CEST4972480192.168.2.493.184.221.240
              Jul 3, 2024 23:22:06.387697935 CEST4972380192.168.2.493.184.221.240
              Jul 3, 2024 23:22:06.396507978 CEST804972393.184.221.240192.168.2.4
              Jul 3, 2024 23:22:06.396600008 CEST4972380192.168.2.493.184.221.240
              Jul 3, 2024 23:22:06.396830082 CEST804972493.184.221.240192.168.2.4
              Jul 3, 2024 23:22:06.396981001 CEST4972480192.168.2.493.184.221.240
              Jul 3, 2024 23:22:08.927031040 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:22:08.927089930 CEST44349754142.250.184.196192.168.2.4
              Jul 3, 2024 23:22:08.927141905 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:22:09.952637911 CEST49754443192.168.2.4142.250.184.196
              Jul 3, 2024 23:22:09.952660084 CEST44349754142.250.184.196192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Jul 3, 2024 23:20:53.508519888 CEST53534911.1.1.1192.168.2.4
              Jul 3, 2024 23:20:53.509767056 CEST53652031.1.1.1192.168.2.4
              Jul 3, 2024 23:20:54.685648918 CEST53585901.1.1.1192.168.2.4
              Jul 3, 2024 23:20:55.438292027 CEST6148253192.168.2.41.1.1.1
              Jul 3, 2024 23:20:55.438469887 CEST5995953192.168.2.41.1.1.1
              Jul 3, 2024 23:20:56.909207106 CEST5333353192.168.2.41.1.1.1
              Jul 3, 2024 23:20:56.909460068 CEST5976853192.168.2.41.1.1.1
              Jul 3, 2024 23:20:56.916553020 CEST53533331.1.1.1192.168.2.4
              Jul 3, 2024 23:20:56.919969082 CEST53597681.1.1.1192.168.2.4
              Jul 3, 2024 23:20:57.962236881 CEST5454153192.168.2.41.1.1.1
              Jul 3, 2024 23:20:57.962472916 CEST5521753192.168.2.41.1.1.1
              Jul 3, 2024 23:20:57.968995094 CEST53545411.1.1.1192.168.2.4
              Jul 3, 2024 23:20:57.969326019 CEST53552171.1.1.1192.168.2.4
              Jul 3, 2024 23:20:59.628623962 CEST5147253192.168.2.41.1.1.1
              Jul 3, 2024 23:20:59.629026890 CEST5082653192.168.2.41.1.1.1
              Jul 3, 2024 23:20:59.637269020 CEST53514721.1.1.1192.168.2.4
              Jul 3, 2024 23:20:59.638528109 CEST53508261.1.1.1192.168.2.4
              Jul 3, 2024 23:21:11.790183067 CEST53626161.1.1.1192.168.2.4
              Jul 3, 2024 23:21:18.002732038 CEST138138192.168.2.4192.168.2.255
              Jul 3, 2024 23:21:30.786276102 CEST53583571.1.1.1192.168.2.4
              Jul 3, 2024 23:21:53.288048029 CEST53554841.1.1.1192.168.2.4
              Jul 3, 2024 23:21:53.663250923 CEST53535581.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jul 3, 2024 23:20:55.438292027 CEST192.168.2.41.1.1.10x9f15Standard query (0)lodgesonvashon.us11.list-manage.comA (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:55.438469887 CEST192.168.2.41.1.1.10xd6d5Standard query (0)lodgesonvashon.us11.list-manage.com65IN (0x0001)false
              Jul 3, 2024 23:20:56.909207106 CEST192.168.2.41.1.1.10x7b11Standard query (0)mailchimp.comA (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:56.909460068 CEST192.168.2.41.1.1.10x9c5aStandard query (0)mailchimp.com65IN (0x0001)false
              Jul 3, 2024 23:20:57.962236881 CEST192.168.2.41.1.1.10x798dStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:57.962472916 CEST192.168.2.41.1.1.10xb41eStandard query (0)www.google.com65IN (0x0001)false
              Jul 3, 2024 23:20:59.628623962 CEST192.168.2.41.1.1.10x5e11Standard query (0)mailchimp.comA (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:59.629026890 CEST192.168.2.41.1.1.10x7b48Standard query (0)mailchimp.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jul 3, 2024 23:20:55.450805902 CEST1.1.1.1192.168.2.40x9f15No error (0)lodgesonvashon.us11.list-manage.comswc.list-manage.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:20:55.450829029 CEST1.1.1.1192.168.2.40xd6d5No error (0)lodgesonvashon.us11.list-manage.comswc.list-manage.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:20:56.916553020 CEST1.1.1.1192.168.2.40x7b11No error (0)mailchimp.com23.197.52.224A (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:57.968995094 CEST1.1.1.1192.168.2.40x798dNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
              Jul 3, 2024 23:20:57.969326019 CEST1.1.1.1192.168.2.40xb41eNo error (0)www.google.com65IN (0x0001)false
              Jul 3, 2024 23:20:59.637269020 CEST1.1.1.1192.168.2.40x5e11No error (0)mailchimp.com23.197.52.224A (IP address)IN (0x0001)false
              Jul 3, 2024 23:21:10.091778994 CEST1.1.1.1192.168.2.40xd7No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Jul 3, 2024 23:21:10.091778994 CEST1.1.1.1192.168.2.40xd7No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Jul 3, 2024 23:21:10.622416973 CEST1.1.1.1192.168.2.40xd21eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:21:10.622416973 CEST1.1.1.1192.168.2.40xd21eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Jul 3, 2024 23:21:23.571543932 CEST1.1.1.1192.168.2.40xb3b7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:21:23.571543932 CEST1.1.1.1192.168.2.40xb3b7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Jul 3, 2024 23:21:45.926076889 CEST1.1.1.1192.168.2.40x1102No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:21:45.926076889 CEST1.1.1.1192.168.2.40x1102No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Jul 3, 2024 23:22:06.401721001 CEST1.1.1.1192.168.2.40x2b70No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jul 3, 2024 23:22:06.401721001 CEST1.1.1.1192.168.2.40x2b70No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • mailchimp.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973923.197.52.2244434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-03 21:20:57 UTC673OUTGET /about/mcsv-static HTTP/1.1
              Host: mailchimp.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-03 21:20:58 UTC1627INHTTP/1.1 200 OK
              Last-Modified: Wed, 08 Mar 2023 17:36:17 GMT
              ETag: "274-5f666f72ac892"
              X-Frame-Options: SAMEORIGIN
              Cache-Control: max-age=29635715
              Expires: Wed, 11 Jun 2025 21:29:33 GMT
              Date: Wed, 03 Jul 2024 21:20:58 GMT
              Content-Length: 628
              Connection: close
              Server-Timing: cdn-cache; desc=HIT
              Server-Timing: edge; dur=95
              Server-Timing: origin; dur=0
              Content-Type: text/plain; charset=utf-8
              Set-Cookie: _abck=9B8C05219FF12A52C26F129C89D069D2~-1~YAAQrLEPF/K7E1SQAQAA29Z4egy77LFR0/lfM3tqRcxfrb8CiQmlxI257cfbQgtokVzwg06TUDvovLVOJbNDX8VztU4k+HPugdkFDScRMZpbdsrARBhR5mH7giUEmUJww81VbAYHX4C5MTqkUl9uOp41a4JlzmTsmMlpSu0tNZJQjkmuE8P4o3x+FZtmUJyorTDNBPzQGWKYnDDB1Xl0lnnX1rEJu27SpLq8xysra3IyafMUtrrDC5tfUEoUu1ry3DCfnG4nQqNd8gXcBFNSR59hQuWbSmPv8a5KIB1URlcoBC+yNSaKX5/T+AOM/fikBctp4deoPli19EhVD0f3OLdl0x8efKtn3CnN8HIlrDLlV4HEQlfLuf/r6M/1Cx4=~-1~-1~-1; Domain=.mailchimp.com; Path=/; Expires=Thu, 03 Jul 2025 21:20:58 GMT; Max-Age=31536000; SameSite=None; Secure
              Set-Cookie: bm_sz=E89BCAAF16F8E04A0E8560308FCDB31B~YAAQrLEPF/O7E1SQAQAA29Z4ehgdE19We3S1jhyVGywiJRMbDEuxAkzsR91Th5QeIsw/0A+EgiZdN+y1a1Cc6eAAV0xfM9l3LOMJi23iF8QAEqYAd75hOl4cR9dclTHH1o3PQOCK+z1rRzpEPUlYM2xAzcdeuUzFx4rhJzm2u4jso+11dqm3ORSNMG17xFQts+S5/3BxUIUdabdukCA8SW7W3iistzSQkoa5wQHMFKnjvXRQSB8OhxMLLJI+UTRfB6Q0+X2Uj7QxKt2eRk0ghZRzKUF2GlCIMJga9PZzhaHUySXCqnqUHrRHwEjqM0NF8Pnul2q8xhKR9GT1otRCTcHLq30043BhC6PAstn0DpF87YyYKg1c7SXXfECDBPQjhY13vBuL~4405559~3617093; Domain=.mailchimp.com; Path=/; Expires=Thu, 04 Jul 2024 01:20:57 GMT; Max-Age=14399; SameSite=None; Secure
              Server-Timing: ak_p; desc="1720041657490_386904492_429145152_10379_14668_156_188_-";dur=1
              2024-07-03 21:20:58 UTC628INData Raw: 20 20 20 20 5f 5f 5f 5f 0a 20 20 2f 20 5f 5f 5f 4d 20 5d 5f 5f 0a 43 7b 20 28 20 6f 20 6f 20 29 7d 0a 20 20 20 20 7b 20 20 20 e2 80 a2 e2 80 a2 0a 20 20 20 20 20 5c 5f 5f 5f 0a 20 20 20 20 20 e2 80 93 e2 80 93 e2 80 93 e2 80 93 c2 b4 0a 0a 0a 59 6f 75 20 70 72 6f 62 61 62 6c 79 20 66 6f 75 6e 64 20 74 68 69 73 20 70 61 67 65 20 62 65 63 61 75 73 65 20 6f 6e 65 20 6f 66 20 6f 75 72 20 73 75 62 73 63 72 69 62 65 72 73 20 75 73 65 64 20 4d 61 69 6c 63 68 69 6d 70 20 74 6f 20 73 65 6e 64 20 79 6f 75 20 61 6e 20 65 6d 61 69 6c 20 63 61 6d 70 61 69 67 6e 20 61 6e 64 20 79 6f 75 20 74 72 61 63 65 64 20 61 20 6c 69 6e 6b 20 69 6e 20 74 68 65 20 65 6d 61 69 6c 20 62 61 63 6b 20 68 65 72 65 20 74 6f 20 69 6e 76 65 73 74 69 67 61 74 65 2e 20 4d 61 69 6c 63 68 69 6d
              Data Ascii: ____ / ___M ]__C{ ( o o )} { \___ You probably found this page because one of our subscribers used Mailchimp to send you an email campaign and you traced a link in the email back here to investigate. Mailchim


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44974123.197.52.2244434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-03 21:20:59 UTC1493OUTGET /favicon.ico HTTP/1.1
              Host: mailchimp.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://mailchimp.com/about/mcsv-static
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: _abck=9B8C05219FF12A52C26F129C89D069D2~-1~YAAQrLEPF/K7E1SQAQAA29Z4egy77LFR0/lfM3tqRcxfrb8CiQmlxI257cfbQgtokVzwg06TUDvovLVOJbNDX8VztU4k+HPugdkFDScRMZpbdsrARBhR5mH7giUEmUJww81VbAYHX4C5MTqkUl9uOp41a4JlzmTsmMlpSu0tNZJQjkmuE8P4o3x+FZtmUJyorTDNBPzQGWKYnDDB1Xl0lnnX1rEJu27SpLq8xysra3IyafMUtrrDC5tfUEoUu1ry3DCfnG4nQqNd8gXcBFNSR59hQuWbSmPv8a5KIB1URlcoBC+yNSaKX5/T+AOM/fikBctp4deoPli19EhVD0f3OLdl0x8efKtn3CnN8HIlrDLlV4HEQlfLuf/r6M/1Cx4=~-1~-1~-1; bm_sz=E89BCAAF16F8E04A0E8560308FCDB31B~YAAQrLEPF/O7E1SQAQAA29Z4ehgdE19We3S1jhyVGywiJRMbDEuxAkzsR91Th5QeIsw/0A+EgiZdN+y1a1Cc6eAAV0xfM9l3LOMJi23iF8QAEqYAd75hOl4cR9dclTHH1o3PQOCK+z1rRzpEPUlYM2xAzcdeuUzFx4rhJzm2u4jso+11dqm3ORSNMG17xFQts+S5/3BxUIUdabdukCA8SW7W3iistzSQkoa5wQHMFKnjvXRQSB8OhxMLLJI+UTRfB6Q0+X2Uj7QxKt2eRk0ghZRzKUF2GlCIMJga9PZzhaHUySXCqnqUHrRHwEjqM0NF8Pnul2q8xhKR9GT1otRCTcHLq30043BhC6PAstn0DpF87YyYKg1c7SXXfECDBPQjhY13vBuL~4405559~3617093
              2024-07-03 21:20:59 UTC643INHTTP/1.1 200 OK
              Content-Type: image/vnd.microsoft.icon
              Last-Modified: Wed, 26 Jun 2024 17:51:54 GMT
              ETag: "209c-61bceab7c4b90"
              X-Frame-Options: SAMEORIGIN
              X-EdgeConnect-MidMile-RTT: 0
              X-EdgeConnect-Origin-MEX-Latency: 127
              X-EdgeConnect-MidMile-RTT: 2
              X-EdgeConnect-Origin-MEX-Latency: 104
              Cache-Control: max-age=86400
              Expires: Thu, 04 Jul 2024 21:20:59 GMT
              Date: Wed, 03 Jul 2024 21:20:59 GMT
              Content-Length: 8348
              Connection: close
              Server-Timing: cdn-cache; desc=REVALIDATE
              Server-Timing: edge; dur=10
              Server-Timing: origin; dur=104
              Server-Timing: ak_p; desc="1720041659020_386904492_429145630_11337_10283_177_206_-";dur=1
              2024-07-03 21:20:59 UTC8348INData Raw: 00 00 01 00 02 00 20 20 00 00 01 00 20 00 28 10 00 00 26 00 00 00 10 10 00 00 01 00 20 00 28 04 00 00 4e 10 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1c e3 ff 49 1c e0 fc e3 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1c e0 fc e3 1c e3 ff 49 1c e0 fc e3 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b
              Data Ascii: (& (N( @ II


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.4497422.18.97.153443
              TimestampBytes transferredDirectionData
              2024-07-03 21:20:59 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-07-03 21:20:59 UTC466INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-neu-z1
              Cache-Control: public, max-age=67791
              Date: Wed, 03 Jul 2024 21:20:59 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.4497432.18.97.153443
              TimestampBytes transferredDirectionData
              2024-07-03 21:21:00 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-07-03 21:21:00 UTC534INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
              Cache-Control: public, max-age=67677
              Date: Wed, 03 Jul 2024 21:21:00 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-07-03 21:21:00 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.44974423.197.52.2244434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-03 21:21:00 UTC1242OUTGET /favicon.ico HTTP/1.1
              Host: mailchimp.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: _abck=9B8C05219FF12A52C26F129C89D069D2~-1~YAAQrLEPF/K7E1SQAQAA29Z4egy77LFR0/lfM3tqRcxfrb8CiQmlxI257cfbQgtokVzwg06TUDvovLVOJbNDX8VztU4k+HPugdkFDScRMZpbdsrARBhR5mH7giUEmUJww81VbAYHX4C5MTqkUl9uOp41a4JlzmTsmMlpSu0tNZJQjkmuE8P4o3x+FZtmUJyorTDNBPzQGWKYnDDB1Xl0lnnX1rEJu27SpLq8xysra3IyafMUtrrDC5tfUEoUu1ry3DCfnG4nQqNd8gXcBFNSR59hQuWbSmPv8a5KIB1URlcoBC+yNSaKX5/T+AOM/fikBctp4deoPli19EhVD0f3OLdl0x8efKtn3CnN8HIlrDLlV4HEQlfLuf/r6M/1Cx4=~-1~-1~-1; bm_sz=E89BCAAF16F8E04A0E8560308FCDB31B~YAAQrLEPF/O7E1SQAQAA29Z4ehgdE19We3S1jhyVGywiJRMbDEuxAkzsR91Th5QeIsw/0A+EgiZdN+y1a1Cc6eAAV0xfM9l3LOMJi23iF8QAEqYAd75hOl4cR9dclTHH1o3PQOCK+z1rRzpEPUlYM2xAzcdeuUzFx4rhJzm2u4jso+11dqm3ORSNMG17xFQts+S5/3BxUIUdabdukCA8SW7W3iistzSQkoa5wQHMFKnjvXRQSB8OhxMLLJI+UTRfB6Q0+X2Uj7QxKt2eRk0ghZRzKUF2GlCIMJga9PZzhaHUySXCqnqUHrRHwEjqM0NF8Pnul2q8xhKR9GT1otRCTcHLq30043BhC6PAstn0DpF87YyYKg1c7SXXfECDBPQjhY13vBuL~4405559~3617093
              2024-07-03 21:21:00 UTC601INHTTP/1.1 200 OK
              Content-Type: image/vnd.microsoft.icon
              Last-Modified: Wed, 26 Jun 2024 17:51:54 GMT
              ETag: "209c-61bceab7c4b90"
              X-Frame-Options: SAMEORIGIN
              X-EdgeConnect-MidMile-RTT: 0
              X-EdgeConnect-Origin-MEX-Latency: 127
              X-EdgeConnect-MidMile-RTT: 2
              X-EdgeConnect-Origin-MEX-Latency: 104
              Cache-Control: max-age=86399
              Expires: Thu, 04 Jul 2024 21:20:59 GMT
              Date: Wed, 03 Jul 2024 21:21:00 GMT
              Content-Length: 8348
              Connection: close
              Server-Timing: cdn-cache; desc=HIT
              Server-Timing: edge; dur=1
              Server-Timing: ak_p; desc="1720041660220_386904492_429145832_513_10843_159_189_-";dur=1
              2024-07-03 21:21:00 UTC8348INData Raw: 00 00 01 00 02 00 20 20 00 00 01 00 20 00 28 10 00 00 26 00 00 00 10 10 00 00 01 00 20 00 28 04 00 00 4e 10 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1c e3 ff 49 1c e0 fc e3 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1c e0 fc e3 1c e3 ff 49 1c e0 fc e3 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b e0 ff ff 1b
              Data Ascii: (& (N( @ II


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:17:20:49
              Start date:03/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:17:20:52
              Start date:03/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1996,i,6320455061481165711,4465343319517655028,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:17:20:54
              Start date:03/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lodgesonvashon.us11.list-manage.com"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly