Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.rb.gy/95iujo/

Overview

General Information

Sample URL:http://www.rb.gy/95iujo/
Analysis ID:1521252
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4500 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2036,i,14453290393001941837,6236110503833253448,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/95iujo/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.rb.gy/95iujo/SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: https://dev-39218u12i3ui120932012a.pantheonsite.io/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.100.168
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.100.168
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dev-39218u12i3ui120932012a.pantheonsite.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dev-39218u12i3ui120932012a.pantheonsite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dev-39218u12i3ui120932012a.pantheonsite.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /95iujo/ HTTP/1.1Host: www.rb.gyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.rb.gy
Source: global trafficDNS traffic detected: DNS query: dev-39218u12i3ui120932012a.pantheonsite.io
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/4@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2036,i,14453290393001941837,6236110503833253448,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/95iujo/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2036,i,14453290393001941837,6236110503833253448,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.rb.gy/95iujo/100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.16.196
truefalse
    unknown
    www.rb.gy
    54.236.142.223
    truefalse
      unknown
      fe3.edge.pantheon.io
      23.185.0.3
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          dev-39218u12i3ui120932012a.pantheonsite.io
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            http://www.rb.gy/95iujo/true
              unknown
              https://dev-39218u12i3ui120932012a.pantheonsite.io/false
                unknown
                https://dev-39218u12i3ui120932012a.pantheonsite.io/favicon.icofalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  54.236.142.223
                  www.rb.gyUnited States
                  14618AMAZON-AESUSfalse
                  23.185.0.3
                  fe3.edge.pantheon.ioUnited States
                  54113FASTLYUSfalse
                  172.217.16.196
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  192.168.2.6
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1521252
                  Start date and time:2024-09-28 06:39:58 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 11s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://www.rb.gy/95iujo/
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@17/4@6/6
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.185.142, 66.102.1.84, 34.104.35.123, 13.85.23.86, 93.184.221.240, 192.229.221.95, 13.95.31.18, 40.69.42.241, 216.58.206.67
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://www.rb.gy/95iujo/
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text
                  Category:downloaded
                  Size (bytes):616
                  Entropy (8bit):4.562595923555264
                  Encrypted:false
                  SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
                  MD5:98DD13B362E5AFD02246C08839DB3122
                  SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
                  SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
                  SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
                  Malicious:false
                  Reputation:low
                  URL:https://dev-39218u12i3ui120932012a.pantheonsite.io/favicon.ico
                  Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text
                  Category:downloaded
                  Size (bytes):616
                  Entropy (8bit):4.562595923555264
                  Encrypted:false
                  SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
                  MD5:98DD13B362E5AFD02246C08839DB3122
                  SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
                  SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
                  SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
                  Malicious:false
                  Reputation:low
                  URL:https://dev-39218u12i3ui120932012a.pantheonsite.io/
                  Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 28, 2024 06:40:54.993246078 CEST49675443192.168.2.4173.222.162.32
                  Sep 28, 2024 06:40:55.973750114 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:55.974066019 CEST4973680192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:55.978559017 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:40:55.978642941 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:55.978801012 CEST804973654.236.142.223192.168.2.4
                  Sep 28, 2024 06:40:55.978828907 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:55.978856087 CEST4973680192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:55.983555079 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:40:56.463191986 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:40:56.488210917 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.488336086 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.488424063 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.488662958 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.488702059 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.509933949 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:40:56.944183111 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.944470882 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.944509029 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.945617914 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.945698977 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.948304892 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.948401928 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.948900938 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:56.948935986 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:56.995671034 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.066365004 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.066448927 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.066519022 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.067218065 CEST49737443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.067262888 CEST4434973723.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.145251036 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.145296097 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.145381927 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.145697117 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.145705938 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.617367983 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.639763117 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.639796972 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.640259027 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.666157961 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.666232109 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.671912909 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.715404987 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.793327093 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.793457985 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.793509007 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.906986952 CEST49740443192.168.2.423.185.0.3
                  Sep 28, 2024 06:40:57.907028913 CEST4434974023.185.0.3192.168.2.4
                  Sep 28, 2024 06:40:57.953167915 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:57.953203917 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:57.953258991 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:57.953855991 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:57.953871965 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.587779045 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.606141090 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:58.606175900 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.607186079 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.607248068 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:58.634079933 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:58.634157896 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.680648088 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:58.680674076 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:40:58.732588053 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:40:58.929949045 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:58.929979086 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:58.930044889 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:58.932981014 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:58.932992935 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.599972010 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.600152969 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.614223003 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.614239931 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.614485025 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.665050030 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.708383083 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.751446962 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.904784918 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.904839039 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.905952930 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.921165943 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.921199083 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:40:59.921703100 CEST49742443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:40:59.921713114 CEST44349742184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.085547924 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.085589886 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.085706949 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.086740017 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.086759090 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.737404108 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.737468958 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.761682987 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.761710882 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.762039900 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:00.781056881 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:00.827408075 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:01.015204906 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:01.015285015 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:01.015333891 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:01.018611908 CEST49743443192.168.2.4184.28.90.27
                  Sep 28, 2024 06:41:01.018632889 CEST44349743184.28.90.27192.168.2.4
                  Sep 28, 2024 06:41:08.495404005 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:08.495455980 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:08.496139050 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:08.655436993 CEST49741443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:08.655498028 CEST44349741172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:11.740017891 CEST4972380192.168.2.42.16.100.168
                  Sep 28, 2024 06:41:11.745264053 CEST80497232.16.100.168192.168.2.4
                  Sep 28, 2024 06:41:11.745318890 CEST4972380192.168.2.42.16.100.168
                  Sep 28, 2024 06:41:40.993005991 CEST4973680192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:40.997920036 CEST804973654.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:41.477482080 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:41.482482910 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:56.365340948 CEST804973654.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:56.366277933 CEST4973680192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:56.464576960 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:56.464634895 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:56.589637995 CEST4973680192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:56.589848995 CEST4973580192.168.2.454.236.142.223
                  Sep 28, 2024 06:41:56.594511032 CEST804973654.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:56.594662905 CEST804973554.236.142.223192.168.2.4
                  Sep 28, 2024 06:41:57.993587017 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:57.993665934 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:57.993789911 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:57.994246960 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:57.994277954 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:58.636487007 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:58.636766911 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:58.636786938 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:58.637917995 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:58.638381958 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:41:58.638567924 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:41:58.680218935 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:42:08.563043118 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:42:08.563188076 CEST44349752172.217.16.196192.168.2.4
                  Sep 28, 2024 06:42:08.563286066 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:42:08.591185093 CEST49752443192.168.2.4172.217.16.196
                  Sep 28, 2024 06:42:08.591206074 CEST44349752172.217.16.196192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 28, 2024 06:40:54.242891073 CEST53572691.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:54.295586109 CEST53559131.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:55.584104061 CEST53568501.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:55.964021921 CEST6182053192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:55.964202881 CEST5687853192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:55.972623110 CEST53568781.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:55.973289013 CEST53618201.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:56.468189955 CEST6163253192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:56.468347073 CEST6490953192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:56.486531019 CEST53616321.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:56.487590075 CEST53649091.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:57.943613052 CEST5323253192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:57.944149017 CEST5176653192.168.2.41.1.1.1
                  Sep 28, 2024 06:40:57.950488091 CEST53532321.1.1.1192.168.2.4
                  Sep 28, 2024 06:40:57.950963974 CEST53517661.1.1.1192.168.2.4
                  Sep 28, 2024 06:41:11.531215906 CEST138138192.168.2.4192.168.2.255
                  Sep 28, 2024 06:41:12.501725912 CEST53649241.1.1.1192.168.2.4
                  Sep 28, 2024 06:41:31.548553944 CEST53589421.1.1.1192.168.2.4
                  Sep 28, 2024 06:41:53.487356901 CEST53600281.1.1.1192.168.2.4
                  Sep 28, 2024 06:41:54.112093925 CEST53629521.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Sep 28, 2024 06:40:55.964021921 CEST192.168.2.41.1.1.10xf182Standard query (0)www.rb.gyA (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:55.964202881 CEST192.168.2.41.1.1.10x2285Standard query (0)www.rb.gy65IN (0x0001)false
                  Sep 28, 2024 06:40:56.468189955 CEST192.168.2.41.1.1.10xac44Standard query (0)dev-39218u12i3ui120932012a.pantheonsite.ioA (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:56.468347073 CEST192.168.2.41.1.1.10xcf88Standard query (0)dev-39218u12i3ui120932012a.pantheonsite.io65IN (0x0001)false
                  Sep 28, 2024 06:40:57.943613052 CEST192.168.2.41.1.1.10x4db6Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:57.944149017 CEST192.168.2.41.1.1.10xe18eStandard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Sep 28, 2024 06:40:55.973289013 CEST1.1.1.1192.168.2.40xf182No error (0)www.rb.gy54.236.142.223A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:55.973289013 CEST1.1.1.1192.168.2.40xf182No error (0)www.rb.gy44.193.97.228A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:55.973289013 CEST1.1.1.1192.168.2.40xf182No error (0)www.rb.gy44.197.136.35A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:56.486531019 CEST1.1.1.1192.168.2.40xac44No error (0)dev-39218u12i3ui120932012a.pantheonsite.iofe3.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:40:56.486531019 CEST1.1.1.1192.168.2.40xac44No error (0)fe3.edge.pantheon.io23.185.0.3A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:56.487590075 CEST1.1.1.1192.168.2.40xcf88No error (0)dev-39218u12i3ui120932012a.pantheonsite.iofe3.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:40:57.950488091 CEST1.1.1.1192.168.2.40x4db6No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:40:57.950963974 CEST1.1.1.1192.168.2.40xe18eNo error (0)www.google.com65IN (0x0001)false
                  Sep 28, 2024 06:41:10.727058887 CEST1.1.1.1192.168.2.40x499aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:41:10.727058887 CEST1.1.1.1192.168.2.40x499aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:41:22.940846920 CEST1.1.1.1192.168.2.40x600dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:41:22.940846920 CEST1.1.1.1192.168.2.40x600dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:41:46.704705954 CEST1.1.1.1192.168.2.40xd3d6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:41:46.704705954 CEST1.1.1.1192.168.2.40xd3d6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 28, 2024 06:42:06.596719980 CEST1.1.1.1192.168.2.40x5e29No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2024 06:42:06.596719980 CEST1.1.1.1192.168.2.40x5e29No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  • dev-39218u12i3ui120932012a.pantheonsite.io
                  • https:
                  • fs.microsoft.com
                  • www.rb.gy
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44973554.236.142.223802416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Sep 28, 2024 06:40:55.978828907 CEST431OUTGET /95iujo/ HTTP/1.1
                  Host: www.rb.gy
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Sep 28, 2024 06:40:56.463191986 CEST266INHTTP/1.1 301 Moved Permanently
                  Date: Sat, 28 Sep 2024 04:40:56 GMT
                  Content-Length: 0
                  Connection: keep-alive
                  Cache-Control: no-cache, no-store
                  Expires: -1
                  Location: https://dev-39218u12i3ui120932012a.pantheonsite.io/
                  Engine: Rebrandly.redirect, version 2.1
                  Sep 28, 2024 06:41:41.477482080 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44973654.236.142.223802416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Sep 28, 2024 06:41:40.993005991 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44973723.185.0.34432416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-09-28 04:40:56 UTC685OUTGET / HTTP/1.1
                  Host: dev-39218u12i3ui120932012a.pantheonsite.io
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-09-28 04:40:57 UTC560INHTTP/1.1 504 Target in maintenance
                  Connection: close
                  Content-Length: 616
                  Retry-After: 0
                  X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
                  Content-Type: text/html; charset=utf-8
                  Fastly-Restarts: 1
                  Date: Sat, 28 Sep 2024 04:40:57 GMT
                  Server: Pantheon
                  X-Served-By: cache-chi-klot8100164-CHI, cache-ewr-kewr1740034-EWR
                  X-Cache: MISS, MISS
                  X-Cache-Hits: 0, 0
                  X-Timer: S1727498457.001006,VS0,VE24
                  Vary: Cookie, Cookie
                  X-Robots-Tag: noindex
                  Age: 0
                  Accept-Ranges: bytes
                  Via: 1.1 varnish, 1.1 varnish
                  2024-09-28 04:40:57 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                  Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44974023.185.0.34432416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-09-28 04:40:57 UTC640OUTGET /favicon.ico HTTP/1.1
                  Host: dev-39218u12i3ui120932012a.pantheonsite.io
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://dev-39218u12i3ui120932012a.pantheonsite.io/
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-09-28 04:40:57 UTC560INHTTP/1.1 504 Target in maintenance
                  Connection: close
                  Content-Length: 616
                  Retry-After: 0
                  X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
                  Content-Type: text/html; charset=utf-8
                  Fastly-Restarts: 1
                  Date: Sat, 28 Sep 2024 04:40:57 GMT
                  Server: Pantheon
                  X-Served-By: cache-chi-kigq8000152-CHI, cache-ewr-kewr1740048-EWR
                  X-Cache: MISS, MISS
                  X-Cache-Hits: 0, 0
                  X-Timer: S1727498458.723733,VS0,VE24
                  Vary: Cookie, Cookie
                  X-Robots-Tag: noindex
                  Age: 0
                  Accept-Ranges: bytes
                  Via: 1.1 varnish, 1.1 varnish
                  2024-09-28 04:40:57 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                  Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449742184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-09-28 04:40:59 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-09-28 04:40:59 UTC467INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF67)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-neu-z1
                  Cache-Control: public, max-age=216243
                  Date: Sat, 28 Sep 2024 04:40:59 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.449743184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-09-28 04:41:00 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-09-28 04:41:01 UTC515INHTTP/1.1 200 OK
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-weu-z1
                  Cache-Control: public, max-age=216272
                  Date: Sat, 28 Sep 2024 04:41:00 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-09-28 04:41:01 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:00:40:50
                  Start date:28/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:00:40:52
                  Start date:28/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2036,i,14453290393001941837,6236110503833253448,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:00:40:55
                  Start date:28/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/95iujo/"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly