Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.sgtllcsales.ae

Overview

General Information

Sample URL:http://www.sgtllcsales.ae
Analysis ID:1554991
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 4720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1980,i,13586612571391427626,8045038456143489032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4952 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.sgtllcsales.ae" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.5:55348 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.5:65076 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.5:55347 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficDNS traffic detected: DNS query: www.sgtllcsales.ae
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 55365 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55348
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55349
Source: unknownNetwork traffic detected: HTTP traffic on port 55359 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55371 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55351
Source: unknownNetwork traffic detected: HTTP traffic on port 55352 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55352
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55353
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55354
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55350
Source: unknownNetwork traffic detected: HTTP traffic on port 55349 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55368 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55366 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55362 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55359
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55358 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55372 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55355
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55356
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55357
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55358
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55362
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55363
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55364
Source: unknownNetwork traffic detected: HTTP traffic on port 55355 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55365
Source: unknownNetwork traffic detected: HTTP traffic on port 55351 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55360
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55361
Source: unknownNetwork traffic detected: HTTP traffic on port 55348 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55361 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55369 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55363 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55357 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55373 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55366
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55367
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55368
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55369
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55373
Source: unknownNetwork traffic detected: HTTP traffic on port 55354 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55350 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55370
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55371
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55372
Source: unknownNetwork traffic detected: HTTP traffic on port 55360 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55364 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55370 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55356 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55353 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 55367 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.5:55348 version: TLS 1.2
Source: classification engineClassification label: unknown1.win@25/6@17/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1980,i,13586612571391427626,8045038456143489032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.sgtllcsales.ae"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1980,i,13586612571391427626,8045038456143489032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.sgtllcsales.ae0%Avira URL Cloudsafe
http://www.sgtllcsales.ae0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
www.sgtllcsales.ae0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.238
truefalse
    high
    s-part-0017.t-0009.t-msedge.net
    13.107.246.45
    truefalse
      high
      www.google.com
      172.217.18.4
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          high
          www.sgtllcsales.ae
          unknown
          unknownfalseunknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          172.217.18.4
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.5
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1554991
          Start date and time:2024-11-13 09:55:22 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 58s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://www.sgtllcsales.ae
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:6
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown1.win@25/6@17/3
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.186.131, 216.58.206.46, 74.125.133.84, 34.104.35.123, 184.28.90.27, 20.109.210.53, 93.184.221.240, 192.229.221.95, 13.95.31.18, 20.3.187.198, 20.242.39.171
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, azureedge-t-prod.trafficmanager.net, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
          No simulations
          InputOutput
          URL: Model: claude-3-5-sonnet-latest
          {
              "typosquatting": false,
              "unusual_query_string": false,
              "suspicious_tld": true,
              "ip_in_url": false,
              "long_subdomain": false,
              "malicious_keywords": false,
              "encoded_characters": false,
              "redirection": false,
              "contains_email_address": false,
              "known_domain": false,
              "brand_spoofing_attempt": false,
              "third_party_hosting": false
          }
          URL: http://www.sgtllcsales.ae
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 13 07:56:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9732406185428464
          Encrypted:false
          SSDEEP:48:88dPTnjwHpidAKZdA19ehwiZUklqehNy+3:8MfmKy
          MD5:523DB55A845021A73A49C356199C5ACF
          SHA1:0435FCA00B2AB3521169524A80D193C84897A2E1
          SHA-256:3C72E879433962C9C71B203FBC7E475AAC5962BFE9CF9E592C178B8BDC03B638
          SHA-512:C8ED8F8CE3C2CEF2EDA77089D3E48B297A405971AB7A54173D74365D2E9516600CCCF4B371A55B0F4A9FE2DF23AD7884CDF941314BE92F060B7EB84E7AD2955D
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....0..5..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VmY.G...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 13 07:56:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.9898223610654973
          Encrypted:false
          SSDEEP:48:86dPTnjwHpidAKZdA1weh/iZUkAQkqeh6y+2:86fk9Q/y
          MD5:C1FD2BF9CA4D186186BFCD283DFFC674
          SHA1:1799E562D7192B1364639B78DBB937723FDE7C2E
          SHA-256:59EA6C717CE528FB9AD1E8B7FA173F960369FD78232760ABC61B534699DC80F3
          SHA-512:80E25D5ABA65931619EBAB3A7C4757D45757544E062CE1B6756D4EFC25BA97846F4AFD31773FFB5AEB0A308A1DBD78829F976031413D8763EDC3B109BB8894E4
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,........5..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VmY.G...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2693
          Entropy (8bit):4.002799686633239
          Encrypted:false
          SSDEEP:48:8xMdPTnjsHpidAKZdA14tseh7sFiZUkmgqeh7s8y+BX:8x8fAn2y
          MD5:87FDE66107A7AF969F16845C107B90E9
          SHA1:EF0D8B0C0D568B2E7212C78AA714F569CC916217
          SHA-256:CE47625A69EDB45C43E7246D910A30FC21120A94C53C791DCB84BDEF956E10D5
          SHA-512:8546F27B090048C7FC36350588B3C746943561315EF44B0D07071FB6F64C085A25E411BAA173D217FBEDF47345DA11F070B39267505C2D9189AEB5BD88953189
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 13 07:56:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.989962998598412
          Encrypted:false
          SSDEEP:48:83dPTnjwHpidAKZdA1vehDiZUkwqehOy+R:8Zfv0y
          MD5:BF4541C1AD6D2553A410EC0C43131645
          SHA1:D1041A62C7EEBDB262DB7C5A52110B3B47DDEBE7
          SHA-256:BE9E814E011396BD48265509B6E02B8D556BD46A836236B601F2B5AB4BCC3C52
          SHA-512:8C56D5DEB48A2F48D5E43E44CB824EF9CAFA1CC61625DA5E950A319A0B0811604A8A207D7BFBC04D5F484621364A9530A38BBEEAC60E3246135CED6F3EBECCE6
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....'...5..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VmY.G...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 13 07:56:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.9762446433899417
          Encrypted:false
          SSDEEP:48:8zdPTnjwHpidAKZdA1hehBiZUk1W1qehYy+C:8NfP94y
          MD5:CDA5809DECE661ACC3FA246AC7D55CB6
          SHA1:71F6AE522DCD31AA22FD056B52030422143EB099
          SHA-256:AE863448BDCF669368AAC980440494824B685760E2B46D459CDC7D77A9DAA5BF
          SHA-512:7679CEA1D0D2A6AB7155839E0BAA2C4D6E587264B4BE424EE5E8666593696ADDBB9351030C1366E4DA4B6899EC20D0A8971385AC865B309717AB8B896AD4277C
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....Gk..5..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VmY.G...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 13 07:56:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2683
          Entropy (8bit):3.9897597158616827
          Encrypted:false
          SSDEEP:48:8YdPTnjwHpidAKZdA1duT+ehOuTbbiZUk5OjqehOuTb2y+yT+:8QfHT/TbxWOvTb2y7T
          MD5:3324F65FBF5481219F98FF7B95B599EC
          SHA1:0E4B88814FE7320A9EC3A958CBB3B7EE9123ABEE
          SHA-256:C20CD792925602AA255D64EFB2CC04EAC75DE562E3FFAB6FD06F31E0B8DB0E18
          SHA-512:3A030BD442103641584A2909BF7A080B1820FE15C2E9C2043645928E9C920D2123EA2B981F031D4F632E188E06C22882097028398B25C9E7D4CE441922283F76
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......}.5..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.ImY.G....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VmY.G....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VmY.G....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VmY.G..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VmY.G...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Nov 13, 2024 09:56:06.763129950 CET49675443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:06.763184071 CET49674443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:06.872404099 CET49673443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:16.373279095 CET49674443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:16.406845093 CET49675443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:16.513645887 CET49673443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:18.226366997 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:18.226455927 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:18.226557016 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:18.226979017 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:18.227015972 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:18.251159906 CET4434970323.1.237.91192.168.2.5
          Nov 13, 2024 09:56:18.251295090 CET49703443192.168.2.523.1.237.91
          Nov 13, 2024 09:56:19.099647999 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:19.103429079 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:19.103471041 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:19.104526997 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:19.104595900 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:19.386434078 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:19.386668921 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:19.436404943 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:19.436429977 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:19.483275890 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:20.100544930 CET6507653192.168.2.51.1.1.1
          Nov 13, 2024 09:56:20.105437994 CET53650761.1.1.1192.168.2.5
          Nov 13, 2024 09:56:20.107484102 CET6507653192.168.2.51.1.1.1
          Nov 13, 2024 09:56:20.107842922 CET6507653192.168.2.51.1.1.1
          Nov 13, 2024 09:56:20.112673044 CET53650761.1.1.1192.168.2.5
          Nov 13, 2024 09:56:20.733849049 CET53650761.1.1.1192.168.2.5
          Nov 13, 2024 09:56:20.734755993 CET6507653192.168.2.51.1.1.1
          Nov 13, 2024 09:56:20.740482092 CET53650761.1.1.1192.168.2.5
          Nov 13, 2024 09:56:20.740622044 CET6507653192.168.2.51.1.1.1
          Nov 13, 2024 09:56:29.133712053 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:29.133810997 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:29.133899927 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:29.971796036 CET49711443192.168.2.5172.217.18.4
          Nov 13, 2024 09:56:29.971865892 CET44349711172.217.18.4192.168.2.5
          Nov 13, 2024 09:56:30.898653984 CET5534753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:30.903608084 CET53553471.1.1.1192.168.2.5
          Nov 13, 2024 09:56:30.903691053 CET5534753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:30.903726101 CET5534753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:30.910204887 CET53553471.1.1.1192.168.2.5
          Nov 13, 2024 09:56:31.368397951 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:31.368429899 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:31.368482113 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:31.370207071 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:31.370215893 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:31.499980927 CET53553471.1.1.1192.168.2.5
          Nov 13, 2024 09:56:31.504388094 CET5534753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:31.509856939 CET53553471.1.1.1192.168.2.5
          Nov 13, 2024 09:56:31.509907007 CET5534753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:32.090749979 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.092253923 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.097784042 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.097791910 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.097999096 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.111824036 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.159327030 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.350608110 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.350625992 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.350790024 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.350908041 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.350915909 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.350974083 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.351015091 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.466177940 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.466191053 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.467433929 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.467438936 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.470985889 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.581404924 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.581424952 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.581532955 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.581532955 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.581537008 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.581602097 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.697544098 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.697557926 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.697839975 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.697845936 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.698086023 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.812370062 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.812383890 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.812467098 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.812472105 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.812510014 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.928437948 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.928456068 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.928493023 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.928558111 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:32.928564072 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:32.928601027 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.042857885 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.042875051 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.042939901 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.042944908 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.042998075 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.504859924 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.504873991 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.504930019 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.504940987 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.504970074 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.504973888 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505060911 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.505060911 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.505070925 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505080938 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505105972 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505135059 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.505153894 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.505896091 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505916119 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505969048 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.505975008 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.505995989 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.506016970 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.509825945 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.509846926 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.509886026 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.509892941 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.509923935 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.509943962 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.511291981 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.511327982 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.511351109 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.511358023 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.511382103 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.511403084 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.547355890 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.547388077 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.547420979 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.547441959 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.547470093 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.547487974 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.599790096 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.599858999 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.599874020 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.599893093 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.599915028 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.599946976 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.600076914 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.600090981 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.600101948 CET55348443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.600109100 CET4435534813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.642344952 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.642432928 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.642483950 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.642514944 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.642518997 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.642569065 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.642921925 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.642935991 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.643217087 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.643259048 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.644840002 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.644867897 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.644957066 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.645072937 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.645088911 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.646189928 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.646215916 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.646279097 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.646383047 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.646389961 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.647322893 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.647365093 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:33.647440910 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.647561073 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:33.647578955 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.375210047 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.375766039 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.375783920 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.375808954 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.376336098 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.376349926 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.376468897 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.376528978 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.376795053 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.376808882 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.378799915 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.379304886 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.379319906 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.379472971 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.379635096 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.379646063 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.380269051 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.380330086 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.380383968 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.380654097 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.380660057 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.380743027 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.380790949 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.381088018 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.381095886 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.504160881 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.504179001 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.504229069 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.504391909 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.504393101 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.504651070 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.504688978 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.504733086 CET55349443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.504748106 CET4435534913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.505140066 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.505341053 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.505537987 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.505647898 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.505666971 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.505896091 CET55350443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.505902052 CET4435535013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508408070 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508445024 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508522987 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508541107 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508604050 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508609056 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508610010 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508627892 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508697033 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508744955 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508744955 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508759975 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508764982 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508790016 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508801937 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.508856058 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.508883953 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.509166956 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.509166956 CET55351443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.509170055 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.509182930 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.509205103 CET4435535113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.509212971 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.509336948 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.509757996 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.510349035 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.510349035 CET55352443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.510365963 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.510413885 CET4435535213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512341976 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512425900 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512458086 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512487888 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512495041 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512531042 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512531042 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512581110 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512588024 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512609959 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512640953 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512641907 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512679100 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512711048 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512780905 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512797117 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.512967110 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.512985945 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.513020992 CET55353443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.513034105 CET4435535313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.514983892 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.515003920 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:34.515237093 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.515237093 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:34.515286922 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.234853029 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.235488892 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.235519886 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.235989094 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.236000061 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.237792969 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.238122940 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.238167048 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.238636017 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.238646030 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.239309072 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.239588022 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.239645958 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.239947081 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.239960909 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.256323099 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.256694078 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.256717920 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.257194996 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.257209063 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.283679962 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.284037113 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.284095049 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.284396887 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.284410954 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.361915112 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.362056017 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.362179041 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.362272978 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.362272978 CET55358443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.362323046 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.362356901 CET4435535813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.364945889 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.365020990 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.365103006 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.365205050 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.365221977 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.369520903 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.369752884 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.369899035 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.369899988 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.369899988 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.371675014 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.371697903 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.371807098 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.371932030 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.371954918 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.373142958 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.373698950 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.373768091 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.373851061 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.373851061 CET55355443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.373894930 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.373924971 CET4435535513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.375545025 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.375595093 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.375655890 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.375768900 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.375787020 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.386778116 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.386976957 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.387161016 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.387161016 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.387161970 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.388886929 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.388942957 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.389019966 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.389130116 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.389151096 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.421370983 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.421819925 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.421933889 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.421935081 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.422013998 CET55356443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.422049046 CET4435535613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.423985004 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.424027920 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.424099922 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.424222946 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.424256086 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.669882059 CET55354443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.669919014 CET4435535413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:35.701076031 CET55357443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:35.701102972 CET4435535713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.108055115 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.108180046 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.108800888 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.108824968 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.108849049 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.108912945 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.109503031 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.109515905 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.109642029 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.109649897 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.122819901 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.123198986 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.123215914 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.123788118 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.123799086 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.124465942 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.124823093 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.124851942 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.125475883 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.125488043 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.143114090 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.143491030 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.143572092 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.144185066 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.144197941 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240196943 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240340948 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240456104 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240509987 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.240650892 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.240686893 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240712881 CET55359443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.240727901 CET4435535913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.240820885 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.241878033 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.241878033 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.241878986 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244469881 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244519949 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.244679928 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244700909 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244728088 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.244812965 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244824886 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.244832993 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244942904 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.244959116 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.251389027 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.251535892 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.251597881 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.251651049 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.251652002 CET55362443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.251676083 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.251701117 CET4435536213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.253469944 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.253640890 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.253755093 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254287004 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254308939 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.254380941 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254426956 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254426956 CET55360443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254442930 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.254465103 CET4435536013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.254676104 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.254704952 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.256943941 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.256956100 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.257015944 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.257129908 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.257143021 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.291523933 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.291594028 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.291763067 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.291893959 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.291893959 CET55363443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.291937113 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.291966915 CET4435536313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.294673920 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.294758081 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.295012951 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.295135975 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.295186996 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.544866085 CET55361443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.544935942 CET4435536113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.970596075 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.971317053 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.971348047 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.971808910 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.971817017 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.974143982 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.974500895 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.974525928 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.974994898 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.975006104 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.984920979 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.985264063 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.985294104 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.985603094 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.985614061 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.995625973 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.995955944 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.995979071 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:36.996335030 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:36.996340990 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.035099983 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.035819054 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.035904884 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.036351919 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.036367893 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.096995115 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.097282887 CET4435536613.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.097543001 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.097543001 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.097543001 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.100794077 CET55369443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.100833893 CET4435536913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.101910114 CET55369443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.101910114 CET55369443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.101946115 CET4435536913.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.104800940 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.104861021 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.104940891 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.105058908 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.105077028 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.105087042 CET55365443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.105093002 CET4435536513.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.107620955 CET55370443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.107712030 CET4435537013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.107796907 CET55370443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.107990026 CET55370443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.108031034 CET4435537013.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.118648052 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.119010925 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.119090080 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.119090080 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.119168043 CET55364443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.119204998 CET4435536413.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.122091055 CET55371443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.122123957 CET4435537113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.122308016 CET55371443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.122592926 CET55371443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.122610092 CET4435537113.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.126513958 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.126666069 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.126732111 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.126756907 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.126770973 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.126779079 CET55367443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.126784086 CET4435536713.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.129718065 CET55372443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.129760981 CET4435537213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.129841089 CET55372443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.129968882 CET55372443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.129987955 CET4435537213.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.167735100 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.168147087 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.168369055 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.168453932 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.168453932 CET55368443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.168498039 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.168526888 CET4435536813.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.171279907 CET55373443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.171327114 CET4435537313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.171413898 CET55373443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.171596050 CET55373443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.171607971 CET4435537313.107.246.45192.168.2.5
          Nov 13, 2024 09:56:37.404228926 CET55366443192.168.2.513.107.246.45
          Nov 13, 2024 09:56:37.404264927 CET4435536613.107.246.45192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Nov 13, 2024 09:56:13.815643072 CET53585471.1.1.1192.168.2.5
          Nov 13, 2024 09:56:13.820065022 CET53540461.1.1.1192.168.2.5
          Nov 13, 2024 09:56:14.854039907 CET6440053192.168.2.51.1.1.1
          Nov 13, 2024 09:56:14.854231119 CET4972353192.168.2.51.1.1.1
          Nov 13, 2024 09:56:14.863600016 CET53644001.1.1.1192.168.2.5
          Nov 13, 2024 09:56:14.863733053 CET53497231.1.1.1192.168.2.5
          Nov 13, 2024 09:56:14.864751101 CET5489353192.168.2.51.1.1.1
          Nov 13, 2024 09:56:14.986758947 CET53548931.1.1.1192.168.2.5
          Nov 13, 2024 09:56:15.024866104 CET5033953192.168.2.58.8.8.8
          Nov 13, 2024 09:56:15.025182009 CET5390753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:15.031974077 CET53539071.1.1.1192.168.2.5
          Nov 13, 2024 09:56:15.031989098 CET53503398.8.8.8192.168.2.5
          Nov 13, 2024 09:56:15.065179110 CET53540831.1.1.1192.168.2.5
          Nov 13, 2024 09:56:16.051985979 CET5004453192.168.2.51.1.1.1
          Nov 13, 2024 09:56:16.052468061 CET6301753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:16.061064959 CET53630171.1.1.1192.168.2.5
          Nov 13, 2024 09:56:16.175569057 CET53500441.1.1.1192.168.2.5
          Nov 13, 2024 09:56:18.211131096 CET5476953192.168.2.51.1.1.1
          Nov 13, 2024 09:56:18.211519003 CET6150553192.168.2.51.1.1.1
          Nov 13, 2024 09:56:18.223396063 CET53547691.1.1.1192.168.2.5
          Nov 13, 2024 09:56:18.223439932 CET53615051.1.1.1192.168.2.5
          Nov 13, 2024 09:56:20.099812031 CET53599311.1.1.1192.168.2.5
          Nov 13, 2024 09:56:21.192234039 CET6467953192.168.2.51.1.1.1
          Nov 13, 2024 09:56:21.192809105 CET5660753192.168.2.51.1.1.1
          Nov 13, 2024 09:56:21.204160929 CET53646791.1.1.1192.168.2.5
          Nov 13, 2024 09:56:21.226448059 CET6328353192.168.2.51.1.1.1
          Nov 13, 2024 09:56:21.323079109 CET53566071.1.1.1192.168.2.5
          Nov 13, 2024 09:56:21.361298084 CET53632831.1.1.1192.168.2.5
          Nov 13, 2024 09:56:27.727612972 CET5194453192.168.2.51.1.1.1
          Nov 13, 2024 09:56:27.727777004 CET6299153192.168.2.51.1.1.1
          Nov 13, 2024 09:56:27.738647938 CET53519441.1.1.1192.168.2.5
          Nov 13, 2024 09:56:27.754590988 CET5681453192.168.2.51.1.1.1
          Nov 13, 2024 09:56:27.764894962 CET53568141.1.1.1192.168.2.5
          Nov 13, 2024 09:56:27.775708914 CET5157253192.168.2.51.1.1.1
          Nov 13, 2024 09:56:27.775949955 CET5787453192.168.2.58.8.8.8
          Nov 13, 2024 09:56:27.783648968 CET53515721.1.1.1192.168.2.5
          Nov 13, 2024 09:56:27.784127951 CET53578748.8.8.8192.168.2.5
          Nov 13, 2024 09:56:27.851222992 CET53629911.1.1.1192.168.2.5
          Nov 13, 2024 09:56:30.897978067 CET53638551.1.1.1192.168.2.5
          TimestampSource IPDest IPChecksumCodeType
          Nov 13, 2024 09:56:21.323179960 CET192.168.2.51.1.1.1c220(Port unreachable)Destination Unreachable
          Nov 13, 2024 09:56:27.851389885 CET192.168.2.51.1.1.1c220(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Nov 13, 2024 09:56:14.854039907 CET192.168.2.51.1.1.10xf0b8Standard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:14.854231119 CET192.168.2.51.1.1.10x54fStandard query (0)www.sgtllcsales.ae65IN (0x0001)false
          Nov 13, 2024 09:56:14.864751101 CET192.168.2.51.1.1.10xacf3Standard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:15.024866104 CET192.168.2.58.8.8.80xe220Standard query (0)google.comA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:15.025182009 CET192.168.2.51.1.1.10x9587Standard query (0)google.comA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:16.051985979 CET192.168.2.51.1.1.10xe81eStandard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:16.052468061 CET192.168.2.51.1.1.10x9270Standard query (0)www.sgtllcsales.ae65IN (0x0001)false
          Nov 13, 2024 09:56:18.211131096 CET192.168.2.51.1.1.10xd51dStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:18.211519003 CET192.168.2.51.1.1.10xf730Standard query (0)www.google.com65IN (0x0001)false
          Nov 13, 2024 09:56:21.192234039 CET192.168.2.51.1.1.10xda3aStandard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:21.192809105 CET192.168.2.51.1.1.10x6aaeStandard query (0)www.sgtllcsales.ae65IN (0x0001)false
          Nov 13, 2024 09:56:21.226448059 CET192.168.2.51.1.1.10x7b0eStandard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.727612972 CET192.168.2.51.1.1.10x93c0Standard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.727777004 CET192.168.2.51.1.1.10x31eStandard query (0)www.sgtllcsales.ae65IN (0x0001)false
          Nov 13, 2024 09:56:27.754590988 CET192.168.2.51.1.1.10x3c56Standard query (0)www.sgtllcsales.aeA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.775708914 CET192.168.2.51.1.1.10x2a38Standard query (0)google.comA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.775949955 CET192.168.2.58.8.8.80x6920Standard query (0)google.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Nov 13, 2024 09:56:14.863600016 CET1.1.1.1192.168.2.50xf0b8Name error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:14.863733053 CET1.1.1.1192.168.2.50x54fName error (3)www.sgtllcsales.aenonenone65IN (0x0001)false
          Nov 13, 2024 09:56:14.986758947 CET1.1.1.1192.168.2.50xacf3Name error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:15.031974077 CET1.1.1.1192.168.2.50x9587No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:15.031989098 CET8.8.8.8192.168.2.50xe220No error (0)google.com216.58.206.46A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:16.061064959 CET1.1.1.1192.168.2.50x9270Name error (3)www.sgtllcsales.aenonenone65IN (0x0001)false
          Nov 13, 2024 09:56:16.175569057 CET1.1.1.1192.168.2.50xe81eName error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:18.223396063 CET1.1.1.1192.168.2.50xd51dNo error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:18.223439932 CET1.1.1.1192.168.2.50xf730No error (0)www.google.com65IN (0x0001)false
          Nov 13, 2024 09:56:21.204160929 CET1.1.1.1192.168.2.50xda3aName error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:21.323079109 CET1.1.1.1192.168.2.50x6aaeName error (3)www.sgtllcsales.aenonenone65IN (0x0001)false
          Nov 13, 2024 09:56:21.361298084 CET1.1.1.1192.168.2.50x7b0eName error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.738647938 CET1.1.1.1192.168.2.50x93c0Name error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.764894962 CET1.1.1.1192.168.2.50x3c56Name error (3)www.sgtllcsales.aenonenoneA (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.783648968 CET1.1.1.1192.168.2.50x2a38No error (0)google.com172.217.18.14A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.784127951 CET8.8.8.8192.168.2.50x6920No error (0)google.com216.58.206.46A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:27.851222992 CET1.1.1.1192.168.2.50x31eName error (3)www.sgtllcsales.aenonenone65IN (0x0001)false
          Nov 13, 2024 09:56:28.567090034 CET1.1.1.1192.168.2.50x295aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Nov 13, 2024 09:56:28.567090034 CET1.1.1.1192.168.2.50x295aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
          Nov 13, 2024 09:56:31.366552114 CET1.1.1.1192.168.2.50x4fffNo error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
          Nov 13, 2024 09:56:31.366552114 CET1.1.1.1192.168.2.50x4fffNo error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
          • otelrules.azureedge.net
          Session IDSource IPSource PortDestination IPDestination Port
          0192.168.2.55534813.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:32 UTC195OUTGET /rules/other-Win32-v19.bundle HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:32 UTC471INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:32 GMT
          Content-Type: text/plain
          Content-Length: 218853
          Connection: close
          Vary: Accept-Encoding
          Cache-Control: public
          Last-Modified: Mon, 11 Nov 2024 13:19:38 GMT
          ETag: "0x8DD02537E74B538"
          x-ms-request-id: 38692f1b-b01e-0002-0984-341b8f000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085632Z-r178fb8d765tllwdhC1DFWaz8400000000w0000000008aqp
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:32 UTC15913INData Raw: 31 30 30 30 76 35 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 22 20 56 3d 22 35 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 52 75 6c 65 45 72 72 6f 72 73 41 67 67 72 65 67 61 74 65 64 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 53 3d 22 37 30 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20
          Data Ascii: 1000v5+<?xml version="1.0" encoding="utf-8"?><R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU"
          2024-11-13 08:56:32 UTC16384INData Raw: 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 42 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20
          Data Ascii: /> </R> </O> </R> </O> </C> <C T="B" I="5" O="false"> <O T="AND"> <L> <O T="GE"> <L> <S T="1" F="0" /> </L> <R> <V V="400" T="I32" />
          2024-11-13 08:56:32 UTC16384INData Raw: 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 38 32 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 6f 6e 74 61 63 74 43 61 72 64 50 72 6f 70 65 72 74 69 65 73 43 6f 75 6e 74 73 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d
          Data Ascii: .0" encoding="utf-8"?><R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryShutdown" />
          2024-11-13 08:56:32 UTC16384INData Raw: 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 39 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 41 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 31 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 46 69 6c 65 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 38 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20
          Data Ascii: </C> <C T="U32" I="9" O="true" N="Purged_Age"> <S T="4" F="Count" /> </C> <C T="U32" I="10" O="true" N="Purged_Count"> <S T="5" F="Count" /> </C> <C T="U32" I="11" O="true" N="File_Count"> <S T="8" F="Count" /> </C>
          2024-11-13 08:56:32 UTC16384INData Raw: 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 4d 61 6e 61 67 65 72 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 52 65 73 75 6c 74 5f 56 61 6c 69 64 50 65 72 73 6f 6e 61 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 32 22 20 2f 3e 0d 0a 20
          Data Ascii: <S T="10" /> </C> </C> <C T="U32" I="1" O="false" N="Count_CreateCard_ValidManager_False"> <C> <S T="11" /> </C> </C> <C T="U32" I="2" O="false" N="Count_CreateResult_ValidPersona_False"> <C> <S T="12" />
          2024-11-13 08:56:32 UTC16384INData Raw: 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 57 61 73 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6c 65 61 6e 75 70 4d 73 6f 50 65 72 73 6f 6e 61 5f 49 4d 73 6f 50 65 72 73 6f 6e
          Data Ascii: Paint_IMsoPersona_WasNull_Count"> <C> <S T="32" /> </C> </C> <C T="U32" I="20" O="false" N="Paint_IMsoPersona_Null_Count"> <C> <S T="33" /> </C> </C> <C T="U32" I="21" O="false" N="CleanupMsoPersona_IMsoPerson
          2024-11-13 08:56:33 UTC16384INData Raw: 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 30 30 22 20 54 3d 22 49 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63 6f 6e 64 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22
          Data Ascii: <R> <V V="200" T="I64" /> </R> </O> </L> <R> <O T="LT"> <L> <S T="3" F="RetrievalMilliseconds" /> </L> <R> <V V="400"
          2024-11-13 08:56:33 UTC16384INData Raw: 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 53 75 63 63 65 73 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 46 61 69 6c 65 64 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43
          Data Ascii: </S> <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount"> <C> <S T="9" /> </C> </C> <C T="U32" I="1" O="false" N="Ocom2IUCOfficeIntegrationFirstCallFailedCount"> <C> <S T="10" /> </C
          2024-11-13 08:56:33 UTC16384INData Raw: 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 54 65 6e 61 6e 74 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 55 73 65 72 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20
          Data Ascii: L> <S T="3" F="Tenant enabled" /> </L> <R> <O T="EQ"> <L> <S T="3" F="User enabled" /> </L> <R> <V V="false" T="B" /> </R>
          2024-11-13 08:56:33 UTC16384INData Raw: 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 34 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 48 74 74 70 53 74 61 74 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20
          Data Ascii: us" /> </L> <R> <V V="404" T="U32" /> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T="GE"> <L> <S T="2" F="HttpStatus" /> </L>


          Session IDSource IPSource PortDestination IPDestination Port
          1192.168.2.55535013.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:34 UTC192OUTGET /rules/rule224902v2s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:34 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:34 GMT
          Content-Type: text/xml
          Content-Length: 450
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:27:25 GMT
          ETag: "0x8DC582BD4C869AE"
          x-ms-request-id: b9f0e195-301e-0033-8068-35fa9c000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085634Z-1749fc9bdbdqhv2phC1DFWvd3000000000sg00000000434s
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:34 UTC450INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 62 72 35 71 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 61 33 36 61 39 37 30 64 2d 34 35 61 39 2d 34 65 30 64 2d 39 63 61 62 2d 32 61 32 33 35 63 63 39 64 37 63 36 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 47 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 4e
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224902" V="2" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120100" /> <UTS T="2" Id="bbr5q" /> <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" /> </S> <C T="G" I="0" O="falseN


          Session IDSource IPSource PortDestination IPDestination Port
          2192.168.2.55534913.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:34 UTC193OUTGET /rules/rule120402v21s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:34 UTC494INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:34 GMT
          Content-Type: text/xml
          Content-Length: 3788
          Connection: close
          Vary: Accept-Encoding
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
          ETag: "0x8DC582BAC2126A6"
          x-ms-request-id: 47cde2a8-501e-0047-01a2-34ce6c000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085634Z-1749fc9bdbdpg69chC1DFWhecg00000000n000000000a8k5
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:34 UTC3788INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 34 30 32 22 20 56 3d 22 32 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 6e 67 72 61 63 65 66 75 6c 41 70 70 45 78 69 74 44 65 73 6b 74 6f 70 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 22 20 78 6d 6c 6e 73 3d 22 22
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns=""


          Session IDSource IPSource PortDestination IPDestination Port
          3192.168.2.55535113.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:34 UTC192OUTGET /rules/rule120600v4s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:34 UTC494INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:34 GMT
          Content-Type: text/xml
          Content-Length: 2980
          Connection: close
          Vary: Accept-Encoding
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
          ETag: "0x8DC582BA80D96A1"
          x-ms-request-id: 26663d07-401e-0029-2faf-319b43000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085634Z-16547b76f7fr28cchC1DFWnuws0000000h0g000000006p8w
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:34 UTC2980INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 30 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 44 65 76 69 63 65 43 6f 6e 73 6f 6c 69 64 61 74 65 64 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC"


          Session IDSource IPSource PortDestination IPDestination Port
          4192.168.2.55535213.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:34 UTC192OUTGET /rules/rule120609v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:34 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:34 GMT
          Content-Type: text/xml
          Content-Length: 408
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
          ETag: "0x8DC582BB56D3AFB"
          x-ms-request-id: df0930aa-501e-00a3-28a3-34c0f2000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085634Z-r178fb8d765kzgrxhC1DFWrsuc00000000s000000000295z
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:34 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 44 64 5d 5b 45 65 5d 5b 4c 6c 5d 5b 4c 6c 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120609" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120682" /> <SR T="2" R="^([Dd][Ee][Ll][Ll])"> <S T="1" F="0" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


          Session IDSource IPSource PortDestination IPDestination Port
          5192.168.2.55535313.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:34 UTC192OUTGET /rules/rule120608v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:34 UTC517INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:34 GMT
          Content-Type: text/xml
          Content-Length: 2160
          Connection: close
          Vary: Accept-Encoding
          Vary: Accept-Encoding
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
          ETag: "0x8DC582BA3B95D81"
          x-ms-request-id: dcc6854f-e01e-0051-7b03-2d84b2000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085634Z-16547b76f7f2g4rlhC1DFWnx880000000gu0000000007azg
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:34 UTC2160INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 37 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 33 22 20 52 3d 22 31 32 30 36 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 36 31 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 35 22 20 52 3d 22 31 32 30 36 31 34 22 20 2f 3e 0d 0a 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120609" /> <R T="2" R="120679" /> <R T="3" R="120610" /> <R T="4" R="120612" /> <R T="5" R="120614" />


          Session IDSource IPSource PortDestination IPDestination Port
          6192.168.2.55535813.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:35 UTC192OUTGET /rules/rule120614v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:35 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:35 GMT
          Content-Type: text/xml
          Content-Length: 467
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
          ETag: "0x8DC582BA6C038BC"
          x-ms-request-id: a2886317-b01e-00ab-6c01-2ddafd000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085635Z-16547b76f7fxdzxghC1DFWmf7n0000000gwg00000000e2sa
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:35 UTC467INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120614" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          7192.168.2.55535413.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:35 UTC192OUTGET /rules/rule120610v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:35 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:35 GMT
          Content-Type: text/xml
          Content-Length: 474
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
          ETag: "0x8DC582B9964B277"
          x-ms-request-id: ee786005-101e-0065-140e-2d4088000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085635Z-16547b76f7fp46ndhC1DFW66zg0000000h1g000000001a8m
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:35 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120610" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          8192.168.2.55535513.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:35 UTC192OUTGET /rules/rule120611v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:35 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:35 GMT
          Content-Type: text/xml
          Content-Length: 415
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:56 GMT
          ETag: "0x8DC582B9F6F3512"
          x-ms-request-id: 1fd8da66-e01e-0052-0e78-35d9df000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085635Z-1749fc9bdbdjznvchC1DFWx4dc00000000sg00000000109k
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:35 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4c 6c 5d 5b 45 65 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 56 76 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120611" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


          Session IDSource IPSource PortDestination IPDestination Port
          9192.168.2.55535713.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:35 UTC192OUTGET /rules/rule120612v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:35 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:35 GMT
          Content-Type: text/xml
          Content-Length: 471
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:25 GMT
          ETag: "0x8DC582BB10C598B"
          x-ms-request-id: 42046764-d01e-0028-78a2-347896000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085635Z-r178fb8d765w8fzdhC1DFW8ep400000000u0000000002m3h
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:35 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120612" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          10192.168.2.55535613.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:35 UTC192OUTGET /rules/rule120613v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:35 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:35 GMT
          Content-Type: text/xml
          Content-Length: 632
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
          ETag: "0x8DC582BB6E3779E"
          x-ms-request-id: 23cb21e1-e01e-0052-4e08-2cd9df000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085635Z-16547b76f7f7scqbhC1DFW0m5w0000000gp000000000eepy
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:35 UTC632INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 48 68 5d 5b 50 70 5d 28 5b 5e 45 5d 7c 24 29 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 33 22 20 52 3d 22 28 5b 48 68 5d 5b 45 65 5d 5b 57 77 5d 5b 4c 6c 5d 5b 45 65 5d
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120613" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <SR T="2" R="^([Hh][Pp]([^E]|$))"> <S T="1" F="1" M="Ignore" /> </SR> <SR T="3" R="([Hh][Ee][Ww][Ll][Ee]


          Session IDSource IPSource PortDestination IPDestination Port
          11192.168.2.55536113.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120617v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:36 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:36 GMT
          Content-Type: text/xml
          Content-Length: 427
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:02 GMT
          ETag: "0x8DC582BA310DA18"
          x-ms-request-id: 7c20effc-801e-0015-04a3-34f97f000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085636Z-r178fb8d765d5f82hC1DFWsrm800000000t000000000mhra
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:36 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120617" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


          Session IDSource IPSource PortDestination IPDestination Port
          12192.168.2.55535913.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120615v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:36 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:36 GMT
          Content-Type: text/xml
          Content-Length: 407
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
          ETag: "0x8DC582BBAD04B7B"
          x-ms-request-id: 2e71ae26-601e-0097-6701-2df33a000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085636Z-16547b76f7fkj7j4hC1DFW0a9g0000000gx0000000005sr5
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:36 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 53 73 5d 5b 55 75 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120615" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <SR T="2" R="([Aa][Ss][Uu][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


          Session IDSource IPSource PortDestination IPDestination Port
          13192.168.2.55536013.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120616v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:36 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:36 GMT
          Content-Type: text/xml
          Content-Length: 486
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
          ETag: "0x8DC582BB344914B"
          x-ms-request-id: 7d8278ac-d01e-00ad-2054-35e942000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085636Z-1749fc9bdbdlzhmchC1DFWe68s00000000q00000000059dn
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:36 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120616" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          14192.168.2.55536213.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120618v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:36 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:36 GMT
          Content-Type: text/xml
          Content-Length: 486
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:30 GMT
          ETag: "0x8DC582B9018290B"
          x-ms-request-id: 2e9646c6-a01e-0098-2aa5-348556000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085636Z-r178fb8d7656shmjhC1DFWu5kw00000000t000000000a205
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:36 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120618" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          15192.168.2.55536313.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120619v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:36 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:36 GMT
          Content-Type: text/xml
          Content-Length: 407
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:41 GMT
          ETag: "0x8DC582B9698189B"
          x-ms-request-id: 636fa6f6-501e-0078-3aa7-3406cf000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085636Z-r178fb8d765dbczshC1DFW33an00000000hg00000000cbfz
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:36 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 43 63 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120619" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <SR T="2" R="([Aa][Cc][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


          Session IDSource IPSource PortDestination IPDestination Port
          16192.168.2.55536613.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120622v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 477
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
          ETag: "0x8DC582BB8CEAC16"
          x-ms-request-id: c860b0c2-d01e-007a-2fa3-34f38c000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-r178fb8d7652zbm6hC1DFWqtr400000000f0000000007a5e
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120622" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          17192.168.2.55536513.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120620v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 469
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
          ETag: "0x8DC582BBA701121"
          x-ms-request-id: 88f0aa43-e01e-0033-32a0-344695000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-1749fc9bdbdcm45lhC1DFWeab800000000mg00000000akt5
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120620" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          18192.168.2.55536413.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120621v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 415
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
          ETag: "0x8DC582BA41997E3"
          x-ms-request-id: 183719b9-d01e-00a1-43c3-2c35b1000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7f7lhvnhC1DFWa2k00000000gug000000005v2p
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 56 76 5d 5b 4d 6d 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120621" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


          Session IDSource IPSource PortDestination IPDestination Port
          19192.168.2.55536713.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:36 UTC192OUTGET /rules/rule120623v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 464
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
          ETag: "0x8DC582B97FB6C3C"
          x-ms-request-id: 63ea3643-901e-0015-3101-2db284000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7fcrtpchC1DFW52e80000000gy0000000008hb7
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC464INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 49 69 5d 5b 47 67 5d 5b 41 61 5d 5b 42 62 5d 5b 59 79 5d 5b 54 74 5d 5b 45 65 5d 20 5b 54 74 5d 5b 45 65 5d 5b 43 63 5d 5b 48 68 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 47 67 5d 5b 59 79 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120623" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])"> <S T="1" F="1" M="Ignor


          Session IDSource IPSource PortDestination IPDestination Port
          20192.168.2.55536813.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120624v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 494
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
          ETag: "0x8DC582BB7010D66"
          x-ms-request-id: 7f7db364-701e-005c-2f05-2dbb94000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7f7jnp2hC1DFWfc300000000h1g000000001ceb
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120624" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          21192.168.2.55536913.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120625v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 419
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:42 GMT
          ETag: "0x8DC582B9748630E"
          x-ms-request-id: cc46dee9-d01e-007a-0efd-2cf38c000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7fxdzxghC1DFWmf7n0000000h1g000000005hnq
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 46 66 5d 5b 55 75 5d 5b 4a 6a 5d 5b 49 69 5d 5b 54 74 5d 5b 53 73 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120625" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


          Session IDSource IPSource PortDestination IPDestination Port
          22192.168.2.55537113.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120627v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:37 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 404
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:54 GMT
          ETag: "0x8DC582B9E8EE0F3"
          x-ms-request-id: e44b56bd-701e-0053-1778-353a0a000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-1749fc9bdbdwv5sghC1DFWwp6n00000000rg000000001wq9
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:37 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4e 6e 5d 5b 45 65 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120627" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <SR T="2" R="^([Nn][Ee][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


          Session IDSource IPSource PortDestination IPDestination Port
          23192.168.2.55537013.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120626v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 472
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
          ETag: "0x8DC582B9DACDF62"
          x-ms-request-id: 7dbe6cd5-601e-00ab-1ca2-3466f4000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-r178fb8d765d5f82hC1DFWsrm800000000vg00000000b19w
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120626" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          24192.168.2.55537213.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120628v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 468
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
          ETag: "0x8DC582B9C8E04C8"
          x-ms-request-id: 1e45a1cf-401e-0029-3ef1-2c9b43000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7fr4g8xhC1DFW9cqc0000000g20000000008ya8
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120628" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          25192.168.2.55537313.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:37 UTC192OUTGET /rules/rule120629v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:37 GMT
          Content-Type: text/xml
          Content-Length: 428
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
          ETag: "0x8DC582BAC4F34CA"
          x-ms-request-id: 9f11ee7d-201e-0096-73f2-2cace6000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085637Z-16547b76f7fdf69shC1DFWcpd00000000grg00000000da52
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC428INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 2d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120629" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


          Session IDSource IPSource PortDestination IPDestination Port
          26192.168.2.55537513.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:38 UTC192OUTGET /rules/rule120631v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:38 GMT
          Content-Type: text/xml
          Content-Length: 415
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
          ETag: "0x8DC582B988EBD12"
          x-ms-request-id: 6d06536c-d01e-005a-3ca0-347fd9000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085638Z-1749fc9bdbdjgplnhC1DFWhrks00000000ng000000006z5g
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 48 68 5d 5b 55 75 5d 5b 41 61 5d 5b 57 77 5d 5b 45 65 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120631" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


          Session IDSource IPSource PortDestination IPDestination Port
          27192.168.2.55537413.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:38 UTC192OUTGET /rules/rule120630v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:38 GMT
          Content-Type: text/xml
          Content-Length: 499
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:25:45 GMT
          ETag: "0x8DC582B98CEC9F6"
          x-ms-request-id: 57085b9e-f01e-005d-1ca2-3413ba000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085638Z-r178fb8d765x865whC1DFWag6c00000000q000000000b67a
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC499INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120630" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          28192.168.2.55537613.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:38 UTC192OUTGET /rules/rule120632v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:38 GMT
          Content-Type: text/xml
          Content-Length: 471
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
          ETag: "0x8DC582BB5815C4C"
          x-ms-request-id: f61e936b-a01e-006f-0ea2-3413cd000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085638Z-r178fb8d765bflfthC1DFWuy9n00000000w00000000073zw
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          X-Cache-Info: L1_T2
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120632" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Session IDSource IPSource PortDestination IPDestination Port
          29192.168.2.55537713.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:38 UTC192OUTGET /rules/rule120633v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC491INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:38 GMT
          Content-Type: text/xml
          Content-Length: 419
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
          ETag: "0x8DC582BB32BB5CB"
          x-ms-request-id: d33f60ae-f01e-0085-74ec-2b88ea000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085638Z-16547b76f7fcjqqhhC1DFWrrrc0000000gxg000000005mwm
          x-fd-int-roxy-purgeid: 0
          X-Cache-Info: L1_T2
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 53 73 5d 5b 41 61 5d 5b 4d 6d 5d 5b 53 73 5d 5b 55 75 5d 5b 4e 6e 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120633" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


          Session IDSource IPSource PortDestination IPDestination Port
          30192.168.2.55537813.107.246.45443
          TimestampBytes transferredDirectionData
          2024-11-13 08:56:38 UTC192OUTGET /rules/rule120634v0s19.xml HTTP/1.1
          Connection: Keep-Alive
          Accept-Encoding: gzip
          User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
          Host: otelrules.azureedge.net
          2024-11-13 08:56:38 UTC470INHTTP/1.1 200 OK
          Date: Wed, 13 Nov 2024 08:56:38 GMT
          Content-Type: text/xml
          Content-Length: 494
          Connection: close
          Cache-Control: public, max-age=604800, immutable
          Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
          ETag: "0x8DC582BB8972972"
          x-ms-request-id: 2361c5fe-901e-0064-45f6-2ce8a6000000
          x-ms-version: 2018-03-28
          x-azure-ref: 20241113T085638Z-16547b76f7fdtmzhhC1DFW6zhc00000005v0000000003spz
          x-fd-int-roxy-purgeid: 0
          X-Cache: TCP_HIT
          Accept-Ranges: bytes
          2024-11-13 08:56:38 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
          Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120634" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:03:56:09
          Start date:13/11/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:03:56:12
          Start date:13/11/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1980,i,13586612571391427626,8045038456143489032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:03:56:14
          Start date:13/11/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.sgtllcsales.ae"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly