Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://ionl.ca

Overview

General Information

Sample URL:http://ionl.ca
Analysis ID:1580411
Infos:

Detection

Score:21
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

AI detected landing page (webpage, office document or email)
HTML page contains hidden javascript code
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5688 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6624 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=2004,i,7577569698952660962,12297675400179224436,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6308 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ionl.ca" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: http://ionl.ca/Joe Sandbox AI: Page contains button: 'CLICK HERE' Source: '1.0.pages.csv'
Source: http://ionl.ca/HTTP Parser: Base64 decoded: {"popupbox":{"id":"2","title":"Notice of Address Change","popup_name":"","description":"","category_id":"1","autoclose":"20","cookie":"43200","width":400,"height":500,"bgcolor":"#ffffff","textcolor":"#000000","bordersize":"1","bordercolor":"#ffffff","bord...
Source: http://ionl.ca/wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdfHTTP Parser: No favicon
Source: file:///C:/Users/user/Downloads/downloaded.pdfHTTP Parser: No favicon
Source: file:///C:/Users/user/Downloads/downloaded.pdfHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ionl.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/css/dist/block-library/style.min.css?ver=6.6.2 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/ays-popup-box/public/css/animate.css?ver=5.0.5 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/genericons/genericons.css?ver=3.4.1 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/style.css?ver=6.6.2 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/css/bootstrap.min.css?ver=20150930 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/css/bootstrap-theme.min.css?ver=20150930 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/style.css?ver=20150930 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=7.9 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/js_composer/custom.css?ver=7.9 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.5 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/circleFit.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/img/logo-top.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rbtools.min.js?rev=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.5 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/circleFit.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/img/logo-top.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/header01.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rbtools.min.js?rev=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/500-IMG_2508_855x525.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/mkt_workplace_810x440.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/header01.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/500-IMG_2508_855x525.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/ays-popup-box/public/css/ays-pb-public-min.css?ver=5.0.5 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/mkt_workplace_810x440.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/js/bootstrap.min.js?ver=20151204 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.17 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/js/skip-link-focus-fix.js?ver=20151112 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.9 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/img/facebook-30.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/wp-content/themes/prime/style.css?ver=20150930Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/js/skip-link-focus-fix.js?ver=20151112 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/js/bootstrap.min.js?ver=20151204 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.9 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/themes/prime/assets/img/facebook-30.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/bk-testimonials.jpg?id=551 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/installation-400x450.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/assets/loader.gif HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.17Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /track/ctin.php?t=1735044226030&custnum=c291e5e867c41a37&sname=ionl.ca&pagename=php5-cgi&group=%2Fservices%2Fwebpages%2Fi%2Fo%2Fionl.ca%2Fcgi-bin&version=%24Rev%3A%207840%20%24&js=1&jv=0&resolution=1280x1024&color_depth=24&campaign=&referrer=&page_url=http%253A%252F%252Fionl.ca%252F&plugins=PDF%20Viewer%3BChrome%20PDF%20Viewer%3BChromium%20PDF%20Viewer%3BMicrosoft%20Edge%20PDF%20Viewer%3BWebKit%20built-in%20PDF%3B HTTP/1.1Host: count.carrierzone.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/installation-400x450.jpg HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/revslider/public/assets/assets/loader.gif HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2016/11/bk-testimonials.jpg?id=551 HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222
Source: global trafficHTTP traffic detected: GET /track/ctin.php?t=1735044226030&custnum=c291e5e867c41a37&sname=ionl.ca&pagename=php5-cgi&group=%2Fservices%2Fwebpages%2Fi%2Fo%2Fionl.ca%2Fcgi-bin&version=%24Rev%3A%207840%20%24&js=1&jv=0&resolution=1280x1024&color_depth=24&campaign=&referrer=&page_url=http%253A%252F%252Fionl.ca%252F&plugins=PDF%20Viewer%3BChrome%20PDF%20Viewer%3BChromium%20PDF%20Viewer%3BMicrosoft%20Edge%20PDF%20Viewer%3BWebKit%20built-in%20PDF%3B HTTP/1.1Host: count.carrierzone.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon-32x32.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /favicon-16x16.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /favicon-96x96.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /android-icon-192x192.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /wp-admin/admin-ajax.php HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdf HTTP/1.1Host: ionl.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdfAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdf HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ionl.ca/wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdfAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficHTTP traffic detected: GET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1Host: ionl.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227
Source: global trafficDNS traffic detected: DNS query: ionl.ca
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: fast.fonts.net
Source: global trafficDNS traffic detected: DNS query: count.carrierzone.com
Source: unknownHTTP traffic detected: POST /wp-admin/admin-ajax.php HTTP/1.1Host: ionl.caConnection: keep-aliveContent-Length: 34Accept: text/plain, */*; q=0.01X-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencoded; charset=UTF-8Origin: http://ionl.caReferer: http://ionl.ca/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ays_popup_cookie_2=Notice%20of%20Address%20Change; ays_show_popup_only_once_2=Notice%20of%20Address%20Change; _ga_S9ESYSL6PQ=GS1.1.1735044222.1.0.1735044222.0.0.0; _ga=GA1.1.669240536.1735044222; __utma=212917772.669240536.1735044222.1735044227.1735044227.1; __utmc=212917772; __utmz=212917772.1735044227.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=212917772.1.10.1735044227Data Raw: 69 64 3d 32 26 61 63 74 69 6f 6e 3d 61 79 73 5f 69 6e 63 72 65 6d 65 6e 74 5f 70 62 5f 76 69 65 77 73 Data Ascii: id=2&action=ays_increment_pb_views
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 12:43:51 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Content-Encoding: gzipData Raw: 31 37 65 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 d5 5d eb 92 db 36 96 fe ad ae da 77 40 94 9a 91 14 8b 77 52 b7 be 64 1d c7 19 67 cb c9 78 c7 9e 71 4d d9 ae 2e 88 84 24 b6 29 92 21 a9 96 3a 3d 5d b5 af b1 af b7 4f b2 e7 00 bc 4a d4 bd b3 55 ab 6a 4b 24 70 2e 1f 0e 80 83 03 12 80 af be f9 f1 af af 3e fc f3 dd 6b 32 4b e6 de cd c5 15 fe 10 8f fa d3 eb 26 f3 a5 57 2f 9b c4 f6 68 1c 5f 37 fd 40 ba 8b 9b 48 c1 a8 73 73 d1 b8 b8 fa 46 92 c8 5f 82 60 ea 31 92 d0 29 69 4f e1 5b be 8b 3b 44 92 80 2c b6 23 37 4c 08 8d 1f 7c 9b c4 91 7d dd 9c 25 49 18 8f 14 65 b9 5c ca 53 ce 07 0c 73 ea d3 29 8b 64 3b 98 2b 28 40 b9 8b bf 77 9d eb bf 48 ef 87 af df ff f3 fd db de bb ff 6c de 5c 29 42 5a 2e f6 e6 82 90 a5 eb 3b c1 52 76 68 42 df d2 07 16 91 eb cd a4 7f fd 8b 7c fa 72 09 c4 93 85 6f 27 6e e0 13 d4 d1 ee 3c e6 24 72 b8 88 67 6d 1a 4d 17 73 e6 27 71 e7 f2 09 a8 39 51 eb 2e 6e 75 89 cf 96 e4 47 9a b0 76 a7 73 79 91 67 d9 81 3f 71 a7 90 dd 2a 03 6d 01 49 01 15 4c 44 e0 73 e5 b9 fe 57 12 31 ef ba 49 c3 d0 63 52 12 2c ec 99 e4 82 88 26 89 dd df 19 d8 d6 ea af ac 7e 93 cc 22 36 b9 6e 2a 82 0c 09 24 9e 21 87 fe b4 79 73 b0 b0 9e ba ea a9 75 c2 78 c6 91 c2 fa fa aa af d7 09 e3 19 c7 0a eb ad fa bd 5a 61 98 71 a4 30 4d 33 57 f0 af 4e 5c 9a 75 ac 40 5d 5d c1 bf 5a 81 22 eb 58 81 26 c0 30 eb 11 8a ac 63 05 5a fa 0a fe d5 0a 14 59 c7 0a 1c 40 b9 06 f5 45 16 59 f5 02 85 90 e4 21 64 70 3d 87 fe ab 20 59 2e 75 08 58 86 00 33 17 eb 3b 51 e0 3a a9 60 91 7b 8a 60 43 5f 19 45 e9 27 f4 9e 0b e4 a9 a7 88 1b f6 56 c3 de 86 38 9e 7a 8a 38 ad b7 d2 36 c5 f1 d4 7a 71 e0 fa dc 09 8b 93 9c 27 4b 00 27 0a 8a 52 fa 39 78 49 e2 d3 39 e8 9c c7 58 41 ae 4d d1 93 49 1f 5c 8f bd 0a bc 20 02 17 1d f8 09 78 af eb e6 b7 13 fe 39 88 f7 67 2c 41 89 57 99 c7 5b 1b 67 49 50 32 63 73 26 d9 3b 15 8b af 8b 86 e0 b3 67 34 8a 19 10 fd fd c3 4f d2 00 48 1a 65 79 f7 2e 5b 86 41 94 94 84 2d 5d 27 99 5d 3b 0c 2c c8 24 7e d3 25 ae ef 26 2e f5 a4 d8 a6 1e bb d6 b8 94 c2 94 61 14 4c a0 48 99 25 71 a4 81 81 66 3a 0f a7 72 10 4d 95 d5 c4 57 34 ce d3 c8 06 10 27 b0 b9 c7 97 b3 8b d7 1e e3 f7 7c b8 7b eb c6 09 f9 9e ec 27 92 a9 e3 b4 5b f7 21 8c 8d ad 0e 19 ed e1 f8 15 4a 4c 5e 5c 93 16 11 1c 97 a5 81 2d 71 13 8f dd bc 83 3a 21 7e 90 90 49 b0 f0 1d f2 e7 6f 07 ba a6 5d 92 9f 63 18 92 1d f2 d7 c9 04 4c 72 a5 08 da 8b 92 19 5b 51 30 0e 92 b8 95 1b b1 35 a7 2b 89 37 52 29 8c 18 1a 79 e4 c1 28 c7 5a 44 01 c6 dc 72 ad 38 79 f0 58 3c 63 2c 69 11 18 77 5b cb 50 1a 7b 81 fd 55 f2 dc 71 44 a3 07 c9 8e 41 2a 37 6b 2b 35 2b 34 20 4f b6 a9 02 a4 ae 6f 7b 0b 87 c5 0a 50 29 0e d8 43 a9 30 2b 5c ba 3c 77 7d 19 08 be bf 67 d1 75 4f ee c9 7a 4b 74 a2 56 c2 56 89 c2 15 cc 99 e3 d2 eb 16 f5 3c 01 90 33 72 40 dc 70 ae 2d 89 76 27 e0 82 5e 28 01 13 d8 d6 44 dd 5c
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 12:43:53 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Content-Encoding: gzipData Raw: 31 37 65 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 d5 5d eb 92 db 36 96 fe ad ae da 77 40 94 9a 91 14 8b 77 52 b7 be 64 1d c7 19 67 cb c9 78 c7 9e 71 4d d9 ae 2e 88 84 24 b6 29 92 21 a9 96 3a 3d 5d b5 af b1 af b7 4f b2 e7 00 bc 4a d4 bd b3 55 ab 6a 4b 24 70 2e 1f 0e 80 83 03 12 80 af be f9 f1 af af 3e fc f3 dd 6b 32 4b e6 de cd c5 15 fe 10 8f fa d3 eb 26 f3 a5 57 2f 9b c4 f6 68 1c 5f 37 fd 40 ba 8b 9b 48 c1 a8 73 73 d1 b8 b8 fa 46 92 c8 5f 82 60 ea 31 92 d0 29 69 4f e1 5b be 8b 3b 44 92 80 2c b6 23 37 4c 08 8d 1f 7c 9b c4 91 7d dd 9c 25 49 18 8f 14 65 b9 5c ca 53 ce 07 0c 73 ea d3 29 8b 64 3b 98 2b 28 40 b9 8b bf 77 9d eb bf 48 ef 87 af df ff f3 fd db de bb ff 6c de 5c 29 42 5a 2e f6 e6 82 90 a5 eb 3b c1 52 76 68 42 df d2 07 16 91 eb cd a4 7f fd 8b 7c fa 72 09 c4 93 85 6f 27 6e e0 13 d4 d1 ee 3c e6 24 72 b8 88 67 6d 1a 4d 17 73 e6 27 71 e7 f2 09 a8 39 51 eb 2e 6e 75 89 cf 96 e4 47 9a b0 76 a7 73 79 91 67 d9 81 3f 71 a7 90 dd 2a 03 6d 01 49 01 15 4c 44 e0 73 e5 b9 fe 57 12 31 ef ba 49 c3 d0 63 52 12 2c ec 99 e4 82 88 26 89 dd df 19 d8 d6 ea af ac 7e 93 cc 22 36 b9 6e 2a 82 0c 09 24 9e 21 87 fe b4 79 73 b0 b0 9e ba ea a9 75 c2 78 c6 91 c2 fa fa aa af d7 09 e3 19 c7 0a eb ad fa bd 5a 61 98 71 a4 30 4d 33 57 f0 af 4e 5c 9a 75 ac 40 5d 5d c1 bf 5a 81 22 eb 58 81 26 c0 30 eb 11 8a ac 63 05 5a fa 0a fe d5 0a 14 59 c7 0a 1c 40 b9 06 f5 45 16 59 f5 02 85 90 e4 21 64 70 3d 87 fe ab 20 59 2e 75 08 58 86 00 33 17 eb 3b 51 e0 3a a9 60 91 7b 8a 60 43 5f 19 45 e9 27 f4 9e 0b e4 a9 a7 88 1b f6 56 c3 de 86 38 9e 7a 8a 38 ad b7 d2 36 c5 f1 d4 7a 71 e0 fa dc 09 8b 93 9c 27 4b 00 27 0a 8a 52 fa 39 78 49 e2 d3 39 e8 9c c7 58 41 ae 4d d1 93 49 1f 5c 8f bd 0a bc 20 02 17 1d f8 09 78 af eb e6 b7 13 fe 39 88 f7 67 2c 41 89 57 99 c7 5b 1b 67 49 50 32 63 73 26 d9 3b 15 8b af 8b 86 e0 b3 67 34 8a 19 10 fd fd c3 4f d2 00 48 1a 65 79 f7 2e 5b 86 41 94 94 84 2d 5d 27 99 5d 3b 0c 2c c8 24 7e d3 25 ae ef 26 2e f5 a4 d8 a6 1e bb d6 b8 94 c2 94 61 14 4c a0 48 99 25 71 a4 81 81 66 3a 0f a7 72 10 4d 95 d5 c4 57 34 ce d3 c8 06 10 27 b0 b9 c7 97 b3 8b d7 1e e3 f7 7c b8 7b eb c6 09 f9 9e ec 27 92 a9 e3 b4 5b f7 21 8c 8d ad 0e 19 ed e1 f8 15 4a 4c 5e 5c 93 16 11 1c 97 a5 81 2d 71 13 8f dd bc 83 3a 21 7e 90 90 49 b0 f0 1d f2 e7 6f 07 ba a6 5d 92 9f 63 18 92 1d f2 d7 c9 04 4c 72 a5 08 da 8b 92 19 5b 51 30 0e 92 b8 95 1b b1 35 a7 2b 89 37 52 29 8c 18 1a 79 e4 c1 28 c7 5a 44 01 c6 dc 72 ad 38 79 f0 58 3c 63 2c 69 11 18 77 5b cb 50 1a 7b 81 fd 55 f2 dc 71 44 a3 07 c9 8e 41 2a 37 6b 2b 35 2b 34 20 4f b6 a9 02 a4 ae 6f 7b 0b 87 c5 0a 50 29 0e d8 43 a9 30 2b 5c ba 3c 77 7d 19 08 be bf 67 d1 75 4f ee c9 7a 4b 74 a2 56 c2 56 89 c2 15 cc 99 e3 d2 eb 16 f5 3c 01 90 33 72 40 dc 70 ae 2d 89 76 27 e0 82 5e 28 01 13 d8 d6 44 dd 5c
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 12:43:55 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Content-Encoding: gzipData Raw: 31 37 65 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 d5 5d eb 92 db 36 96 fe ad ae da 77 40 94 9a 91 14 8b 77 52 b7 be 64 1d c7 19 67 cb c9 78 c7 9e 71 4d d9 ae 2e 88 84 24 b6 29 92 21 a9 96 3a 3d 5d b5 af b1 af b7 4f b2 e7 00 bc 4a d4 bd b3 55 ab 6a 4b 24 70 2e 1f 0e 80 83 03 12 80 af be f9 f1 af af 3e fc f3 dd 6b 32 4b e6 de cd c5 15 fe 10 8f fa d3 eb 26 f3 a5 57 2f 9b c4 f6 68 1c 5f 37 fd 40 ba 8b 9b 48 c1 a8 73 73 d1 b8 b8 fa 46 92 c8 5f 82 60 ea 31 92 d0 29 69 4f e1 5b be 8b 3b 44 92 80 2c b6 23 37 4c 08 8d 1f 7c 9b c4 91 7d dd 9c 25 49 18 8f 14 65 b9 5c ca 53 ce 07 0c 73 ea d3 29 8b 64 3b 98 2b 28 40 b9 8b bf 77 9d eb bf 48 ef 87 af df ff f3 fd db de bb ff 6c de 5c 29 42 5a 2e f6 e6 82 90 a5 eb 3b c1 52 76 68 42 df d2 07 16 91 eb cd a4 7f fd 8b 7c fa 72 09 c4 93 85 6f 27 6e e0 13 d4 d1 ee 3c e6 24 72 b8 88 67 6d 1a 4d 17 73 e6 27 71 e7 f2 09 a8 39 51 eb 2e 6e 75 89 cf 96 e4 47 9a b0 76 a7 73 79 91 67 d9 81 3f 71 a7 90 dd 2a 03 6d 01 49 01 15 4c 44 e0 73 e5 b9 fe 57 12 31 ef ba 49 c3 d0 63 52 12 2c ec 99 e4 82 88 26 89 dd df 19 d8 d6 ea af ac 7e 93 cc 22 36 b9 6e 2a 82 0c 09 24 9e 21 87 fe b4 79 73 b0 b0 9e ba ea a9 75 c2 78 c6 91 c2 fa fa aa af d7 09 e3 19 c7 0a eb ad fa bd 5a 61 98 71 a4 30 4d 33 57 f0 af 4e 5c 9a 75 ac 40 5d 5d c1 bf 5a 81 22 eb 58 81 26 c0 30 eb 11 8a ac 63 05 5a fa 0a fe d5 0a 14 59 c7 0a 1c 40 b9 06 f5 45 16 59 f5 02 85 90 e4 21 64 70 3d 87 fe ab 20 59 2e 75 08 58 86 00 33 17 eb 3b 51 e0 3a a9 60 91 7b 8a 60 43 5f 19 45 e9 27 f4 9e 0b e4 a9 a7 88 1b f6 56 c3 de 86 38 9e 7a 8a 38 ad b7 d2 36 c5 f1 d4 7a 71 e0 fa dc 09 8b 93 9c 27 4b 00 27 0a 8a 52 fa 39 78 49 e2 d3 39 e8 9c c7 58 41 ae 4d d1 93 49 1f 5c 8f bd 0a bc 20 02 17 1d f8 09 78 af eb e6 b7 13 fe 39 88 f7 67 2c 41 89 57 99 c7 5b 1b 67 49 50 32 63 73 26 d9 3b 15 8b af 8b 86 e0 b3 67 34 8a 19 10 fd fd c3 4f d2 00 48 1a 65 79 f7 2e 5b 86 41 94 94 84 2d 5d 27 99 5d 3b 0c 2c c8 24 7e d3 25 ae ef 26 2e f5 a4 d8 a6 1e bb d6 b8 94 c2 94 61 14 4c a0 48 99 25 71 a4 81 81 66 3a 0f a7 72 10 4d 95 d5 c4 57 34 ce d3 c8 06 10 27 b0 b9 c7 97 b3 8b d7 1e e3 f7 7c b8 7b eb c6 09 f9 9e ec 27 92 a9 e3 b4 5b f7 21 8c 8d ad 0e 19 ed e1 f8 15 4a 4c 5e 5c 93 16 11 1c 97 a5 81 2d 71 13 8f dd bc 83 3a 21 7e 90 90 49 b0 f0 1d f2 e7 6f 07 ba a6 5d 92 9f 63 18 92 1d f2 d7 c9 04 4c 72 a5 08 da 8b 92 19 5b 51 30 0e 92 b8 95 1b b1 35 a7 2b 89 37 52 29 8c 18 1a 79 e4 c1 28 c7 5a 44 01 c6 dc 72 ad 38 79 f0 58 3c 63 2c 69 11 18 77 5b cb 50 1a 7b 81 fd 55 f2 dc 71 44 a3 07 c9 8e 41 2a 37 6b 2b 35 2b 34 20 4f b6 a9 02 a4 ae 6f 7b 0b 87 c5 0a 50 29 0e d8 43 a9 30 2b 5c ba 3c 77 7d 19 08 be bf 67 d1 75 4f ee c9 7a 4b 74 a2 56 c2 56 89 c2 15 cc 99 e3 d2 eb 16 f5 3c 01 90 33 72 40 dc 70 ae 2d 89 76 27 e0 82 5e 28 01 13 d8 d6 44 dd 5c
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 12:43:56 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Content-Encoding: gzipData Raw: 31 37 65 37 0d 0a 1f 8b 08 00 00 00 00 00 00 03 d5 5d eb 92 db 36 96 fe ad ae da 77 40 94 9a 91 14 8b 77 52 b7 be 64 1d c7 19 67 cb c9 78 c7 9e 71 4d d9 ae 2e 88 84 24 b6 29 92 21 a9 96 3a 3d 5d b5 af b1 af b7 4f b2 e7 00 bc 4a d4 bd b3 55 ab 6a 4b 24 70 2e 1f 0e 80 83 03 12 80 af be f9 f1 af af 3e fc f3 dd 6b 32 4b e6 de cd c5 15 fe 10 8f fa d3 eb 26 f3 a5 57 2f 9b c4 f6 68 1c 5f 37 fd 40 ba 8b 9b 48 c1 a8 73 73 d1 b8 b8 fa 46 92 c8 5f 82 60 ea 31 92 d0 29 69 4f e1 5b be 8b 3b 44 92 80 2c b6 23 37 4c 08 8d 1f 7c 9b c4 91 7d dd 9c 25 49 18 8f 14 65 b9 5c ca 53 ce 07 0c 73 ea d3 29 8b 64 3b 98 2b 28 40 b9 8b bf 77 9d eb bf 48 ef 87 af df ff f3 fd db de bb ff 6c de 5c 29 42 5a 2e f6 e6 82 90 a5 eb 3b c1 52 76 68 42 df d2 07 16 91 eb cd a4 7f fd 8b 7c fa 72 09 c4 93 85 6f 27 6e e0 13 d4 d1 ee 3c e6 24 72 b8 88 67 6d 1a 4d 17 73 e6 27 71 e7 f2 09 a8 39 51 eb 2e 6e 75 89 cf 96 e4 47 9a b0 76 a7 73 79 91 67 d9 81 3f 71 a7 90 dd 2a 03 6d 01 49 01 15 4c 44 e0 73 e5 b9 fe 57 12 31 ef ba 49 c3 d0 63 52 12 2c ec 99 e4 82 88 26 89 dd df 19 d8 d6 ea af ac 7e 93 cc 22 36 b9 6e 2a 82 0c 09 24 9e 21 87 fe b4 79 73 b0 b0 9e ba ea a9 75 c2 78 c6 91 c2 fa fa aa af d7 09 e3 19 c7 0a eb ad fa bd 5a 61 98 71 a4 30 4d 33 57 f0 af 4e 5c 9a 75 ac 40 5d 5d c1 bf 5a 81 22 eb 58 81 26 c0 30 eb 11 8a ac 63 05 5a fa 0a fe d5 0a 14 59 c7 0a 1c 40 b9 06 f5 45 16 59 f5 02 85 90 e4 21 64 70 3d 87 fe ab 20 59 2e 75 08 58 86 00 33 17 eb 3b 51 e0 3a a9 60 91 7b 8a 60 43 5f 19 45 e9 27 f4 9e 0b e4 a9 a7 88 1b f6 56 c3 de 86 38 9e 7a 8a 38 ad b7 d2 36 c5 f1 d4 7a 71 e0 fa dc 09 8b 93 9c 27 4b 00 27 0a 8a 52 fa 39 78 49 e2 d3 39 e8 9c c7 58 41 ae 4d d1 93 49 1f 5c 8f bd 0a bc 20 02 17 1d f8 09 78 af eb e6 b7 13 fe 39 88 f7 67 2c 41 89 57 99 c7 5b 1b 67 49 50 32 63 73 26 d9 3b 15 8b af 8b 86 e0 b3 67 34 8a 19 10 fd fd c3 4f d2 00 48 1a 65 79 f7 2e 5b 86 41 94 94 84 2d 5d 27 99 5d 3b 0c 2c c8 24 7e d3 25 ae ef 26 2e f5 a4 d8 a6 1e bb d6 b8 94 c2 94 61 14 4c a0 48 99 25 71 a4 81 81 66 3a 0f a7 72 10 4d 95 d5 c4 57 34 ce d3 c8 06 10 27 b0 b9 c7 97 b3 8b d7 1e e3 f7 7c b8 7b eb c6 09 f9 9e ec 27 92 a9 e3 b4 5b f7 21 8c 8d ad 0e 19 ed e1 f8 15 4a 4c 5e 5c 93 16 11 1c 97 a5 81 2d 71 13 8f dd bc 83 3a 21 7e 90 90 49 b0 f0 1d f2 e7 6f 07 ba a6 5d 92 9f 63 18 92 1d f2 d7 c9 04 4c 72 a5 08 da 8b 92 19 5b 51 30 0e 92 b8 95 1b b1 35 a7 2b 89 37 52 29 8c 18 1a 79 e4 c1 28 c7 5a 44 01 c6 dc 72 ad 38 79 f0 58 3c 63 2c 69 11 18 77 5b cb 50 1a 7b 81 fd 55 f2 dc 71 44 a3 07 c9 8e 41 2a 37 6b 2b 35 2b 34 20 4f b6 a9 02 a4 ae 6f 7b 0b 87 c5 0a 50 29 0e d8 43 a9 30 2b 5c ba 3c 77 7d 19 08 be bf 67 d1 75 4f ee c9 7a 4b 74 a2 56 c2 56 89 c2 15 cc 99 e3 d2 eb 16 f5 3c 01 90 33 72 40 dc 70 ae 2d 89 76 27 e0 82 5e 28 01 13 d8 d6 44 dd 5c
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: classification engineClassification label: sus21.win@26/47@20/187
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=2004,i,7577569698952660962,12297675400179224436,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ionl.ca"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=2004,i,7577569698952660962,12297675400179224436,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ionl.ca0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ionl.ca/wp-includes/js/jquery/jquery.min.js?ver=3.7.10%Avira URL Cloudsafe
http://ionl.ca/wp-includes/css/dist/block-library/style.min.css?ver=6.6.20%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=7.90%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap.min.css?ver=201509300%Avira URL Cloudsafe
http://ionl.ca/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.10%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/genericons/genericons.css?ver=3.4.10%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/style.css?ver=6.6.20%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap-theme.min.css?ver=201509300%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.50%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/style.css?ver=201509300%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.170%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/animate.css?ver=5.0.50%Avira URL Cloudsafe
http://ionl.ca/0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/circleFit.png0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/js_composer/custom.css?ver=7.90%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/bk-testimonials.jpg?id=5510%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.170%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/assets/loader.gif0%Avira URL Cloudsafe
http://ionl.ca/favicon-16x16.png0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/500-IMG_2508_855x525.jpg0%Avira URL Cloudsafe
http://ionl.ca/favicon-32x32.png0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/header01.jpg0%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.170%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/ays-pb-public-min.css?ver=5.0.50%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/js/skip-link-focus-fix.js?ver=201511120%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/js/bootstrap.min.js?ver=201512040%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.170%Avira URL Cloudsafe
http://count.carrierzone.com/track/ctin.php?t=1735044226030&custnum=c291e5e867c41a37&sname=ionl.ca&pagename=php5-cgi&group=%2Fservices%2Fwebpages%2Fi%2Fo%2Fionl.ca%2Fcgi-bin&version=%24Rev%3A%207840%20%24&js=1&jv=0&resolution=1280x1024&color_depth=24&campaign=&referrer=&page_url=http%253A%252F%252Fionl.ca%252F&plugins=PDF%20Viewer%3BChrome%20PDF%20Viewer%3BChromium%20PDF%20Viewer%3BMicrosoft%20Edge%20PDF%20Viewer%3BWebKit%20built-in%20PDF%3B0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/mkt_workplace_810x440.jpg0%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?rev=6.2.170%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/img/logo-top.png0%Avira URL Cloudsafe
http://ionl.ca/wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.90%Avira URL Cloudsafe
http://ionl.ca/wp-content/themes/prime/assets/img/facebook-30.png0%Avira URL Cloudsafe
http://ionl.ca/wp-content/uploads/2016/11/installation-400x450.jpg0%Avira URL Cloudsafe
http://ionl.ca/android-icon-192x192.png0%Avira URL Cloudsafe
http://ionl.ca/favicon-96x96.png0%Avira URL Cloudsafe
http://ionl.ca/wp-admin/admin-ajax.php0%Avira URL Cloudsafe
http://ionl.ca/wp-includes/images/w-logo-blue-white-bg.png0%Avira URL Cloudsafe
http://ionl.ca/favicon.ico0%Avira URL Cloudsafe
file:///C:/Users/user/Downloads/downloaded.pdf0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
ionl.ca
69.49.101.51
truefalse
    high
    fast.fonts.net
    104.16.40.28
    truefalse
      high
      www.google.com
      172.217.21.36
      truefalse
        high
        count.carrierzone.com
        66.175.41.113
        truefalse
          high
          NameMaliciousAntivirus DetectionReputation
          http://ionl.ca/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=7.9true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/uploads/2016/11/bk-testimonials.jpg?id=551true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/favicon-32x32.pngtrue
          • Avira URL Cloud: safe
          unknown
          file:///C:/Users/user/Downloads/downloaded.pdffalse
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/plugins/revslider/public/assets/assets/loader.giftrue
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap.min.css?ver=20150930true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/themes/prime/style.css?ver=20150930true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.17true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/themes/prime/assets/js/skip-link-focus-fix.js?ver=20151112true
          • Avira URL Cloud: safe
          unknown
          http://ionl.ca/wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdftrue
            unknown
            http://ionl.ca/favicon-16x16.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/2016/11/header01.jpgtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/favicon-96x96.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/animate.css?ver=5.0.5true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/ays-pb-public-min.css?ver=5.0.5true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/js_composer/custom.css?ver=7.9true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/2016/11/500-IMG_2508_855x525.jpgtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/2016/11/circleFit.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.17true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-includes/images/w-logo-blue-white-bg.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/assets/img/logo-top.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-admin/admin-ajax.phptrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/assets/img/facebook-30.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/assets/js/bootstrap.min.js?ver=20151204true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?rev=6.2.17true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/android-icon-192x192.pngtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.5true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/2016/11/mkt_workplace_810x440.jpgtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-includes/js/jquery/jquery.min.js?ver=3.7.1true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/assets/genericons/genericons.css?ver=3.4.1true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/style.css?ver=6.6.2true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/uploads/2016/11/installation-400x450.jpgtrue
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap-theme.min.css?ver=20150930true
            • Avira URL Cloud: safe
            unknown
            http://count.carrierzone.com/track/ctin.php?t=1735044226030&custnum=c291e5e867c41a37&sname=ionl.ca&pagename=php5-cgi&group=%2Fservices%2Fwebpages%2Fi%2Fo%2Fionl.ca%2Fcgi-bin&version=%24Rev%3A%207840%20%24&js=1&jv=0&resolution=1280x1024&color_depth=24&campaign=&referrer=&page_url=http%253A%252F%252Fionl.ca%252F&plugins=PDF%20Viewer%3BChrome%20PDF%20Viewer%3BChromium%20PDF%20Viewer%3BMicrosoft%20Edge%20PDF%20Viewer%3BWebKit%20built-in%20PDF%3Bfalse
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.17true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.17true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.9true
            • Avira URL Cloud: safe
            unknown
            http://ionl.ca/favicon.icotrue
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            172.217.19.206
            unknownUnited States
            15169GOOGLEUSfalse
            172.217.19.238
            unknownUnited States
            15169GOOGLEUSfalse
            1.1.1.1
            unknownAustralia
            13335CLOUDFLARENETUSfalse
            172.217.17.35
            unknownUnited States
            15169GOOGLEUSfalse
            216.58.208.227
            unknownUnited States
            15169GOOGLEUSfalse
            69.49.101.51
            ionl.caUnited States
            14116INFB-ASUSfalse
            142.250.181.104
            unknownUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            66.175.41.113
            count.carrierzone.comUnited States
            30447INFB2-ASUSfalse
            172.217.21.35
            unknownUnited States
            15169GOOGLEUSfalse
            64.233.161.84
            unknownUnited States
            15169GOOGLEUSfalse
            172.217.17.40
            unknownUnited States
            15169GOOGLEUSfalse
            172.217.21.36
            www.google.comUnited States
            15169GOOGLEUSfalse
            142.250.181.78
            unknownUnited States
            15169GOOGLEUSfalse
            172.217.19.10
            unknownUnited States
            15169GOOGLEUSfalse
            216.239.36.178
            unknownUnited States
            15169GOOGLEUSfalse
            104.16.40.28
            fast.fonts.netUnited States
            13335CLOUDFLARENETUSfalse
            IP
            192.168.2.17
            192.168.2.16
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1580411
            Start date and time:2024-12-24 13:43:04 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowsinteractivecookbook.jbs
            Sample URL:http://ionl.ca
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:13
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            Analysis Mode:stream
            Analysis stop reason:Timeout
            Detection:SUS
            Classification:sus21.win@26/47@20/187
            • Exclude process from analysis (whitelisted): svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.21.35, 172.217.19.238, 64.233.161.84, 172.217.17.46, 199.232.214.172, 172.217.17.40, 172.217.19.10
            • Excluded domains from analysis (whitelisted): fonts.googleapis.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, www.googletagmanager.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
            • VT rate limit hit for: http://ionl.ca
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2673
            Entropy (8bit):3.9723923214103762
            Encrypted:false
            SSDEEP:
            MD5:736526DBC2FC95304429371D348650EA
            SHA1:9E81080B7F01A75E3AD3338087811CE2B4BFF633
            SHA-256:64354915FD550478DD5BDA7D78167F215FF35C002F475172C45BD0B085CE0A8D
            SHA-512:DFD50F01068B7897698BABD6AC798D4E29418F40E0AB84A64623F143AD6727E87A182D03448E0CFA0ED7059302FD8FB7CCC146343138EEA968579A21A798593C
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,......mr.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yre...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2675
            Entropy (8bit):3.9913988421715305
            Encrypted:false
            SSDEEP:
            MD5:E85DA4D5305AE65F436BAD239807A8F1
            SHA1:244B5BDAD9FAE733F9FC09D97B8FBF65DD577713
            SHA-256:34649C82E2022A87BC63B7EC964849F3183F4C7CA2DE9CA76656F6CC0DB70501
            SHA-512:085EAF7824C02D1E6B9BCA279CEBFA38E96782CB4739FF57590D0716615E45A40E723882A34F7F50A5746B5DCD22A9865A89874A0050FA89954DD37D8D8B7CDD
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,....(.br.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yre...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2689
            Entropy (8bit):4.005017355763925
            Encrypted:false
            SSDEEP:
            MD5:8145CBBE82F6F59CAFE701B251F2F35E
            SHA1:31688602A0211B8B04414723E38E787CDE17FDFB
            SHA-256:568907DF9A96382059AAF03203D2FE6BDFA99ADC1C58F10922FD0294CBB417C8
            SHA-512:04975688B0EA63713CB0A3A1A69E9A935F4E21E4E055D01E97F9D92954A9AE8C48147F9BC919728B3332755F8F5092A375AC499FC8B49A88F5A5A3B8E53F1FE4
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9915706186105058
            Encrypted:false
            SSDEEP:
            MD5:FEEA20E66ED4D285E367EDB3BC439FBE
            SHA1:C31250D263B9A20EDEBE503B1AC6A1307B0183FA
            SHA-256:88A5CE875AE67BBA99B52F62253588E2A9980CDDA7C6C0FB1D0AAA8B6AC8C61D
            SHA-512:5EF032B0FD58C5475985143870F961C0D5014AEA4DE7CC8889182F18E17A1417E26E42B76528D7F4F972F14FF561FF514CCAD48185E912392417E374A8D3A467
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,......[r.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yre...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.977586268103821
            Encrypted:false
            SSDEEP:
            MD5:721F6A00DCEADAB3AD5F078E909A0266
            SHA1:FBD1B3177EE23BC660D66EBFB624B7B69FF0F1F1
            SHA-256:4D3BD8BC945E3AF6A0154D04D4F4BF327A02301AFC1F1E885D11770A927AF474
            SHA-512:82C390B040707750F6EF25DE232B5E0F0D4495BC201734286C9E2E2EABFF019450584C39DC26452EFC8D8A5DC5ABE70DA5F9DAF23E55AB65CA34D7B164B56156
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,......hr.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yre...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.9864647407183207
            Encrypted:false
            SSDEEP:
            MD5:55847041CDA5426E61E162613DEAC6C5
            SHA1:69569A42F051172D3079D7B6DB8783A61E89B1C0
            SHA-256:1796F0E39E31F39AF5EED5B2A9C84575EF384E34137267E0CF0A600461F9FB06
            SHA-512:60D372A7F192ABD776F149A3ABF4B94EFF42633D098C8E6E0D720FA8ACBB54F37DA526E7BB5025DD7BCD0B86F6741D020C76534A759439E6742FDDF0C69D616A
            Malicious:false
            Reputation:unknown
            Preview:L..................F.@.. ...$+.,......Qr.V..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yie....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Yqe....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Yqe....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Yqe..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Yre...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............,......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PDF document, version 1.7
            Category:dropped
            Size (bytes):0
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:
            MD5:F7293B5066383E7764AD217F4BF9A35F
            SHA1:2C0BF5F9F035D0ABC599DB59FF2695CEBEC8909B
            SHA-256:2310AFC2B0363D5EB7AF75618BEDBDF97D91CA452E8FEB517B298A0EE61D5F90
            SHA-512:3D6C24035FA7E9154F90BFC29753B9C53EB683CAC1D969BCB4D85EECE1EB77BD061075312CA4B695BA0C8580BF3AA216E57F43DDB2D470DEBD453CFE270EE5A9
            Malicious:false
            Reputation:unknown
            Preview:%PDF-1.7.%......199 0 obj.<</Linearized 1/L 4697417/O 209/E 941264/N 6/T 4693321/H [ 1096 487]>>.endobj. .xref..199 40..0000000016 00000 n..0000001583 00000 n..0000001874 00000 n..0000001918 00000 n..0000002001 00000 n..0000002075 00000 n..0000002149 00000 n..0000002181 00000 n..0000002278 00000 n..0000002305 00000 n..0000002490 00000 n..0000003618 00000 n..0000003827 00000 n..0000004060 00000 n..0000004353 00000 n..0000004747 00000 n..0000004784 00000 n..0000005168 00000 n..0000005282 00000 n..0000005394 00000 n..0000005732 00000 n..0000006068 00000 n..0000008823 00000 n..0000010809 00000 n..0000012876 00000 n..0000015525 00000 n..0000016320 00000 n..0000016576 00000 n..0000017731 00000 n..0000018028 00000 n..0000018360 00000 n..0000056709 00000 n..0000056748 00000 n..0000108873 00000 n..0000108912 00000 n..0000111825 00000 n..0000114738 00000 n..0000205692 00000 n..0000941205 00000 n..0000001096 00000 n..trailer.<</Size 239/Root 200 0 R/Info 198 0 R/ID[<4233CB1FCBC94F52B532
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PDF document, version 1.7
            Category:dropped
            Size (bytes):0
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:
            MD5:F7293B5066383E7764AD217F4BF9A35F
            SHA1:2C0BF5F9F035D0ABC599DB59FF2695CEBEC8909B
            SHA-256:2310AFC2B0363D5EB7AF75618BEDBDF97D91CA452E8FEB517B298A0EE61D5F90
            SHA-512:3D6C24035FA7E9154F90BFC29753B9C53EB683CAC1D969BCB4D85EECE1EB77BD061075312CA4B695BA0C8580BF3AA216E57F43DDB2D470DEBD453CFE270EE5A9
            Malicious:false
            Reputation:unknown
            Preview:%PDF-1.7.%......199 0 obj.<</Linearized 1/L 4697417/O 209/E 941264/N 6/T 4693321/H [ 1096 487]>>.endobj. .xref..199 40..0000000016 00000 n..0000001583 00000 n..0000001874 00000 n..0000001918 00000 n..0000002001 00000 n..0000002075 00000 n..0000002149 00000 n..0000002181 00000 n..0000002278 00000 n..0000002305 00000 n..0000002490 00000 n..0000003618 00000 n..0000003827 00000 n..0000004060 00000 n..0000004353 00000 n..0000004747 00000 n..0000004784 00000 n..0000005168 00000 n..0000005282 00000 n..0000005394 00000 n..0000005732 00000 n..0000006068 00000 n..0000008823 00000 n..0000010809 00000 n..0000012876 00000 n..0000015525 00000 n..0000016320 00000 n..0000016576 00000 n..0000017731 00000 n..0000018028 00000 n..0000018360 00000 n..0000056709 00000 n..0000056748 00000 n..0000108873 00000 n..0000108912 00000 n..0000111825 00000 n..0000114738 00000 n..0000205692 00000 n..0000941205 00000 n..0000001096 00000 n..trailer.<</Size 239/Root 200 0 R/Info 198 0 R/ID[<4233CB1FCBC94F52B532
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PDF document, version 1.7
            Category:dropped
            Size (bytes):4060
            Entropy (8bit):5.3686552660441675
            Encrypted:false
            SSDEEP:
            MD5:F7293B5066383E7764AD217F4BF9A35F
            SHA1:2C0BF5F9F035D0ABC599DB59FF2695CEBEC8909B
            SHA-256:2310AFC2B0363D5EB7AF75618BEDBDF97D91CA452E8FEB517B298A0EE61D5F90
            SHA-512:3D6C24035FA7E9154F90BFC29753B9C53EB683CAC1D969BCB4D85EECE1EB77BD061075312CA4B695BA0C8580BF3AA216E57F43DDB2D470DEBD453CFE270EE5A9
            Malicious:false
            Reputation:unknown
            Preview:%PDF-1.7.%......199 0 obj.<</Linearized 1/L 4697417/O 209/E 941264/N 6/T 4693321/H [ 1096 487]>>.endobj. .xref..199 40..0000000016 00000 n..0000001583 00000 n..0000001874 00000 n..0000001918 00000 n..0000002001 00000 n..0000002075 00000 n..0000002149 00000 n..0000002181 00000 n..0000002278 00000 n..0000002305 00000 n..0000002490 00000 n..0000003618 00000 n..0000003827 00000 n..0000004060 00000 n..0000004353 00000 n..0000004747 00000 n..0000004784 00000 n..0000005168 00000 n..0000005282 00000 n..0000005394 00000 n..0000005732 00000 n..0000006068 00000 n..0000008823 00000 n..0000010809 00000 n..0000012876 00000 n..0000015525 00000 n..0000016320 00000 n..0000016576 00000 n..0000017731 00000 n..0000018028 00000 n..0000018360 00000 n..0000056709 00000 n..0000056748 00000 n..0000108873 00000 n..0000108912 00000 n..0000111825 00000 n..0000114738 00000 n..0000205692 00000 n..0000941205 00000 n..0000001096 00000 n..trailer.<</Size 239/Root 200 0 R/Info 198 0 R/ID[<4233CB1FCBC94F52B532
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 236 x 236, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):4033
            Entropy (8bit):7.925915851203238
            Encrypted:false
            SSDEEP:
            MD5:E29559DA64C1DDE5AE2430B7FE332454
            SHA1:2CE3579251F4D080840E2E272245083CE4AF9B62
            SHA-256:19BC37A1B6C5E189569D0FCC236EB5CD7BE9C38FD15A38139D05946DC46D1F40
            SHA-512:2C6171AE2574B31EA62D7FC4FF1E7B3A882278618982D6E67E719F8B225DE2493404932B83CA5FA3231CD16DBBA0F5BFEEF144A8BC31C81C21BB78DF902560D1
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/uploads/2016/11/circleFit.png
            Preview:.PNG........IHDR.............w.J.....IDATx...kUw...."AW..E....*E..N..b.V....2......YB..A\J....Y.....k..W..?.<-..V.s......9.{.....s..H7....2/..;y ?.c..sy!#.S....8..3...<......b..b.'..r..<+_.=.I....M....><.}...x...%j.3q.[._.e..j........#......2... a.t.A.m.c=g..!...'.....[..k.r.c_.c.....J...m.YF.._.Q...\.".D.....2..M]..8f7...!....<.L.b......5.i.#O.MB..}o....cm..s....|.m.n...F.GN.k.L....3..\3B.J\.y..l...kc..D.!.....Z.Z..3*........z.......&4...4RfT.9Y...fA7.GM....w....6..s.r."^....@?lx..+*.)Y..*M....t?*...Px.....n&..d.Pl.a.=..cQA.....L..#F.........W...X/i-......N5.x.f'.x...O.5.....H0.^22..bg..B..4`q.....<...Z..I..\....|.....'..~.P...E.]7r.....%....{.{F>i.~S.{h....F>j...~`t..{...'..LVt..{....~...f.......%.|gE....1Y.#.j...o].t..:..wZ....".c{.....kr.!...{....n.GA..}..9..9.h...iy....XI.8....ee,7.]...*0...n..$...";.^B.u.Q.5.c|.....}.7..{L....{....S./...l..y.z....%xd]..@...M;.Ri?...s._.;..X;..08.D..h...$a`@.&>G..._.?...H..P...+.v.#....j.hmF;0'
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 24 x 24
            Category:dropped
            Size (bytes):2545
            Entropy (8bit):7.144078312196678
            Encrypted:false
            SSDEEP:
            MD5:4B3AFB84B2B71EF56DF09997A350BD04
            SHA1:ACCDAC8A7ABEAB0E21C49539AAD0A973ADDB28EF
            SHA-256:9034D5D34015E4B05D2C1D1A8DC9F6EC9D59BD96D305EB9E24E24E65C591A645
            SHA-512:D65078B5D13873ADB363472B5C358F6B42C128B530F8FEBA9776F8E4906CC97F20EE7BF1E823336CDA8049147A9C7FA5E4016F07F96EC154F3774FBDE1A564B6
            Malicious:false
            Reputation:unknown
            Preview:GIF89a...........................................vvv......hhh..........................................!..Created with ajaxload.info.!.......!..NETSCAPE2.0.....,........... .$.AeZ...<...Q46.<...A.......H.a....:....ID0.F...a\xG.3...!...O:-....Rj...TJ..*........t...........~."...ds]......)t...-"...i;H>.n.Qg]_*......R.3.....GI?.....v$...j3!.!.......,........... .$.0eZ..y..0..q ..P..W...)";..qX.^..D50......<H3.!.....k-.n..a. .(.i...d.$P@y.w`.J..#.....?..y........o...g.....f....'8..{..'C.p`j.n."...2.{.`x...jy.4...C,.4..o#n.$.....!.!.......,........... .$. eZ...$.2.....q....E. ....p$H@D/.....G.D.j8v#..P((D..... ..N.(3..#.y....(@...gUx*.kK.).....?K...............$..."....*.......K.....W......x..?.G...#.W....n.h.K,.....+.....*!.!.......,........... .$ .eZ..Y.$1..Q(c......O'"............. 1....q.d"..A.....V.x8p..4988.MRC.@....e*.3@.iI.)..'.?I.........@.......,.....#.........5..,.....".E..z...?..@.E...@.....).....*!.!.......,........... .$.(e..$....C.E1..;...('2$..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 139894
            Category:downloaded
            Size (bytes):24864
            Entropy (8bit):7.988684293746509
            Encrypted:false
            SSDEEP:
            MD5:855DF083971439DB7CA238122FCFE80F
            SHA1:013BE34EF4C52ED7A50DC3C7AF30A357F5D89BB2
            SHA-256:5786207BDD2CAB3FC67DFDFD0DF96D5886B9B2C396C0633AE67D4737E47813CD
            SHA-512:D55163ACCE1382904B3FCE3DD705DF058CEA7DD660E4A9DFDB5E55077C1D5B12FEB0DFBF6BDB896DF5FFB004A4F2DBA7E7761147C722608AE8966ABBC5DCE40A
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/
            Preview:............v.8.(.;Y..Z.gd..e...c..;q&v.c;...E..D..9$eI..Y.5...>.~..$...)..DR..=3....>..B.....7?..tx.....y}s....CLe..-...p.@TSq...........m....o~......N<.K6..Y.w7. @6Wu..#.;...u..B..lw{kk4.......+...;e..o!..{.o...N.h.]|..X..sa.......{M...h..)..Q........".....;....`....,e{..6..;.........i..[,..>"o.O....y.$..ct!..F..Y......7.1x .n....6u...jO0.D......5.F.....[.b.0.@....[.......b.0...XC.7.$`4!/...QO...9.IRu......eq..........F5.C...`M..D.,)/.&....d......&....0~.0[.........@s,C.Y.2.+.2m}Gy..i.2.Z.q.>.....N...Yp46...>...^P..!....}..d......d..J2..0.C........[..CC..'.P..;.9C......ua....+VN.)..C./..B.....{4..m9^........u..(.c`x.b......D.LIi;V...S.5.(.n..-..5...$Z.@4K.....92u.........LeE.6..6...&.N)q.-&?."a%vB..3<S.;qA.j.S..m'...)K..9U..A....r..o.X..!b...myn1 e........H.m.t.^$[P0._..&...t.+...-.MK}.L..(.DP].J.[...62...Y..j.5..\[.Pe+Rx.B/..A.2..Qwv..zY...T....E+......d...!J>C...1t.^h..p...{...?....d.....g.]}.;..5.[..A3.C..wwH.o.....w...u..@.xlE.4*.N.r
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 112427
            Category:downloaded
            Size (bytes):15271
            Entropy (8bit):7.985808625185267
            Encrypted:false
            SSDEEP:
            MD5:38AAFBD06E6910BD6F3DAFC0D56FA52D
            SHA1:84BA675634422CCE64F2C75272255799A346ADCC
            SHA-256:146EBB318637AA7232EA0821602029740997CE6C304C20016460AB3965E27A1F
            SHA-512:C86E62DBC34EA82C8A0984F1264AEC4106DBF32676F28A4E5F79E3E28ED76BD04B665B61A6408402686022B9B72C46A201A0ED9FADFDC201182DCD281F45872E
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2
            Preview:...........}....}.M5...N.}..>U8....v.Y4..Y..:%[>..Y.F.k..}..U.%(Q.w.9.JT.-._..A2.$....A..........7.v....O...d.1~C.m.~........Y.2.?.a&..,.D...K.=JnQ._..cKS...".nI|F....b;1^?........M:......s..[...>}.eO...(N.AI*o.~D.z8.ap)..<....5>..E...St..'Ez...d.0.'..=...v>.\.....d.a....,.o0....i...1).N.;>S.R..Q..;......m.o.<..v...)#.+..~p1.9G7^.,..k.}...|h..V..9=..%."".0H..j.F'..ov.>...x>...."..Y@.b.........EK..YjD...\qa.._.'.c...5.:....w.. k..6.k4.......q.\&hSr......QZ{.........>...g|....iZ....r..r".]N.....V..v-..Q\..C.... .s..u=N>.s..eE..t&RV!... ..Z..e).5.%AdU....d(z4ah..O..&&.s.+il..t:..K......Y....w.4...Z.1c.X.c.7..v.[..zy..Q.e.....p.{..v^.S..$.F.....[<.fx .w.e....k.^...E..o..V:..E.$;.E|.^.ep..".g.8C!..1..tn.x.I.cI..$.,,.%.........@X..X.........f.0.'.P....dK..c......9Q...t.;Br.L..b.5.Y.k...?Pp.l..MH.rk.._....*..:.<*o..v.p..../..R.yO...5.nd.@Jix;#P..Z.b"Ci.'u&...l.t.Y....[....R`..*...H......3.>^N..r.N#.L..w6.^L&P*>U.:y...r.O..4p.$..h+>.z.f..U....b.X-.n.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1950x675, components 3
            Category:downloaded
            Size (bytes):134955
            Entropy (8bit):7.9766879541972635
            Encrypted:false
            SSDEEP:
            MD5:38825A89D00BCE68296926F190C36BFE
            SHA1:5AF71E22A258F41672F86F3C1A15868E66C2E3EE
            SHA-256:4A074EB19B7E30514333DFF2FB35AABA41E3EA69A0DA04B5DF6F721E15DFA2FF
            SHA-512:C2ACB9868A058222AC0117C6FA19357D540F1A49F1498D8DD1763CA6B7520810140E513EC2543297F3C01ACFDA3D3AA7D50138178AA4EA0DAB8C6D29B73970EB
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/uploads/2016/11/header01.jpg
            Preview:......JFIF.............C............................. .....!%0)!#-$..*9*-13666 (;?:4>0563...C...........3"."33333333333333333333333333333333333333333333333333..............................................................................................AE.A..Q..(...R................!..!.V5....:.........R.....@..(.....(......*............*. .....A@.........!...[.EP..@@..V.(..Q..C`.RMJ..e..F.IR..W-.DREh...*.CHQJ.C...z....]..f..".....2t.9.A.;.v1l.g.....B.F(....B..-......`. .......C..........(.$%..@..)$H(..(....(.....(.............(............@......0hP:E.......j...u$ "T1^'.h.,.9...0m2..:.4e.R1...e...T.Es..\..Q$AW!..,8..e..,..:.h...hjms.5(.y6oi/.J...0.P(..b....*....oP.........(.A%t.J..Q......@..QG.)!j.<}.G..+%H..ZQ@....... . .A.( 2W. ... .............. ).rS%Q.H......A.U.Q.8A.....d.5..9.a.6....Y..........S.P*.CHPH.hgI..>....U.!x.X,.).[r...g3. .......&6.B.,(..R..TQiE..!....2.........C..$.D.....!.k`E.P.`....J.E.d.<h.c............!bf..(. ....O-...... ........D....(...)!)...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 1059
            Category:dropped
            Size (bytes):588
            Entropy (8bit):7.660727736199433
            Encrypted:false
            SSDEEP:
            MD5:6209669D9298E364D532DAC780C3B015
            SHA1:A00A7286154427C580F0B5FD65FFAB6148662104
            SHA-256:7F119C8A8A132FF8C30088B18D4A4479C2D4FC1C65C275F49348DB4DE92FC58F
            SHA-512:939751308E6784365A479666F7891F72B9D3CAC1978D771665565E7A6F4C0D41BBC0967706B505BB417C1228FD40705EEEF9CD50AEB639D13F873379FF78D092
            Malicious:false
            Reputation:unknown
            Preview:............Mo.0...........JV....h...t+....6.6ckq.@..K..(....jC. ..^....Q.G.Y....[.....hBM{.*......Y.%..P.f...\5.,q.RWp.B+=hn,.H..dY.s.P..M.A.......L...s]....k$Q.....c1.....[......d...C.`..cH`...I...h--(...."x.Z.U-..sh/j...\...t.........8.C.!.....(.".Bi.J..I...4...^.Z:...@.q..9W.<U.....gR88....k.i.~{..U>.3.........c.}..Q..H...5...kz.k{...>.....G.ML`...D..N..&......"..g....o.EN.(..4..."uV...}H.X........z.x@>..|<.[..J.*..h[tDFo.oIZ..P........%..2z..3.%...E...o.Y.K.}....W.).@...`.....e......G.t\..:Y-y2.v..dal.6.....|u.5m{.I`<.....&.....a8...!....)...#...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):40
            Entropy (8bit):4.362814895472355
            Encrypted:false
            SSDEEP:
            MD5:8268A2329ED0A7F4D9BF04CFA05A568B
            SHA1:50825AB8E16E25B62E21A1ED6864FD7267DA0C81
            SHA-256:6107509EB2DA22B4FB99AC0558B32896FD54252EEC5D938048A04E93FDFCC31B
            SHA-512:E7A5256565F1F6B4CA24F540FAC80BF93952E558A2545052CA9A32F017C50715873F394F6C27DDAEF80CD7D7678B2A42919A58EEA5649590776C6BCE4553D0A7
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/uploads/js_composer/custom.css?ver=7.9
            Preview:.clickbutton {.. font-weight:bold;..}
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 58023
            Category:downloaded
            Size (bytes):4262
            Entropy (8bit):7.95116921776258
            Encrypted:false
            SSDEEP:
            MD5:DA22D62960AF38A84EF52B4B17097545
            SHA1:AFAD526AF2A6C3EF30740D27A9A5E09637C5981C
            SHA-256:A0598E049815DFC8A1AE2D7791B6DA727859CB055FFE7F4A94A326B4AF127C41
            SHA-512:18FAF6933CE909F4B92774741E3EE8DEBD34F21E2573CF4551578CC4322B1B250C4E4E935CB311CDA01FF2A1B0BE4A3EF2B182E54370DB7C69155CD3DBFC68C1
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/animate.css?ver=5.0.5
            Preview:...........]mo.6..~..-.@......I.e....@........F].2l.m..~".F...RR..F.&u4Cr^...)Zz.._..A<...o...._.....~.,...2...p.x.q..z.n....`...w9.s.7...h;...6c#~..p.l..z.]..A|......&..r..F....q..X........i7...F.....xp.z;.....O...f.T.....EY?y_...a.e.R....^|......]....xA2.=.........(._@......p..A..j6......U...Y..Ew.......0.M9V..x.f8...^....G..82.......w.6....o.w.....36..C6.l2.......q..r{....W..&..d}6....]`..<..|..Y.y*...?....^..%..7....4)....k.O.Mr..R..d>':..I..........A...,..n.m...0_..t..S[..t.H."....N6..w....i*EQ.[....+?.O....7....-Y..(/.u..E....!x..}..j.....>.O..L..-.8.._.nT..</VF.I.8B....M..?.......u..N.M.ix.@...'S......HT...9.<%5.MQy........Gp.v...UAi..St ....q.Q..b.....3...'...O.........3..2..bHx..k..HT.D.T.U.r............4q....`..Ut.K...Y2~=.1c8IL.l....>..n..u.........S...._.K&>.7Q.."..8...9.Xn6......j.:9.z,.r,...zr./...!...=...Q...V9h=i.....%...=...L........H.j..o....r.df..!X&.y..Kt...8m.X..3..i.w.Wu.....V.<..n..>,0.TO..z._4.e.\/;X...........E...[O.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:very short file (no magic)
            Category:dropped
            Size (bytes):1
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:
            MD5:CFCD208495D565EF66E7DFF9F98764DA
            SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
            SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
            SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
            Malicious:false
            Reputation:unknown
            Preview:0
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 28266
            Category:downloaded
            Size (bytes):16292
            Entropy (8bit):7.988157456803789
            Encrypted:false
            SSDEEP:
            MD5:4FF8D3AEED6011B489510558FAF1D907
            SHA1:620A71557C57A39EDB8FDD2AFC755FEF280EC86F
            SHA-256:136CFD450171390EA34B3121B8FE05E74F1E1AC1C01B514692C039F8313CD573
            SHA-512:AF28C20A83D934145CFA6A2D8DB1874211F488B9BD1DA4A504ABEE12DDD0FFAAEA16EBC2CB842544C29346E75D0F4259E786323C92CD29445751F62A85BAF8B3
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/themes/prime/assets/genericons/genericons.css?ver=3.4.1
            Preview:..............L.-6..._.D.4.w....P...{(.B...;t.R...z..$w....ZD=.?..?..H.X.M6..?....?.....R..d..J.~:.:../....I.?5.:m.n.^.U.i...X.._...'...........4.......)/....f..w....i.1.....-.M......3...S.v\.i....c.......m...9.......N._.4..og......o.5._b...t.........IV.......44.............q[....X...O......+..............^.d.o.......Ns1..\.g.G>......k..l..To..........O..dO.=.....F.....v*....d...;.._.........%.bX...'..@........Vrz.xo........A|.....-J.J..s.v.........O....-...b....J^....N....(.y...Z..[...-....#....X.}.#..S....>.......D.9#..r>R.m.[...O.3.g..SI..C...o..?.M.=.....Q..B......yc.|......=S..I...t....._....?-...J.>S..3.......Nt...h.D..E..h...O.@>....%...A...;.3K...+...)c.......l.(J.3.X.Z.2....F.Y....og.?....Y.}..Q.W......2.!.QE%........q....O.-.+ivz.]:.....Qt..l|^9H.*J.2.......p.*....y.n.....6'.LE....h`v..H.K.k..V....+.4U..q,...`JR...u..1e&..B..H....?....\...r.IT_...n...!&r.B..FBVOE..g. .r.c~9..&..../....3.!.z...o4E.....w...~|......S.s.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (6075), with no line terminators
            Category:downloaded
            Size (bytes):6075
            Entropy (8bit):5.56504268499283
            Encrypted:false
            SSDEEP:
            MD5:31B37559307EC803B48F97C67FDEC57A
            SHA1:5A47F5996F979AFB1369990FF01DB9CE58C87CCE
            SHA-256:86C8179CB38EBF40335278310AA24716895AE4C14B759D7E9AD7EB0130E9759B
            SHA-512:17A9133447425746D617F89F0B05357A60960D9FA9FE0140AADA78DC0D0DCE4736C45AE746B1CBBDC2DDC0DDF7705A516FD1942EADDEA98D2B7AA1354CC7C734
            Malicious:false
            Reputation:unknown
            URL:https://fast.fonts.net/jsapi/98f657ed-a3ad-4e29-b56a-362b39fe01bf.js
            Preview:var MonoTypeWebFonts={};MonoTypeWebFonts.addEvent=function(e,n){if("undefined"!=typeof MonoTypeWebFonts.loadFonts)MonoTypeWebFonts.addEvent(e,n);else{var o=this;setTimeout(function(){o.addEvent(e,n)},0)}};mti_loadScript( function () {if(window.addEventListener){ window.addEventListener('load', function(){MonoTypeWebFonts.cleanup();}, false);}else if(window.attachEvent){ window.attachEvent('onload', function(){MonoTypeWebFonts.cleanup();});}MonoTypeWebFonts.loadColo = function(){};MonoTypeWebFonts.cleanupExecuted = false;MonoTypeWebFonts.cleanup = function(){if(MonoTypeWebFonts.cleanupExecuted === true){ return; }MonoTypeWebFonts.cleanupExecuted = (window['mti_element_cache'].length > 0);var className = document.documentElement.className;var MTIConfig = window['MTIConfig'] || { 'RemoveMTIClass': false };if(MTIConfig['RemoveMTIClass']==true){eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 30302
            Category:downloaded
            Size (bytes):5787
            Entropy (8bit):7.967892923422752
            Encrypted:false
            SSDEEP:
            MD5:1F3AAFE31F98BDEA01D3C6749711E2E8
            SHA1:B8C5924D07097F315770D6FAC5A4003D1F0E4176
            SHA-256:C4E8174912B6D4BDAEC4241BC8FB69AC4BD961EC56C0D7943FDBA2CEF8470F93
            SHA-512:89AAC66C6ADADF6A2358675F5337D8CBFC0E5309EF65C1D2CF0285B4AF65DAE00ACA4D2CCB932F7530718D7351EBC44EB7CD21539F96A927F4249710F89E1390
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/ays-pb-public-min.css?ver=5.0.5
            Preview:...........=.n.H.......n%.@...i..F....VM.%p.&....B.o..9....nM.....q......8.s...s.4..X./.?.6..7.P..s..*.0...J....yX...5|..2rOE......!>%........K...W_J.j.....^v..,.s.*.=.sS...C...S.d..%.d..K..9....SYTMxn...,u[.uF:.1^P..Q..}S..w.=..]T4Mq......g...#'{8.bD`.....{.6..;.M.f1..>....k..QY..4.4..0....ql{.D.K...;..g/..P..?!..C...p.u.mZ.......<.Z.du.....gg.Fy.?....E._./?|.....Q]...t.V!..}..?..|DU.QQ!..*;?P....c...SQ4G...d.ia.7......_.w.*.g..p].....i...:<.......wz.-...7.C...K+.R..l/.S.....#....._:.Q..j.....>....s..M..{...]%....s-.v~......I.........w.Q=.`...E.w.....t&V..S....s9..]........7.%..^.E..i.t..F...>.g.v..ZI.p...U..&..u.$G.SX=`1.......fY.....Q..V.P.q)..^.e.\X....dk..."/...6..4...*.9./..>.*<...V....$ ... d.b.X`..9...].WE..ub1.8..h9..#.......QX.1R.J...+.E...............Y..A....\>>.g. ...0...F...o.V......rN^ooME.....*..+M =E....F.S.R..dfb.l1.6*D.....l.....Ms....?.|..q..J..[WmC. .6. ....-03.< ....I2...-...."...Ua9.......L..RA...0aD.4..1q8.Q......Q.U
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 249 x 130, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5480
            Entropy (8bit):7.901285716976838
            Encrypted:false
            SSDEEP:
            MD5:3F2057130962DC553E43DECA1F09E35C
            SHA1:50E99CCA48C4B4E63DD334CEF405844A2A32D4FF
            SHA-256:BA4E9B66FF1D233537543698BFCBA796FDF5327BD3349D7AF14223D4A4F9EFCB
            SHA-512:BF65E7110F7BC40E33491C141AAB01D30DE046ABBF4149413E27AFB3DC4BD5809034D2F034EB84D164351210CF66985C12D946A5836C57923AF6F154B76CD67A
            Malicious:false
            Reputation:unknown
            Preview:.PNG........IHDR...............n.....sBIT....|.d.....pHYs..,#..,#...1....tEXtSoftware.Adobe Fireworks CS6......IDATx..y.]E../..,@..v...=.2.(...1F....,a.e...8. .Q.d....G.... b.Q#.J.@P..P..ab..!1...?.:.^^.z.o....|.........n.s..B.z.:w...........n........E.X..h'.....y.0.8.x......l.V...n.~....z.)d#".....70.x...?.|.........#FD.l....,.b`.(..=p\Gw.G.0ZD....]._..b...vt.<X.>.. ".....20..].......A.B"".6....h.....8.oGw.5.C..b..F;!4....o.x.=./.x.!..y.r..u...XoW..u.G(..........]....g.i,a.D...Q..:.wdoW..:.'. "oO...x..o..BDD.f.vun.....o...".v...v.....c.......z.M......#....k.m....X.q%.A...e4Fp.6`L..y;.........S@D.vtt.l..o...4`L..y.rc...CGw...<.....'..z.8.7.8.0..y......pQ..{..^....@D.tt.....a..ut..T.q.2.....5.....k.....jsz.:.....[......sX...*D.?.tt....$dX.....W.. Or...N.|..>.n^.....:^..E.......<.......m.n.>....xM..F..\....q..1......l..JB...:.{....B."r!........[........ge#}..)...vA..Z"............B.#"...GD..-..\.Z... .8"rAhqD........5......P(.&.4S..Y..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (1146)
            Category:downloaded
            Size (bytes):287205
            Entropy (8bit):5.220249049002685
            Encrypted:false
            SSDEEP:
            MD5:F6EFB8C940AE7A9D2BEB3976DC3A788B
            SHA1:38C773F7B36EE68C04DC2F64CE099FA98DD8176A
            SHA-256:B62CA8B9F23036BC9B90E3FE8624DAB0AC998AFC58067F47D4E2521ED2F1657C
            SHA-512:9E8F242275D3F559C3D8D227EB35C24DC238AB402D876F1841E5AFC51C21C572D733906B6EBA4C7F11D2C9B9100EBFD523086F7F708143E37FC52C003D216472
            Malicious:false
            Reputation:unknown
            URL:https://fonts.googleapis.com/css2?family=Noto+Sans+KR:wght@100;300;400&display=swap
            Preview:/* [0] */.@font-face {. font-family: 'Noto Sans KR';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/notosanskr/v36/PbykFmXiEBPT4ITbgNA5Cgm20xz64px_1hVWr0wuPNGmlQNMEfD4.0.woff2) format('woff2');. unicode-range: U+f9ca-fa0b, U+ff03-ff05, U+ff07, U+ff0a-ff0b, U+ff0d-ff19, U+ff1b, U+ff1d, U+ff20-ff5b, U+ff5d, U+ffe0-ffe3, U+ffe5-ffe6;.}./* [1] */.@font-face {. font-family: 'Noto Sans KR';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/notosanskr/v36/PbykFmXiEBPT4ITbgNA5Cgm20xz64px_1hVWr0wuPNGmlQNMEfD4.1.woff2) format('woff2');. unicode-range: U+f92f-f980, U+f982-f9c9;.}./* [2] */.@font-face {. font-family: 'Noto Sans KR';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/notosanskr/v36/PbykFmXiEBPT4ITbgNA5Cgm20xz64px_1hVWr0wuPNGmlQNMEfD4.2.woff2) format('woff2');. unicode-range: U+d723-d728, U+d72a-d733, U+d735-d748, U+d7
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 47104
            Category:downloaded
            Size (bytes):8484
            Entropy (8bit):7.975336405943132
            Encrypted:false
            SSDEEP:
            MD5:4189DB70B0150AE5015BF97B3D66224E
            SHA1:3C335F4F9FF82F23538A12EFBCCB55D02D853A65
            SHA-256:D83083BD55C4EEBAB9E072D9001A73770C11B46C48D1FA68EBD977246E7DD537
            SHA-512:5D6E3E35658B3F3BF0AB3DD1DC848AB7229F64C2C85036EAEB25895B0CF7C9AB06598A045034A8FB4A7480AD93A360FA7BCDBF4E5CFC26A7F7CD70B3C0234213
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/themes/prime/style.css?ver=20150930
            Preview:...........=ks.8r.._.[.33....S.k'w.J..rI.m.U..)Z.-f%Q..y..{.F.A..x....K...F..h4.|....M...?..."....Uoh.O......6]w8^<}..i..:...y.......C..N.p.m....^.U..o....j.CW7..`..U{.O.....}..lve....)...l.....^N.^.q.^N...t./q.M[}@Q4=.W....'.,A..L1.e.<~1M.Y...C.lz..._./..E3.-./.&.....y..E:C...r`\L.^$/....-..Z..W.O.^>'..1Z../.F8........_Z..N...w....v.....u...M..l..P..U.{.:.....w....j..?...........=..e...(..u}<l..?...GO.IQ..U.......w...\.(...O... .7.z].....g.....~..,..ep7..IR.^..#Fj.Y.w.i..SR%a0.N............D=..1S..z,..B=..#n`...C1..9.L;.jKu....Jm..K...y&..z].o.-O...mu.R..M._I...n....s"...-Q...B...".....,.J.i.....B.d.7....5..$.@.P........C....d....v..A4.....)...`..B.k...TxF.P.B.........(^.........(^.....%./v....W; u_........k^.!..%p$...K."....o).......,F+$Z..b.\.9j.Ih..b.T...*FK$.........ZJ.f.6...cm.+..l..M+......"Cdf.kl.ai......&Z_.s........[.Nyd&Z.fp....S......S.v...a.._.V.F.i*..m.wh.....V...Y.j..9."/\^.~.|..nj...B.G.\...B..6.Hx.9.jr...D..^.d.1V..zL.c..s
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 810x440, components 3
            Category:dropped
            Size (bytes):64652
            Entropy (8bit):7.9857390940216675
            Encrypted:false
            SSDEEP:
            MD5:3A19E10E3DEA438703CAB66C52335CAF
            SHA1:D73001914C318D5B309B7CA2AFB6B4CC7C330E12
            SHA-256:9CE5E8112CED0B18659E52D21D0A08B3E959E0291D95F7D672AE15614BD22E2E
            SHA-512:83DBB2C281AB17A36A040BDD17114E7A35EEBC9451F2432673E487F0C89E47D7A190D415CA6069C3E0F43C22A4E8A9645608A469C0754EFE6E9206133DDE9173
            Malicious:false
            Reputation:unknown
            Preview:......JFIF.............C.....................................!........'.."#%%%..),($+!$%$...C...........$...$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$........*....................................................................................ub.:...8....j(.G.4..'..*..)....k.....o<........a...9vu*.....-....)<~.9...\..b....+..T.rS...l=a;...`..<..5.;6X.WSD:c.-Ln.a..qX..I9....+....yn.DW1h3..yq......p.....Ff.Q.n\....j..7".NW..y..oy\>....p..z.SQ.....u..G.}y....................fjs.nE5....r.o:./......K#sE..?...)J.6.Z....j.....6....:.l.Z..jQ.7L.%4..5.*.ic....4..t.6.T.....\...tR.|....2K,.5..9~.....+..Z....ZCN.&.....z..........-..c6..v.tR..N....?N....<y.....0.3.Q.....k...x=...b....zyO.r....clR.@...R5...E..6...&....r...}../W8.t.j!.......Q6..{<{..W...#.Ckr.[He...E.r..nyt.,..M.n..J.r..;.9..6I.....j.....*.....(...~s.o~......k...n..G.........o..Y....'....F(.N..W..G*.......*l-@,..HZ..Y.J..-.=xOY.K.......,.mM... .j.....Vt.u]+9u..vC...........
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 458836
            Category:downloaded
            Size (bytes):46668
            Entropy (8bit):7.992461395108861
            Encrypted:true
            SSDEEP:
            MD5:172C302BC5B61DD128F55C82C9BAC116
            SHA1:961132B457B91EC293C0C1267D7DA713795DC043
            SHA-256:1302B1CC9047C2CBEDDED1EE4C58B263A972B37D005FB50FEB88A410411135B3
            SHA-512:4DB3206248C34EBFA96634B8A5AF80DC24893753ACE004783FE00DC2CF924C8E5DDC8ED2A3565A1F463D80E0CABB6E1B39BE7607A27F129E035A932D68BC6D8C
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=7.9
            Preview:...........{..8.'..~.O..Ug&.e[~'..W-........=..Y.3..W...q..%E=H*"...}..vWUZ....`.%...........!.=;.....).|x.wiv.|Y...G......e../..MAu........s..|.LF..p2.L...'.q....].*(..<...l-....9.....?..l.f.8.]...D.x:..l~..3......_.$........:.^..]q.{........l7...............1P.m........p].i.4..v..5.......<......_....^.....n..9O..0.z.U...C./..t<_....%...Dj..C........,W.......4..j....W+..>....:O9,f<....(|.%.....n.R...._..a}.v.U.=lw....e...ky.....A...\..<..4..3....L.rV4..S..G...~...xKY".,..[.0..E....8.L.....9..Fo).%.?f.,9...1.f.e.f<....,.1+...1.f...7]9....].,...$.(L...`l..&....@z`.......~..t}...,..=....M._....`.L..(.;..3.......1.6.9f.\.Y.....~a...7. ....7."bJ1.S).L).o*.).?fk)..Lm../Bd#.}.&6...al#L|.F6..4Iq .(..8?.~.q....5,.Z^Qn..~..wO...fd.3.&.;.M....of....f..Y.oV..}..'..w..D.g...7S..L.3..,.7K.M#...........7..f....o.....f..i..z..oF.;sl..3.D....f....o......jT.2....ux...W..9..Cq...Q.&1..K...|......u7L..}.../.......;?.'./...<.#.......~..?..y.A.:0.}bo..ko
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 13577
            Category:dropped
            Size (bytes):4881
            Entropy (8bit):7.95677044432397
            Encrypted:false
            SSDEEP:
            MD5:E9D7A4E6EF99699429F065CA15677121
            SHA1:0FCF8A61A6E5DF4604969F8D03ACAC46C3D130D2
            SHA-256:BED8B65020015B71183E9E371CBA70FA1957E354C020C2FDEE6020C9EB717FFA
            SHA-512:268CFE82F4A2255CBC217C2AADEAFB19371851DEFD80D39D72352C799E2E6BF06A98E3EF12CD93DB6F7FCF13D6EAEBA42C39B97A67F4023E0116995CD07D1304
            Malicious:false
            Reputation:unknown
            Preview:............ks..{.....d.Qvr."..8.]...k:#+...$.....%...........~....]..........)cbe]F..Kf=.t.u...e...a...s.%./#.X~.Z\N....H..e.......`\.&.8.X.2.y.o...q...x.\......Fx.I.j.....C.Y. ^[:.$..)..$......Z...g.@7.!..Q..9...L$...]DI......~......Y.`...s.d:.w=i..=.........|w....".....'.UH<z.S........_.....M<........../u.....+.e.o...hl.....j'.....q<Q....o.Y.;u..wL..I....D..zD...#....x.....;.....KN....G_.S....w..>{.I6c.L.%.9.3....C6...lh..,..C.30.-....R.X...].;..bC..,&.JE....?m.@o^.G..qZ....]w...\......?.N>....t.._.uu..wWg..x.m_|.D.$.BY.c...g.(.b.,.fY,.y...f,..?...V......m.Uc...#.".S@0.<...6=0......X...@..T.{...42m.......{d.l.T3.fspQ5.....6....2.g..mb.I....8"Z-..`.H..Y...Pc.i.d>.?`.@....8.b...I.M(w.s.....s&.JMx....I&p.= .%..Eo.d....f6B..4.....|..fS!.....=.....o.>o.r@.>.$.@.|.M...q..<^.r...06gSR.T)..t..9.|a%la....L.sk.ef.....[...t.8....V.Q. 2.....8.).j.......B...m....u..CW..R.*.@.ZjG.#o...-..}<..*B.(..y..%.....)u..Jr..f.pi.Y..F..'5..eD.`Hc:.c$d.)..%.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 82", baseline, precision 8, 400x450, components 3
            Category:dropped
            Size (bytes):27779
            Entropy (8bit):7.971505096155548
            Encrypted:false
            SSDEEP:
            MD5:537A41763F6BE221FAA52C38D865AD5E
            SHA1:92E2BE4858304CD4EC801CE6E753E909BE740C74
            SHA-256:052BE49552255D9D8DD11BAADDB2B5414E24F0A22D716DE5699E6F36853DFD1E
            SHA-512:AF389D37F4012DEC612BBA2597C659BBBC3DA1BFC45D01B9123A2045B6ACE6C0B6F4680676B681910AB4FBA9EAEF07F759DECCEEE42DF6A6F5D79068C9F9095E
            Malicious:false
            Reputation:unknown
            Preview:......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 82....C.....................................!........'.."#%%%..),($+!$%$...C...........$...$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..'.....4)........R.P6.*sV.BerqV..7.G.X..".3......'.Jt.w.....$K.SPO.jX....?-'..X....2..H..C.-;..S%.@....@\.4... '=).).v.L.7.1.'..i\........K@../".)..b.H..)...........s..Z.....E*.. .h.b1...p.2EH..*.ylP$2.)E...vi.M:.X...$SM=8Rh.P)..-9NE23..D....vZ....$...L.MI....Q...'...:..c.......M.HT3d..?,h.....U...t
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 149934
            Category:downloaded
            Size (bytes):21946
            Entropy (8bit):7.990468607535973
            Encrypted:true
            SSDEEP:
            MD5:F32264994D6A3F4CAE3AB2F0969B1B1E
            SHA1:F017844E1FC13E7D1FC5D31E2A943B8421B53746
            SHA-256:C910B1B7DCE39978B98073D50C6CC27EE664AE5CE0A89DD8B899BEE1A05C248C
            SHA-512:8C91D6A27DA194E94E2E5189CD693B84FEF484A1E895CCAE98C3E3DFD56BBAE6C57F18F9B2D5CA2CCBD2A8AFFCCB5643EAE9B62F3D96795D00064BD1D127AA84
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap.min.css?ver=20150930
            Preview:...........k.#....}~.5........m.X..Q..q.n.#VkG.Ul...P.9........d.Q.^..!.4K...D".H.......w..t>_.k[\.....x=xw.^/..><W......o9.o..m.|..f..t..Y...^.v8..i7.@.R.SW..........I..T.....>\?o........p,:F......_....E~x....~58..c.......N..../..../@.T..M.}p.8........}...u./.u..q...n.Um..(2G...O.ut..\G..0*.?...`:..F...@........c.>........5..M..%.OY]...o...\..I|..,s.$...P....s{.].o.E....6|s*>..t.Nbv.#+N.\..)X...w?..oe}.....O.+....c.>1n.>Z}j.S5...*....\.Y..EWq.C..t...a.....o}......W&%...uYV...o..A^+.Q..2...'..S9b.}n..L.N.h..U.>.L(.....g.B<..c...m...6...e..m........eP..U)...........z"H....._.VZ}e".....S..j].........`V.9<..Ia...z2Q.V.,u...wL..-....bv7^..E.\.].U.q.VL.L^...Ri.P..li...\...h...b,.YK!..3.W..M.o..L.g.Y.-..Z.x........(..'.)..br."...........^....8.j....>..K."..K...,...z.y.37.?mK.'..8j.9..x>.......l*E..1.2.P.......rU......}...Rx....M.....G.~*.......mSA.d.Z.....u.l....X.i......{.....Lcv...IL...Uwd...R......$.jsk;^..f.....`F.`.?:..T..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 855x525, components 3
            Category:downloaded
            Size (bytes):103156
            Entropy (8bit):7.9923822331594225
            Encrypted:true
            SSDEEP:
            MD5:2B0AEA9AB69926B016E659538A4EE090
            SHA1:0ED8503430978697BE35E6488C385D2A2F73CAE4
            SHA-256:C243EC2874B604F536897C08FD2888EE20CBAA4300E5A5650EECC12F07A77C4C
            SHA-512:2CD64CA8BB8014CC8056EC3E6E832C4FA1AB2AC5135D6A2105E3D07ADD55EF9B46382FB09EFB3A703E8B075AF18DB9DB8D059FE21A0A928A541DAD057E92DF86
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/uploads/2016/11/500-IMG_2508_855x525.jpg
            Preview:......JFIF.............C..............................................!........."$".$.......C.........................................................................W...................................................................................31...xS.U<.V. .0u...".R...0S..I..O. ......K.R.........<x....0..UE.*..<$...$4T8*.G+.iE_.b...$2....xA.. ...p...XQO*..ue...j... R.f.T..*#D<5PDq%.......NI*K.(..Lm........~.` ...Y].(.Ckd 6......<xA)..^./...W.:...4Jl......I....... ...j.z.6.4a............!.I)..Tu.d....<.ypl.ET...%I<...@..C....x...4A...4h.Q.A.<!.......H6.$m .pI).\........'.S......h....D441V...F.#.A.....i....S...D|IO=....X.9`D',..$.. .......C..,e0l.A.......m4Em.4h.h....=y...(.d.Z-.X.Zx}.Lx...b...#.DDB..+.W. ..._X.S..a+....%z8.=.$k.xu[...OO.....0.....Q.c....h...;. .h.4l4`.`.a..G...\$.TY.l...."PD.........xA..d6.....D. "..,.P......)=.J.. 26$Bj.-*.2.'$.8..F..FFF.SUISU.XAHy.."*#Q.c).FS)....H..e.....-F..%9M.B.l..CJ.<P........K..2.A...0.......J.c.Kc)....$$.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 87553
            Category:downloaded
            Size (bytes):30633
            Entropy (8bit):7.991386062837272
            Encrypted:true
            SSDEEP:
            MD5:9ABA54DA5D9051AA835D91815A427A5E
            SHA1:DD8D53FA8346CB3C92B624FA7AF4585A4B5B43C2
            SHA-256:2A5ECD5E26156BD1606F90777AC10F52E0101C2570AAE9CCC95BBE05CB883B12
            SHA-512:28141CA50BB8A634E8E8F6F187B27B0476EE4C46048F31A922E07E4EFD6DF1C3295EB6C7EBAF882DB17A83EA063002A04995CC5DB84DA8E61CB808D710B80985
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
            Preview:............{{........"...D.........m.vn..?0.J.!..@..~.3........{NZ..,.:;..9~<8...MR..\.t.?G.....^'.?^..(6.2.."?...AQ_&.....2}............8K.I^%......j./..:..6......7..&t.E..:)V.W.r.%....8J.......(9Z...U.......a.jp...AS$./... On...eQ...w...I.:..n.|Ien.....^0).zS...J.......$.4O...tW...OX_....J..t..:...$..U.}.#?.H.o..P..+.'Q..U.Wu..U..Sw..g...".2.d..Z........v...P.zS]..[..'..<..4....u8.P.......:.N..V..&iJ.Q!]...*KP.u....<jV...o..&e3..Q^,..tC/.'..N.v...|.e..>L...E.e........PW88QU..ON.....pt........*..|.Ji..<...hQ&q.<..T.{.L.....N...v...<H.M.Q=+..-/..Z6.u.}.ApxX.U.g*.&. I..&...2.~....:....Q.\..y...x.(..i2..po.&.m.bM.Yj...`>.....<F+...._....T-.g...L7ho...s....W./.a.s0.4dI~Q_z4.X.#.%.....\.......|/......:.....!...><<9.?.h.5J.9[%...l~._q..v...MR..U..h..d.C.......N.hX+...6.B.!mz.Tx...)...k.8.U....L`.....J.....W.d..=..P..w.x.U./..U..\%.E.u.9....48...\.>..%.;...^R.x.52r...M....m.|.$^.m..,...q...X.8.g6;5.t.....F..ViY.....P.,~..hLe
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1350x300, components 3
            Category:dropped
            Size (bytes):107793
            Entropy (8bit):7.975066775149237
            Encrypted:false
            SSDEEP:
            MD5:1B68A444A23A61A18BFF56AF5A0292FA
            SHA1:91FE739CA9D14265516D11A585D5AB31E5F72A75
            SHA-256:6B4810D75CF1D488B788593CB52605DD5C1982D6CE60AD79122B6412E09704E1
            SHA-512:18805592DDFB61FEE04EA428DE4CAB536D1B4C58C2B525E1F9DDF584FFED5FE9D1F5FE0493C8235AA2B3E3C665F36FD53B270AC21AB019F1D48BE745C03A755B
            Malicious:false
            Reputation:unknown
            Preview:......JFIF.....H.H.....C....................................................... ...C................ ......,.F..".........................................f..........................!..1A."2Qaq#B....3R....$br.....4CSct.....%&'6DTds....57Uu....(EVe...8.F..................................:.......................!1.A.Qq"2a........BR.#r.3b...C...............?...2R..^D..A*2.%*..M...k....d....!....r....dAk.d.......D4.*.-,.[x.Ce#...5....M........U9..S,;.l7w...cr.`."._..ZZ.5'*R.....z..{...4....{.Et....Tt......R...l.(..mi.b.@..._...t..T...3..J.BA..v.H.....d.Q..'b....ad........4.~..l...n.6mw.[.0...ds_.....[..ZzM..).fSJJ....6.})0]Y..~B..%...%......JAHV_S..x....0u.X..Hu....0).z...6JU.c.u.Ye...Vr..}myE.7....C...Q.D..&..x....O>qES..(.....nY..........{+.|...^....8..rX.....3..b..75)....Kq!.P...pT..mgg......d:C.8..&.$.h .9.t...Z.t.,.........HNd.........v.......%.9,]f.p.....1..qz........?E..;$...YhV.Z}d-=...\.km.g.2..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 323042
            Category:downloaded
            Size (bytes):83452
            Entropy (8bit):7.9959992850242285
            Encrypted:true
            SSDEEP:
            MD5:A556D91A425101B6B29442988F4DB776
            SHA1:369BADDCF0BC753B0854292838B92EE45B9C72CF
            SHA-256:825142DCB168134C4F4EAA9F130D8DDCE1738FAC41AEFF5F011CF0129CF9F7A6
            SHA-512:8F18E770E80B8537100BCEA358525AF1145CDCDB2A1BC12CDEF01DEB70C69442950EC4597C57CE18CD5B3007E4599BFBE9C88B0FDED926CA85D2B25E0B66FF46
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.17
            Preview:...........{w.6.8....9gl2.d.;.L(.u.$..i.mw&3.....m3-.Z.....o=...A.N2..s.fw."Px..U....[_|...z..l.....U.X.Y....>..Gr....lY../V.Y..|.......Z...=.i..,........................_._..._.8|s...M1...i.^.....Q....h0.f......U}Q.Q.?......CQ^%.E..x.^..W..w...P..?..J.{..^.^.........u........a.e.Xf8+.w..rY..`..uZbG.......7/_.;|}o.E...v+..'...'.E9_.iUA..j..'...../..UG_.,.7ev~Q..Y...};x2....k.._,z.T.....J../>^dU.........tV......(..^R...^........\..<.._|....[gP+....n...Wu..jor....:...........y.[.q\O..#354?O....M.......|.R...f...{.@r.*s.......W..m.S.M..YQ.8.*....% ..<._/R.Y..y.H..]r..^Y......,.....ht<....2)..]1O....*}y.-.>....G6....Q~..&.M6.....3...t...C?..pk......O...j..x..a...b..0N...?...K?.h..X...0d1c[..v.......LV....y^...)b..$?O.d{.;[-..L..u!H^...M....;.s..01...2.s".<>:.Y...M...#73.S..$.J*.w..A.A..<.4.H..v.,f..jY.Uv.B_.z.U5Lx8+...l^_....yZF..u../...vf.J..../NN9.."..;.....:.}}...'Yz2[d...F..z~..d...7.].b.`.~.H.K.....U...e....N...../.....^..9y..8..u$>9;.\.7.D.b.v.q.<.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, max compression, original size modulo 2^32 46274
            Category:downloaded
            Size (bytes):17168
            Entropy (8bit):7.989364903563379
            Encrypted:false
            SSDEEP:
            MD5:01D5892E6E243B52998310C2925B9F3A
            SHA1:58180151B6A6EE4AF73583A214B68EFB9E8844D4
            SHA-256:7E90EFB4620A78E8869796D256BCDDBDE90B853C8C15C5CC116CB11D3D17BC4D
            SHA-512:DE6CA9D539326C1D63A79E90A87D6A69676FC77A2955050B4C5299FAB12B87AF63C3D7F0789D10F4BE214E5C58D6271106A82944D276D5CA361B6D01F7A9F319
            Malicious:false
            Reputation:unknown
            URL:http://www.google-analytics.com/ga.js
            Preview:...........}k{........m..i...`.@.....-.G..4$MB.........b.qYk.s.w...#it..."..t ..p.....xq.....;..7l..C1.....B....Q.}....9>..d..&~.....~...=_Z...0.{...w'<..e../..L..A..J.w.R.Jy......XZ..<.......<."....K?.~.xx~..AM.....MF.n.{-/h.p...._[.G.O...........h....>.&...YT..A'.l.........vEY..%..xm4.\..q..0}.i.g.. -T.{txt...... .b....v.W........E.5.~i.O~.._.-.A.I{...kc9.s!....J.y.Z}..@..zA.........Z.....Wh.v..s......,h?Za.p..v......U.....6..n..xq...E...M........zSU..."HCC...i..T*..f....g...lf.<k .@.....&n..'...../.+!....3.C...t<..p\...`F..C...t..t. C.RU/.)............_.4/(s........4.[. .........C...x+..A..x.k.i4.2.....5#s.1....m..[.].......6.N....X...dms.._...\...P.2.|....a~..v...@`....t.-F.(.Fl....k..-...>...2....2T.......[...e....eB.s)...IP..~.q0.}...M.Y.p....\g..,...x..^...I*.r.....R.a..x.rqI.H..O..Q...............kb,y*w...N.;J...p>.^..z....:....n B `.6....m...Q....L5.......W2.z^.h.).c...-...H|.-aPK_0n.L..|..b..uKv...6=/..6[.x.Dk.R.X..A.h.A.0. ...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 14560
            Category:downloaded
            Size (bytes):3543
            Entropy (8bit):7.938687414444645
            Encrypted:false
            SSDEEP:
            MD5:36E1EA7218D066D0EAD16DF8961231BD
            SHA1:3B1BA77DDA44A254CE7267957288F7B5FE291937
            SHA-256:CEA64B78BB7A6596A047E6C6E44302BC431F811F680A32108222B7A5000BDCCA
            SHA-512:657C045845E23E933CF097F8B3AB1F27F7CCF62D98C60387F9020C63727406CD790EFC614669ED300A7D0D88B7BDB0CEECAD15D0F46A90D40DAD9ED2F1A97429
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.5
            Preview:...........[.r.6..-?...%.[...IcG.I;I'i.c..G...HHBC.....~...O.O....d..v..E..;....v.y...c....c....%.HY ......{..|.E.O..S..)O...S.......xF~..e..D..f.*.gs.G!Ii.`)...ed.".....zF..2.32.4&~...."..b...2A.o..iz......'.K....#.6..8..b...O....3.F..d...'.En.%.X..W8Lc...L.&8....%.#.f..}5..........o.,.k5/..o{...'..bq.W..q?.a..L.<.....<.........Y.&,b.....QtsH.@.1........L..}`........9Y...A..Wf......r..."..FcR_>......R.e<.v.|g6..SeD...O.....B......3..`#...,...T.hY.A..dE.O../.&2*@....D..."......ULV<.,.:...wC..w...Y...........l.P.<..>.....`''........o.q2./......p....../}s....h\5..!.?Dr.`.....]......@-eSW"z.&.#.:.AbI9F.-..{.t4.o.#..N...Q.UVS....T./..+S.."r..{.....~...1t2....t.#..x.aX..<9...b..S.. .jC.......Q.p..+r.<.Z5..z....P.T.j....ig......,[.,..U...N..+&u..........]G.8E$.p=5..%.:..~4"..}...8..3$D..B.s.B.~..p..;.{Z!.+._.7o|....G.....|........2.k.L...0_.=...I..C?......y.Dg3...J..........o.=.\..$O^.N}..i..q&j....)q.U.....<...!3....3.J..%.lL.~.jT...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (2019)
            Category:dropped
            Size (bytes):26018
            Entropy (8bit):5.591428327582038
            Encrypted:false
            SSDEEP:
            MD5:D22B9D8D3CFE3E19B65A2E09CA164CE7
            SHA1:6FC460C9F19183A9B605F72D1199C0563C68F3D0
            SHA-256:52F7BFF0CCDD80DC36D123955C81195EA7173AF8EB7C5BE8A863E8E0ECFD5954
            SHA-512:4E18FBFEBC2951A69500720F98D46C0F299E22F10AAA673F0A1C0E958DE796700FB0199804E249EDBFBDB161B8C1DC2D8151A79468814750539FF70E44216BA6
            Malicious:false
            Reputation:unknown
            Preview:;(function(window,document,undefined){var w,aa=aa||{};function ba(a,b,c){return a.call.apply(a.bind,arguments)}function ca(a,b,c){if(!a)throw Error();if(2<arguments.length){var d=Array.prototype.slice.call(arguments,2);return function(){var c=Array.prototype.slice.call(arguments);Array.prototype.unshift.apply(c,d);return a.apply(b,c)}}return function(){return a.apply(b,arguments)}}function z(a,b,c){z=Function.prototype.bind&&-1!=Function.prototype.bind.toString().indexOf("native code")?ba:ca;return z.apply(null,arguments)}.var da=aa.ya&&Date.now||function(){return+new Date};mti={bind:function(a,b,c){var d=2<arguments.length?Array.prototype.slice.call(arguments,2):[];return function(){d.push.apply(d,arguments);return b.apply(a,d)}}};function A(a,b){this.i=b||a;this.a=this.i.document;this.c=void 0}w=A.prototype;w.createElement=function(a,b,c){a=this.a.createElement(a);if(b)for(var d in b)b.hasOwnProperty(d)&&("style"==d?F(this,a,b[d]):a.setAttribute(d,b[d]));c&&a.appendChild(this.a.creat
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 17478
            Category:downloaded
            Size (bytes):5170
            Entropy (8bit):7.9622936250104015
            Encrypted:false
            SSDEEP:
            MD5:18FCFD3C061E977B8132D1B7916C810A
            SHA1:CC863311FFD830488772D28934E23BE4AC8D0E03
            SHA-256:0C11DC25C5D672D4FBC9C729E3B1D6CA2083DCB119B437CD138FAD4F05EB711E
            SHA-512:7234EA33FA75A0F799732CF54B3A12188433C2DCBF35DE764A018702383CE9D1E03AC0460F45D060CB38849012C775E3159342099079832EA09E6946249E6266
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.9
            Preview:...........<.....E.N....Iq.PG..N.d.8~..v2.=...$...! ..:.... .R.G.N.N.#...X..BME.Z.\....>c..dT.Wt..b2. .4Q|..$HO.!r%V.B*Z*....I.d.N.Kq.3...V..G%.X.....f&JoM.....=.....d...4...#._r..x4QW,.X>W......;u{ATIs...6.J....s.c.vk...o}....6Mf..(&rr..........a.............y.^..]s.*.'v.;..I"...uA......i'..+....x....dJ=.^.%l...+.T..CKN.h5#[.y>.e.Ai..~.w).wW+h.~.kV....L!....B..zq{,E.#.RC).u.C....b.C}.~.J>.....M...^2u.L...#.....d..h.W....C..tg..a.o<v....{$./..0.Gv..#~.h..\V.Ra'...>p..=}.$..\y,.J..S..P.rM3 .x.."n..R..'...(....8:.MX.G.5...c.??w..........|..)....q....m.X.).Q..7.Q .B..........`.wq.6......t.]..j2.j..&.....cq....Q."..LJ^(...OL....?.5....W>.I|6.OY&1Y(U....\.f.0........9..A.O5..Y.z..:G...nt.(A.z%R...$_.`.........6.W.'......M...^.&.....Q.m.9.-....Fg...p..t.w..k.vP.SD.$...L.jP...X..'3HU..3U.......G.V&@::gC.)+P..~...$....ZD.|AP.....0..`#f3...o..CG.^+......!8...Ylz.`..fK!...(...@.......WC..%:....>.[J...E....kY..{.......J..c3...n..Ozx'.D..4+..1..L.4.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 50394
            Category:downloaded
            Size (bytes):11243
            Entropy (8bit):7.979886134766798
            Encrypted:false
            SSDEEP:
            MD5:2923120E3485EC604187F9273C56A17B
            SHA1:B2FA705BE8E7BA096B9136A0CF09B777FBBDAFE5
            SHA-256:CA5762393E0F9F06E6BBBD41A5AE55987CEE7B7998CE8D9DD4E3D8B463C9BA63
            SHA-512:77A0011191B00A762A8EE718A053B6563424835783AA5F328971235BDDA317334AEB996947755C50FAF2FBBE31524EB27CE362C0FDBDF59B518D2510A71DB445
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/themes/prime/assets/js/bootstrap.min.js?ver=20151204
            Preview:...........}.w.....+.c.5.@....:.teW..X.,9y.\&......00..D...UU....9N..=[DOO.uWuu...._....._..j)......F.._...Md_.w.fq5......n2..7.''....oo.....x9oFX....l....+.O....b.......X....ws....#..\..X\..k..8..V..1.7..j.X......?...M..X.....\.....qO...M.-.e5...B.S\...../.P..j%j.HT..|t.#~<Z/g]_....._._#h...A..B<..........[..8.).Kx.[...B...k.`-..X.....r......oG'b..S.......lqC..........p..P..$...2 ..d....~.d...3.....K1...A8.....GY.....j..SQ..E/.m1.>..........X..k^,.}..buo..c@L..jD.@..zHF..]+...#..u.q&...`..^.....N.z..\....*....e........#.:Dp.o.N8...~.].U...#...}.`.5?.&C...........,T..`..:..U...^...~..2.X9.. Z..mw%..}).m.)p&.lCh>.}.#.*..0....F'.#......(.S..u7o..<M6...."gr.........j..o.$..G}..50.uk.nK..H5......F.r9.H..&..I.5'.[.._..~.tb..c...d.L.........Q[..R......G....cTiH.`o5.....'....B.y}1j..l..d..f.w...[_u...B.uq.<....2.W..-....(..5..ZF......7/_}...d..'....O.{..-......?y.*...._.W.~..Smf.c..Dh..Z.#.....X;rH.....,.AG"$..1.....U...n..cDi.W......}<F...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):376
            Entropy (8bit):6.898851142080951
            Encrypted:false
            SSDEEP:
            MD5:D3F1F843064DC92DEC7562D5A79771CC
            SHA1:14438D49DBE511657123596FC5C90BBCD52BB65A
            SHA-256:1AAD5DB7D7B9DF7DF04C332A5786831CD27B15966E285F260823666F85ECC3C3
            SHA-512:E9C0A1AC716610E0CE0B3654D02C4EFF5A7181873EF3192E3117A16672BB4E27B1BF670D53EC54DD7C28C15D1DF545715A5297E85754477B0622B0504432BB99
            Malicious:false
            Reputation:unknown
            Preview:.PNG........IHDR.............;0......sBIT....|.d.....pHYs...........~.....tEXtCreation Time.11/22/16T.......tEXtSoftware.Adobe Fireworks CS6......IDATH..... .....[7p.G`...Q........n........".)1....qw_...D..U.n...-........pv....`..5.}0n..}......S3{.$o.P.`...F......3&i.y.I.R........*j..4.*...r...&..S.sv......36....O(X.\..?.x:~..r....=.i..n.....ub..........IEND.B`.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (5945)
            Category:downloaded
            Size (bytes):273000
            Entropy (8bit):5.581392787832606
            Encrypted:false
            SSDEEP:
            MD5:99D1F360A6E7E8397C64A5448532CA65
            SHA1:E091AFD8D6983A98EE3662706281532EF02BF08C
            SHA-256:48CE77EF8B9D3715D6565F418F6A9DFD8E7308ED7EED1D6AC0FEEE0C3D542930
            SHA-512:95DB9736D9DFD9AEA6F17085F59C9E0F5AB370D4606FA25EBF771248AABA2982DD1B13E33A0467BDAE70D3914A1C6D86121F3937FF8444639AF2EFA2F00C077C
            Malicious:false
            Reputation:unknown
            URL:https://www.googletagmanager.com/gtag/js?id=G-S9ESYSL6PQ
            Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":6,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"","
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 23409
            Category:downloaded
            Size (bytes):2853
            Entropy (8bit):7.921153708398815
            Encrypted:false
            SSDEEP:
            MD5:0DCCEB882E5A3B77D82454D2B3B0CF57
            SHA1:21D2ABE712C9B0C9F6F68FBA5E71C04291F69ECD
            SHA-256:9A91AD405866872D0D4C1AD89D39477AC4436B9107F87642B13BDA64895548CB
            SHA-512:6C756D52A6486C18FFC3975CBB0186E4EACD97BA841DDC134F67E96281E3AE7DC4693B942E55F15092EA841CC1DA6D14F6ACD0D43589A8A080505E113760A13E
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap-theme.min.css?ver=20150930
            Preview:...........\]o.8.}._.EQLR.,..G.b....@..3]`..>P...cK..4)....?d...+k.yh..1.{x.syD.....O....YV.eNN...p...}Y.v...A]...........t|o>.V..9_..........k.).iZ..yH#.;.?~...CM..............,..IQA.>}...~..u9s.2.F$.W]..iL......q&~:......!.iQ...$O.t...O.'Q.......xN...7a....>.......S.4..Z*...jR.u...e.U<o..};..2.....+.(E;.H....i........V.(....w.2..$...d....,.qY5.f..lj..c..$8.H.........V.6....[..f.zX......[..,m6..Xo,K..qB.Q5R."G.j.j9.L.|B.*.9j........@..YJ.6>.LW.$..SA+c.k..Y.L:..I.d..2g'.p..< ...<.DrZu......b..x....m=".$.$..s.%4-o..4a..7yE=v9s.{}. d......jr.q.0..C..ev..yv.a...2....j....*N...cw.}........KN."...9.....=..%....!.g...*....i.U...._..o'....+MyL.....m..DI...M..x.'.4d..^E....a.j1.......>.Js5...'.SV$e....X.....4...nAG.e.\.uz.l...|..+...pu.|...R.m.v...Tj;M..C..Ak_3.IO.......>p..*.-..B.X.I.f....f..Jk{.\.h............M......EE._.V.O..uN.E.H.w./......>..U",.........2T$.fm.C^......%.].-.}....}.U........>p..).H.\..f.2.Y.w.9V"....)..D.p.D.|.U[".4 ....
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:Web Open Font Format (Version 2), TrueType, length 24268, version 1.0
            Category:downloaded
            Size (bytes):24268
            Entropy (8bit):7.991233344683517
            Encrypted:true
            SSDEEP:
            MD5:106BEA653D604AC457079B1BE8618A5A
            SHA1:53D6444EE94A43ED8DA3F97279ED9A3E4681C927
            SHA-256:F012A09671A067D6B1FE89A880C3C02B3E2B7E86BE5EBB95FE529275F2219839
            SHA-512:BC0C3DCE1EA62406184F3FCDC0B49AC7B03BEC3EC9E15AC67320570DE6BBF531CE62C757EC335ED212A9BBEE94A1690915A1F3802FE5724EE1ADAFD9B0FB298C
            Malicious:false
            Reputation:unknown
            URL:https://fonts.gstatic.com/s/notosanskr/v36/PbykFmXiEBPT4ITbgNA5Cgm20xz64px_1hVWr0wuPNGmlQNMEfD4.106.woff2
            Preview:wOF2......^...........^W.............................Z?HVAR...`?STAT..'*..i/l.....l.....~.0.z.6.$..V. ..0. ...$..~.h..c..........|..tT.4.~...@[2.z.*T*.,.`'#....af.......Zo....v..3.:I...*...\...@;.hd.!o...Bg'%..:........j....Y....O.\7..B.h.....8.k.]....._...".P:.P.#&.w......m..Q.p..xO.S.. ......p,\+.,.l]..Z......k^.5..5..v..&O<.......F.Gs...g...n.7.....4.B.x.(.i'v..v....2.v.v.s..........H.....'...z.A..N....gf....{..T.s.}.`Q..;?].E.L0.Y.-......LW+..~..3.^Q...N.^H....#.. ....f.1.A..N.m.k....$.....,.A...qB....s.]..Z..t._....|Q....~....Pi..%7.sR..f........{.'...R./d..X.,Q....(.#T@.3.bWY!kd...@...U..:.+5....+...P.2.s.%]4j.{...H.s.J.".J/..F .).JR.+.Rg..(......`=.....J..ri...T.r.q.2...f%0NW..O..\..{..w:...l..$..ER.8.].~...F..p.......z16.^k....0"r..w.lO...O. h...Y.#Gn....."M....).y...\.I....&..i3.n`....v`l..1...G;....V.z4c.(?..w..h..{.!a...u`.pQ.........|D.e...E=.G....Z.:.;...}(..L.J3.....-a...._....=.h..........@.L.o.M.i.^.....,7b4...)_.TJ5...AR..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):36029
            Entropy (8bit):5.119697368807456
            Encrypted:false
            SSDEEP:
            MD5:853F44F8A3814F75CD4556FBDCBE5D26
            SHA1:B3BB2FFD8DDA9CF07A163A754595E57678A9F9B8
            SHA-256:F418E6B5416F03CBC22B24F481582E2D55EE0F7CA6989C562B59F12C9229214E
            SHA-512:5901FD98DE0BEED364D6A9F5A1608A135A77FCAB7B30943C89D85C38F59DC7D31F3151E19123D2BCEE46C243C1BE7E5512B05A6F204C0FB4904AB238454D90A7
            Malicious:false
            Reputation:unknown
            Preview:.if (typeof wm_indiv_stats == 'undefined') {..wm_indiv_stats = new Object(); // object to add the individual parameters.}..(function(){.../**.. * Creates the wiredminds literal object and returns it... *.. * @return.object.. */..function getWiredMinds() {...var wiredminds = {.....getlist : "",.....www_server : "www.count.carrierzone.com",....app_server : "www.count.carrierzone.com",....cnt_server : "count.carrierzone.com",....app_server_proto : "",....cnt_server_proto : "",....numberOfCalls : 0,....wm_track_url : "",....wm_track_alt : "",....wm_cvid : 0,....placeOverlay : false,....placeHeatmap : false,....placeOverlayMenu : false,....overlayKeyLength : 32,....wm_page_name_value : null,....ovk : null,....overlayScriptUrl : '',....validateUrl : '',....still_alive_interval : 5000, // msecs!....still_alive_time_max : 30*60*1000, // msecs!....still_alive_time_remaining : 0,....still_alive_request : false,....use_image_container : true,....wm_use_ic : 0,....cntParamContainer: {},...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:Web Open Font Format (Version 2), TrueType, length 25948, version 1.0
            Category:downloaded
            Size (bytes):25948
            Entropy (8bit):7.993110825371213
            Encrypted:true
            SSDEEP:
            MD5:F286F5E8A1B0D422E9C38D9E6075CB22
            SHA1:A1D20A0E8F8FEB0DE902531E9740D9A5722DD82F
            SHA-256:6B46737EC17D04244EB04C2C164CF604B1D41E5176E524A536EEFDDA3DE056A5
            SHA-512:1E5728D9494D29E550DAAF6712D6251120262F9D7C136273BAED3C93D934167F9205FF3779674A9A9E45134DA30667AA36038FB1698CDE9003EAE15E2CDC0651
            Malicious:false
            Reputation:unknown
            URL:https://fonts.gstatic.com/s/notosanskr/v36/PbykFmXiEBPT4ITbgNA5CgmG0X7t.woff2
            Preview:wOF2......e\.......(..d..........................."..Z..~?HVAR.T.`?STAT..'*..l/l.....H..;..$.0..n.6.$..B. ..0. ...$..D.y.52.)F.m.xp.R.W..1.8X...>......h......)2VR.k.m..*.U.k..6T#..)z.....(MK.T.......ri...VU.v.U...VN....uW......B..F..`.......{|.}....|.....q.......Cr...s..I..+!..G H.S.-V.k.u......b.8y...[.F...u..]z..rb...df......$@ HM.fej..@.b...1...!..-...1..#F.-VJ.....x....x.........:.B.].Q...C^...v|lP..,*6"Gn.*..........0..O..N(:U.xP...9+.2..W......Ji..Sq.E.0....3.......7..........L.F.QnM:.F.&.."..(..0......"o....:{.......4Q.....?a.T.`h..T.S\Hjke%<....w?.....-..4.@.*..O...,I..../...BN?b..:Q.V...g....`E...<..(K.<. ........Kf+.WZ.M....u..yi.2..?.Tr..f?. og...$]q..........7|..@..S.k..........8.<.....6.\... ..0....P...5.?u.................IQ../....!..sC.e....*].{..RQ.[.....v..A.>..)`.:..n...A...)z.4.*,.i..:.c.(2V..\..R/.%...p..q..'..........}Z.z..~..d@..!..vt.1.....Os.hQ.....8f.9f.8b#.H.Z...gY[.3r3zXq......3...B.f!.(...@ ......b..'.n....'..I..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 24998
            Category:downloaded
            Size (bytes):6119
            Entropy (8bit):7.964746082158884
            Encrypted:false
            SSDEEP:
            MD5:8398448105BE72DAEAB989014256526A
            SHA1:1BF21FA3FC462E0EAA13850980CDB39B111510C3
            SHA-256:10E21C5ECBB8E568FCBF6AD4C28FA5D8F44EE4AE5970E2137A9F38BA88C91504
            SHA-512:8699ABCC91D5B814401B36305D30377C39F2014CDA78BCEA5C58254C294ABC16683719F904BF6A2C18C5BA6A5A2CE0FBB2D8B7E3678891C99620D5F835AA4292
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/favicon-96x96.png
            Preview:...........]..6.....w@.....wR..d...g..x.qM....$.).!..:=].....O....J..U.jK$p............>...k2K...........&.W/...h._7.@...H..ss...F.._.`.1..)iO.[..;D..,.#7L...|..}.%I...e.\.S...s..).d;.+(@...w..H........l.\)BZ.....;.RvhB..........|.r...o'n.....<.$r..gm.M.s.'q....9Q..nu...G..v.sy.g.?q...*.m.I..LD.s..W.1.I..cR.,..&.......~.."6.n*...$.!...ys.....u.x...............Za.q.0M3W.N\.u.@]]..Z.".X.&.0....c.Z......Y...@...E.Y.....!dp=... Y.u.X..3..;Q.:.`.{.`C_.E.'.......V..8.z.8...6...zq.......'K.'..R.9xI..9..XA.M.I.\.... .....x.....9..g,A.W..[.gIP2cs&.;......g4......O..H.ey..[.A...-]'.];.,.$~.%..&.........a.L.H.%q...f:..r.M...W4.....'.........|.{......'...[.!.........JL^\.......-q....:!~..I.....o...]..c.......Lr.....[Q0......5.+.7R)...y..(.ZD...r.8y.X<c,i..w[.P.{..U..qD...A*7k+5+4 O.....o{....P)..C.0+\.<w}....g.uO..zKt.V.V.........<..3r@.p.-.v'..^(....D.\(.}C>..`. .K.I M.."....r!.../.$.oo."..U..-_...u.a%Hi...}.....")....GC..+H\I.B.1...]"..av...&.Ch
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text
            Category:downloaded
            Size (bytes):7539
            Entropy (8bit):5.493537609019905
            Encrypted:false
            SSDEEP:
            MD5:D991883786B331A9AADBA5C75F69E2DA
            SHA1:616589D5DC229739BCD00EEED1D18E6E3B7802F0
            SHA-256:236E2825FB0BF02806FE428B48B72C2B546AEAA2FD02106C740392B0EADE381C
            SHA-512:1CEE8AB12724CCC974D28DD3F85F94BDA0C1E7380756B9DA481DCE51A2E5DFFF7EDE17C23E5CFAFD1DE4B56C42BC6AD6D79DBD87665683A1EF6212BAC04CDE13
            Malicious:false
            Reputation:unknown
            URL:https://fonts.googleapis.com/css?family=Roboto:400%2C300%7CNoto+Sans:400
            Preview:/* cyrillic-ext */.@font-face {. font-family: 'Noto Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/notosans/v38/o-0mIpQlx3QUlC5A4PNB6Ryti20_6n1iPHjcz6L1SoM-jCpoiyD9A-9X6VLKzA.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C8A, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Noto Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/notosans/v38/o-0mIpQlx3QUlC5A4PNB6Ryti20_6n1iPHjcz6L1SoM-jCpoiyD9A-9e6VLKzA.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* devanagari */.@font-face {. font-family: 'Noto Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/notosans/v38/o-0mIpQlx3QUlC5A4PNB6Ryti20_6n1iPHjcz6L1SoM-jCpoiyD9A-9b6VLKzA.woff2) format('woff2');. unicode-range: U+0900-097F, U+1CD0-1CF9, U+200C-2
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 59946
            Category:downloaded
            Size (bytes):12758
            Entropy (8bit):7.983198331791621
            Encrypted:false
            SSDEEP:
            MD5:0772C7A51019BFC117208874B3D4007F
            SHA1:9B1A368C890B1834D0BBC5E739639ADDAEEE750E
            SHA-256:8E41787B96ED4CC4174B7DF7A4F58C00B279BD3CF6A6A3B6CFC883D8FC36163F
            SHA-512:4CFE8C94F07ED59976C126726A46888F8546E43ADD531E2BBADC7AE8B8C9622613A18F41EDFDD79DBADCC47D6A012A582AB1920C1F064D0745AEBAE54E8B31AA
            Malicious:false
            Reputation:unknown
            URL:http://ionl.ca/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.17
            Preview:...........}io...g......d..n..%........g..>.I6..I6_wk.A@....,@...{.. ....~.;....Iil.......Sg..S...O..x..,h.%...L..9...$';...%..jV...n...,.. ...(O...*......$/..>!...j.....q..;&.....v...,.*/.|..(/.y..Z..7.%.8....t1..2[.l...&..)..,.......M.,.......m."o..$oN....gG...._.....o?.....y...9<9}w....*......2.....b9...."[$./..e...< .8..@.PK.L..e...[-.............h.#.F..l.1.(...u.F..,3 ...<..ez.....b.....Q.(.l6+....OA..'..Q...H..O..S.YYf.}......K..sx.`.3Z0.}....b..O..f...v.(.x<..........'L".,...H.....3.-b<]..2[.HvB...R.."4..l..M^L&.|..a.$p..;K.I F9....g2.n.I1..=..~wzt..|}x~...2..`...6.......=..2.Y.(...:Y....U3-....B.HRB..3.{.%..?..b...5....4}...2.9:...e4..9)2.Mi...l)...F.xX..K..mh`%.YB!Il..G*.\..j]...@Sj.Y..%l..A.cJ+..a..*VUSPl....m..Q.S.......!.d...(BD.<^..8O..Y4.$W(>.....N..M."..0....B...K.z.>...N..-....Z..:..Q....J_.E:Lgiy.$/...F.G.......9.@M'.6.^..-.4%\.`..f....`.,...*.B.@.B..\.%.`lF...6..?..J.L.......N......E..YH`./.Z.5_C)F.......M....%......T..3y!._
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):4119
            Entropy (8bit):7.949120703870044
            Encrypted:false
            SSDEEP:
            MD5:000BF649CC8F6BF27CFB04D1BCDCD3C7
            SHA1:D73D2F6D74EC6CDCBAE07955592962E77D8AE814
            SHA-256:6BDB369337AC2496761C6F063BFFEA0AA6A91D4662279C399071A468251F51F0
            SHA-512:73D2EA5FFC572C1AE73F37F8F0FF25E945AFEE8E077B6EE42CE969E575CDC2D8444F90848EA1CB4D1C9EE4BD725AEE2B4576AFC25F17D7295A90E1CBFE6EDFD5
            Malicious:false
            Reputation:unknown
            Preview:.PNG........IHDR...P...P............IDATx..].xU...[..V..*).Kk...V.k..J]jKEl?...t...!.{.,...E........@....F.%.....B...N.y..w.....I{.o...;.s..3...WH......./.zBp.o,XW.......#Z.f...|mvD..9..F........y..o....1^.743l.......v..#.c.E&.e..hU1.{..........._cZ..We.v.....f.w....(..6|.Y.. I:x..-.&.......D........<.6.6.l....T..)...|....#..$g...VN.......!'/6.w..B.h.}....EV.......k.7" f.}.G.~#..M..+....G....iB......]..?+......'.j.GB..P%......\........../..%...&.8E...".........44.J...1.........S...........d.j..]ni%._..9.{.O?.H..6T.|A.GC..g...U.oDEt,?.0....~....q=.y.~.9.Z......c...v.._....$.0.2...F.9a.L..)..l...2...w...I..&....Vg......H.I..r......./....z.`..+...Z.^U.=..5aBpb..0< ../>.9.c....".I..0.3N,}}....|]Fb...Q.......W.....OQ..y;.....|.37..}.....(c.....X..`xX).;......<5S....>.9..G.:..=..0^.......l_<G......H....C.O.*.....Hk{..{....]Nc..B.8..}%>..w....Z...).....\..>....c..2...&..0'.DZJ.'~{Y....I....?........fR.a......;.<..lRG..n.....Q......Nf.6.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:gzip compressed data, from Unix, original size modulo 2^32 119386
            Category:dropped
            Size (bytes):45391
            Entropy (8bit):7.993825622568058
            Encrypted:true
            SSDEEP:
            MD5:C6DDFD01F75AADF9B170EBCE56937F23
            SHA1:0519A8BBA9334C2DD68E279C94DC2534F1778F34
            SHA-256:44A53F624C89864109FCCD0B722BCE90287B1EA9D02FD6D475E9D66368300D44
            SHA-512:A8D8F29CF40ABE0F79DF0081990EFC4B8B87873994C9D703BEADC1E04488E82D52036353A6A85E15928CC92435EDA05CFA17C9B1B5F752E7E15C293DE3C6A361
            Malicious:false
            Reputation:unknown
            Preview:............y{.F.?.....{ .h....r..js...._.d.z ..a...C.E...S}. )'....X..}VW....;......o..j...?...g./..{...u.......(.[..=...m!..$L..q.&.&..i<.....:..E.&..7.B..7-.OU..^.y.z7..E.J/['i:.[......no.....YO........./.d.n..w..f.H./.&....w._..iv.eQQfI..~t;O."..H,.$.. .....cp.\.t...F.t....E..x.2..^..L..,D.dD.....+.S<z.......e.Do.t.e..g...r.e..4.........2Y..S&...i..n.....f..tkK..Ez\dqru.^mm=..z^A`..Q.L..4r..x..s~..:.)...........-....'........5.:)7.H3.bk...UKU!.e&u.FYD(.&.t.:.....].C)a9-.U..Q.4.].P.p..\x.i.2..b.G3M......k.(:[..q2.~....~e.Q".ye.C.....}_..>Z.F."..A_Dh.]...Q.h..E.A..0.}..`.U...c..G$..\...{..0kA~.........Es.......*o.~....%.."...o;.........x......8.!.R.&.7.<"..l...W41.u..T.......i.?}u..._..Z....?...u..m..7,.I..^.E......(.......E....G.lgF9.8.*.G...)..l;U/.?..>vU....4...,... .$p\GT._~.)l.;k..\[....u.LLj..*5.GQ....t~..W....n.....u.p..2..t.q.t'k......I. .....%.|........<jaM.".(.w..%..D:..Gd.)..3No.G..I.HL....j....J...?...?.I.N.1..M....2..a.#.
            No static file info