Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://belasting.online-factuur.com

Overview

General Information

Sample URL:https://belasting.online-factuur.com
Analysis ID:1581759
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected suspicious Javascript
AI detected suspicious URL
HTML page contains hidden javascript code

Classification

  • System is w10x64native
  • chrome.exe (PID: 2748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: BB7C48CDDDE076E7EB44022520F40F77)
    • chrome.exe (PID: 2868 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2192,i,11073809685410328450,13977048154993170284,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2204 /prefetch:3 MD5: BB7C48CDDDE076E7EB44022520F40F77)
  • chrome.exe (PID: 4712 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://belasting.online-factuur.com" MD5: BB7C48CDDDE076E7EB44022520F40F77)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: 0.2.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://belasting.online-factuur.com/... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to potentially malicious domains. The use of an iframe to load additional scripts and the obfuscated nature of the code further increase the risk. While the script may have a legitimate purpose, such as a challenge platform, the overall behavior is highly suspicious and indicative of malicious intent.
Source: EmailJoe Sandbox AI: AI detected Brand spoofing attempt in URL: https://belasting.online-factuur.com
Source: https://belasting.online-factuur.com/HTTP Parser: Base64 decoded: 1735421088.000000
Source: https://belasting.online-factuur.com/HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\scoped_dir2748_1285052954Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_2748_377767228Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.28
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.40.147
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.21
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.21
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.80.3
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.21
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.21
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.80.3
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 239.255.255.250
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: belasting.online-factuur.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=84WOhuCZeF70ZDozQU2xqv7HitcDpiA%2BbxYxYrYE5Eo4TgI54JEaVcSXtk%2BuPkKPUq2nr88QYc5ZP5gdBPitYG2XguFMADcDXLVDAgTz9wTsaqcAnc4q4iIai%2BrfMWL6u99IySju9%2FEzHOczdxcy HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 392Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficTCP traffic: 192.168.11.20:53331 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:53331 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:53331 -> 239.255.255.250:1900
Source: global trafficTCP traffic: 192.168.11.20:53331 -> 239.255.255.250:1900
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: classification engineClassification label: mal48.win@16/15@10/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\scoped_dir2748_1285052954Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2192,i,11073809685410328450,13977048154993170284,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2204 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://belasting.online-factuur.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2192,i,11073809685410328450,13977048154993170284,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2204 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\scoped_dir2748_1285052954Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_2748_377767228Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
2
Masquerading
OS Credential Dumping1
Network Service Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://belasting.online-factuur.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
belasting.online-factuur.com
104.21.63.179
truetrue
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      www.google.com
      142.251.40.132
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://belasting.online-factuur.com/true
          unknown
          https://a.nel.cloudflare.com/report/v4?s=aL9JO39GfHrwbe2z9VqwKaI1sfooELu0hz%2FfSuKSgNIn41pUwyTrJ5g5WAJK2Bp%2Ffaol%2Bpuo%2FVvxhW15RM5fd9URtYRnc8jwAuGvj6grsEU04BmwvalnwC%2B%2FnTelkLiFu6SzEsOe7VBYl%2FtdMVjLfalse
            high
            https://a.nel.cloudflare.com/report/v4?s=CQs5dvdRm4qbTB0CTrYWqoZpFh2GoJ%2Fhj6znbq%2Fbxj3LPdpF5d8ujZL9mGOcnVJS6B9xqjZSQTYLmTflrS6s%2FucqJ%2F%2BJHAGyn7MH1xkkfYPNq4XStOfXw2t7uKKQNwTDaPSACQ5Cul2uNPMu6E%2F2false
              high
              https://a.nel.cloudflare.com/report/v4?s=84WOhuCZeF70ZDozQU2xqv7HitcDpiA%2BbxYxYrYE5Eo4TgI54JEaVcSXtk%2BuPkKPUq2nr88QYc5ZP5gdBPitYG2XguFMADcDXLVDAgTz9wTsaqcAnc4q4iIai%2BrfMWL6u99IySju9%2FEzHOczdxcyfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.251.40.132
                www.google.comUnited States
                15169GOOGLEUSfalse
                104.21.63.179
                belasting.online-factuur.comUnited States
                13335CLOUDFLARENETUStrue
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                172.67.171.151
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                IP
                192.168.11.20
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1581759
                Start date and time:2024-12-28 22:22:30 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 4m 34s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://belasting.online-factuur.com
                Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 128, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@16/15@10/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): dllhost.exe, TextInputHost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.80.99, 142.251.40.174, 172.253.122.84, 142.251.35.174, 142.250.65.238, 142.250.80.14, 142.251.32.110, 142.251.40.238, 142.250.72.110, 142.250.65.202, 142.250.65.234, 142.251.40.138, 142.250.64.74, 142.250.80.106, 142.250.80.42, 142.251.40.170, 142.250.64.106, 172.217.165.138, 142.250.80.74, 142.251.40.234, 142.251.41.10, 142.250.72.106, 142.250.176.202, 142.251.40.202, 142.250.65.170, 142.250.80.110, 142.251.40.206, 142.250.65.163
                • Excluded domains from analysis (whitelisted): clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, www.googleapis.com, dns.msftncsi.com
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: https://belasting.online-factuur.com
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Zstandard compressed data (v0.8+), Dictionary ID: None
                Category:dropped
                Size (bytes):4214
                Entropy (8bit):7.933386470284068
                Encrypted:false
                SSDEEP:96:Pde6zxnfC9csVpsB6jYoYy063y+cPHCv4NDrdicmNN9L:x96/fjZYy063Pv4Nr6d
                MD5:23D1060D172C886ED94A903026EB2C49
                SHA1:395BCC518E1A1D31C28E9A2688DBDDFF61AB3B8C
                SHA-256:66416D0F22756D65ADF9A4F045825CCC6AF49A414170779602F0542630D076DF
                SHA-512:635D14D6192256BEC4FCAB3E665CE962F55F4578741BDC3B2D498B758813B2B456936F7C52DC8DFB106C072D7C201E4FD10C4F42AB4FD5D306F5F91DD08378EE
                Malicious:false
                Reputation:low
                Preview:(./..X4..:..//.d*m..L.m..3...U.i......h.p.....G...x.^.............0...{...w...4.\.'...@..P....}...|.....}.;.0._....q._...8...z.c.r.../zy._..\....x.._.1n.3......*~..0,.D2./.Uh...Q<.....r....;T...'U.Y.(...~ao.-./.8..eu.......q`]U.....T7.m.2...7...7.l.n...n8.".Y..eu.;...j)..<1..(.q.+x..`....r90.v}(4.e.}(.bNa?`@.kX.A.1B.....|..a.H..1...,.[.......C/.v...A...5,....g..`..1}...k).n3.b...~!..7........._.N.....e..D3x......w..T..;..0.x/<.....Z.nk.R.\.`a.~........{<..k......~.).k<...-.o......it...~!.C..... ...;.q...3.q.~q..*Ou.-.6.....f......n.x....RU..x..+.J.V..~.N*5...<..s..P........o_.R..~...3.....DR!..4......w.nz~!h:2.........s9...=..{tk.b.n...{tg...b%.....;rY....>.....a...=..H.......`.......3.,..?..(....r...../@K.C......^.j._.....#...x...R..@.>.....$@.;....G..aD....UK!.........kR.l...2,{.....r}VO.J-.n_.J.f...J-..@*....,..4.)A^0.'F.c@...x.#.R.).YywGo_...AC-..(.).B}....R.9..bT[..g.%H{.B*..W..s..#s7...C....c.......]...S..PJw%@..Lj9....f...-..m..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 178 x 175, 8-bit colormap, non-interlaced
                Category:dropped
                Size (bytes):3213
                Entropy (8bit):7.553565995366911
                Encrypted:false
                SSDEEP:96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk
                MD5:0D768CBC261841D3AFFC933B9AC3130E
                SHA1:AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7
                SHA-256:1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0
                SHA-512:CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F
                Malicious:false
                Reputation:low
                Preview:.PNG........IHDR.............n.t.....PLTE..........UU.@@.33.**.$I.@@.99.33....**.''.$7.33.00.--.**.((.&&.$1....,,.**.)).''.&/.$..,,.**.)).((.''.**.)).((.''.&&.%,.$*.**.)).((.''.&&.%*.$*.)).((.&&.&*.%*.$).((.''.&&.&*.%).$(.$(.''.''.&&.%).$(.''.&&.%).%(.$(.$'.''.&&.&).%(.$'.$'.''.&&.&).%(.%(.$'.$'.&&.&&.&(.%(.%'.&&.&&.%(.%(.$'.$&.&&.&(.%(.%'.%'.$'.$&.&&.&(.%'.%'.$'.$&.&&.&(.%'.%'.$&.$&.&(.%'.%'.$&.$&.$(.%'.%'.%'.$&.$&.$(.%'.%'.%'.%&.$&.$&.$'.%'.%'.%'.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%&.%&.%&.$'.$'.$'.%'.%&.%&.%&.$'.$'.$'.$'.%&.%&.%&.$'.$'.$'.$&.%&.%&.%&.$'.$'.$'.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$&.$&.$&.%&.%'.%'.$'.$&.$&.$&.%&.%'.%'.$'.$&.$&.$&.%&.%'.%'.$&.$&.$&.$&........tRNS................................ !$%&'()*+,-./01235678:;<=>?@ABCEFHIKLMNOPQRTUVWXYZ[\]^_`adefgijklmnopqrsuvwxyz|}..................................................................................................................
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:gzip compressed data, from Unix, original size modulo 2^32 24051
                Category:downloaded
                Size (bytes):4515
                Entropy (8bit):7.956467386800229
                Encrypted:false
                SSDEEP:96:4p4l0h92B45gLm/Ie0f5G7dTj4URSht8vOcrIu9JL:I4l0hoW5gLNA7dH4Ucht8vOKX9JL
                MD5:99A8B213866426D482DB5C874E91CFC1
                SHA1:49BFFD206943C4A850376205EE720A87D08CE8CC
                SHA-256:D117A3A72EDA86BB4E103C5DAD01F6828F9454E9232CDD763806D57FF6D3DEBE
                SHA-512:CACDEA20F37A4FD5A551FAA04A2916D467E197CCF971E7104E18A2213CF1F1EA3C84B7389C3841C5249053A1854C28C92A86A5E0986244A8F26BFC35792F15C1
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/cdn-cgi/styles/cf.errors.css
                Preview:...........<..r.......F[:Z,..F. H.....O...%.6.H...n......I\%.3....R...bUI........6..,k.Gy....rK&?...\..._..+.p.!5.~.......r..{(S.#.v....B~.....T.....@o.....a.<fP&.`Yt.W..&.O.<.2C'.U).p+#.D.c,?&..V~L....A.`..[<4rS_.2B.......d.)A..T...%Y.`+.~..`=H.5.W.g..\^.,c.C......FY.Y.:P..;.k..U...v.P..-...&\.B.Ly.*.~(m2A=.].k........[..#...Yezy..HCy.@{F.!<6.(P}>.....l........lQO...}..(.?.{x.....D.......)...Jt....`.j.].....8.2K.u..&S.C..m..*.Q.f...5%.8PK-...'?..P....T..........h-..^.d..2y.5N.!hO.j.:..&..I...a..~.~9...N.-.gI.v.%.7:...".&......!...%...d..m.....;*...r.|T..zx...9.q{........m.j.WO.B....MSB...zXm..D.............1............gXo...u?l...o.lj...7.."Pn:Pw~.[tR.2..6W........... .zLFD.....~.....m........{...t.....D.3.%..6Q.I.M.<M..}....@.u.@.@..M......2..%.......MK.g..qu.a5...!...QS.0...0.x..R.......g..+.V........8.Z7....$H}.zN....^..`..M4....*p........Tb.M.Y..a.6Wq#e.J.....C~........^........K.jN..5.a.t......X .P..?....R?'O6....6q.2q..................m\
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 960 x 53, 8-bit colormap, non-interlaced
                Category:dropped
                Size (bytes):715
                Entropy (8bit):7.3533249502413565
                Encrypted:false
                SSDEEP:12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/
                MD5:226DCB8F6144BDAAFDFBD8F2F354BE64
                SHA1:3785CC5B3BF52F8E398177B0FF1020B24AA86B8C
                SHA-256:8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB
                SHA-512:ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A
                Malicious:false
                Reputation:low
                Preview:.PNG........IHDR.......5.......r....]PLTE........................................................................................9W)....tRNS...u... ........IDATx....n.0....#.......?.f....I.B..g........O...hW...Y^.<..v..E..."....@D;u.#.h....WD.u...nq..vL...J?T.(D..&JtZ`&.....e..!.'m..5..$p.$..k`....+wCk.N=..(<....[.I.O4&.56..kR..O0.H`...%.b.Q........D..X...L.D..(.bT..... ..b+5I.+....W^. .....Y.....L.Ob.&26..IR.$0.y.^6*/..D..X.0_`..s.}..+S.. ..../D......I...ew..Qh.Nn......u.t0k.fX..b.&.!.\..I.cf..RgKC+2.M....6.)o. ..`c..M....../a.&....".Q.....uU.]@....j.......O.'......."....t....d...?z..p.q.Y.C...&0...a.C...&0...a.C...&0...a.C...&0...a.C...&0...a.C...&0...a/..Y.x.I....IEND.B`.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Zstandard compressed data (v0.8+), Dictionary ID: None
                Category:downloaded
                Size (bytes):1838
                Entropy (8bit):7.870601334580426
                Encrypted:false
                SSDEEP:48:eyE9NyzLqP40NHIRTQ9AdFWiJuuKfm9ByMyiA0L:eyE7yPqAIoRHAisuKfm9BdyEL
                MD5:9996FFA61F20C987ABE621C3FC7B1FF6
                SHA1:A48941F2E6F52F1CC7F87A46FFC2B87907A4C745
                SHA-256:1CF434E584E5124908C5B70636F457E707209BB764501EE3D709D6FAB9F6FADA
                SHA-512:EC491F20BD0D3AD026C78C12D84BC6D76C363CEEAED5D138EB5A73CACF3A26D518F3667B663B8F74270C57BF1CFA4B60AA676A8B1C2658345122E6B1C34CF061
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/favicon.ico
                Preview:(./..X.9.:g,.,...:.../p.D..z!Q.u...D.A/.,.].>....!.(h... ......_`.[Z...H.....DB...Qy.z.F....G....tR.L..J....6..Ng....96y....M".kH.#...j...J(..A.....^Mgu1.\3..My..~.NY{B...S+Yz.............E.zjz..M..W...%.....-...9.h.(T`..Jwr.f.Y.....Y3*x.?<......'l.......Y..<....h..**...i........&Th..D.....8O...6%...=R=9.4....;>..Z{p.'R=.......,xp...$...S....$.'.N-r\..5.yk....8.t...v.5.0..GnU....{kbxX...f..V..J.....%3t..tkV.Q.tNx.K............."wV#...".|...\.#....f..U...E..{..Zz5.|.<.7..Y..Y:......f.">yecU.c.[@".r...x...-..x.,1-...|.<....8iE..x.v6p.`A...AK.\...5..../..<......s:..^.RV><...y...Ug....mm.^.6..J%..'".R..H...(..sF..<5.'.......p...3..,mu..uI..z..|.)_...x.7..>ey.s...bkb...w..u.eJ..i.8.....\...."L.^...:..t^.p....d.K.>+:._...t..5.e.W.r......$A..L..Q....pkV.<Q8S5.v.I.G.k..r.B...Z......z......N..V9....d.2]....._%e..vr].{..........q......3"..T......<.....a1..t@ ..f..:..C.i8..s...S&.a....t.YW.A@@...$ ;.N...y.s@.........6i......1...$.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 178 x 175, 8-bit colormap, non-interlaced
                Category:downloaded
                Size (bytes):3213
                Entropy (8bit):7.553565995366911
                Encrypted:false
                SSDEEP:96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk
                MD5:0D768CBC261841D3AFFC933B9AC3130E
                SHA1:AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7
                SHA-256:1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0
                SHA-512:CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/cdn-cgi/images/cf-no-screenshot-error.png
                Preview:.PNG........IHDR.............n.t.....PLTE..........UU.@@.33.**.$I.@@.99.33....**.''.$7.33.00.--.**.((.&&.$1....,,.**.)).''.&/.$..,,.**.)).((.''.**.)).((.''.&&.%,.$*.**.)).((.''.&&.%*.$*.)).((.&&.&*.%*.$).((.''.&&.&*.%).$(.$(.''.''.&&.%).$(.''.&&.%).%(.$(.$'.''.&&.&).%(.$'.$'.''.&&.&).%(.%(.$'.$'.&&.&&.&(.%(.%'.&&.&&.%(.%(.$'.$&.&&.&(.%(.%'.%'.$'.$&.&&.&(.%'.%'.$'.$&.&&.&(.%'.%'.$&.$&.&(.%'.%'.$&.$&.$(.%'.%'.%'.$&.$&.$(.%'.%'.%'.%&.$&.$&.$'.%'.%'.%'.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%'.%&.%&.$&.$'.$'.%'.%&.%&.%&.$'.$'.$'.%'.%&.%&.%&.$'.$'.$'.$'.%&.%&.%&.$'.$'.$'.$&.%&.%&.%&.$'.$'.$'.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$'.$&.$&.%&.%&.%'.$'.$&.$&.$&.%&.%'.%'.$'.$&.$&.$&.%&.%'.%'.$'.$&.$&.$&.%&.%'.%'.$&.$&.$&.$&........tRNS................................ !$%&'()*+,-./01235678:;<=>?@ABCEFHIKLMNOPQRTUVWXYZ[\]^_`adefgijklmnopqrsuvwxyz|}..................................................................................................................
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Zstandard compressed data (v0.8+), Dictionary ID: None
                Category:downloaded
                Size (bytes):2218
                Entropy (8bit):7.895850367838391
                Encrypted:false
                SSDEEP:48:Ugd165r7atHCWIA0p7Mzn9USocbSwMxnDNAItilvUcaLE:t6Efj0pA79BobxJAIolsccE
                MD5:B696342DADB87CA1C146AB6FCEA00E8C
                SHA1:657B9329623B4EBA29C93C3966D50CC3A4EC8C79
                SHA-256:E25686A0D184174CA35146A4E4DB8D679BF0E17184E9AE416C79FFB053A2CA05
                SHA-512:399215A709206951764165BCC348A4D9581181C169CFEA1693AB3058C6229643919B12C00DE6939406144BFE26354E7CD7D1EE23B64FB130BE259C1FE30107F3
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/
                Preview:(./..X.D.z{..+.....D.*[.c..R.@...X...D*)..<.Y:...^.3.L.pW.@.H...A...L.....d@..pFmw...l9.........U..|.,.w!.c...A"$6Cc.+.D.*....26.....|}l.'.#S.s..)....)m.z....&|..QM.]j}..zK....m...%.M.cF)...W...qF...).#.a.:.u.h..S>W..pF..}r.D}...fD..r........ga"....._..Kc...?.b.(1......]*....K.])[o... ..%.3...a.`.mh.;=....R..A$.m9...$e..**..:...p6..h.e..7{...r..P...U..D..|+....2....}.T.........f@..q............~a..H.a_.)..~.4l..o[.......Sj).....w..H.]w.H..uy..k.5n..Sk[..!-..9..Y.6K..].~.2...?iY....Rf...{....UEiU.r.....s.u.........,.......&c.....)o.....~.9...X...NHX..{g..Mak3.V.Q....g.........w..r......Q.......-!HK..%.gY'.w..wq.[......Ts...]..A....y He..T...rb6.%V#t..4.........e.w...+{.7Z..)..73j%...s4M{....[.)m...=.s..m....b.M. ELL8..$.......iy .M.xQ^H...InJS.-Qc....l....4....E7.2. .e6...g.X..........m...U!-P.....S.t..Z.i.p.eq...^.........ncZ}......O.TK......{.........A.6...!.6l5.Jn....rK.^.....9........X.}.........-m{...i>;.j..[....o.............o..".6.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 960 x 53, 8-bit colormap, non-interlaced
                Category:downloaded
                Size (bytes):715
                Entropy (8bit):7.3533249502413565
                Encrypted:false
                SSDEEP:12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/
                MD5:226DCB8F6144BDAAFDFBD8F2F354BE64
                SHA1:3785CC5B3BF52F8E398177B0FF1020B24AA86B8C
                SHA-256:8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB
                SHA-512:ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/cdn-cgi/images/browser-bar.png?1376755637
                Preview:.PNG........IHDR.......5.......r....]PLTE........................................................................................9W)....tRNS...u... ........IDATx....n.0....#.......?.f....I.B..g........O...hW...Y^.<..v..E..."....@D;u.#.h....WD.u...nq..vL...J?T.(D..&JtZ`&.....e..!.'m..5..$p.$..k`....+wCk.N=..(<....[.I.O4&.56..kR..O0.H`...%.b.Q........D..X...L.D..(.bT..... ..b+5I.+....W^. .....Y.....L.Ob.&26..IR.$0.y.^6*/..D..X.0_`..s.}..+S.. ..../D......I...ew..Qh.Nn......u.t0k.fX..b.&.!.\..I.cf..RgKC+2.M....6.)o. ..`c..M....../a.&....".Q.....uU.]@....j.......O.'......."....t....d...?z..p.q.Y.C...&0...a.C...&0...a.C...&0...a.C...&0...a.C...&0...a.C...&0...a/..Y.x.I....IEND.B`.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Zstandard compressed data (v0.8+), Dictionary ID: None
                Category:downloaded
                Size (bytes):4155
                Entropy (8bit):7.940987590244948
                Encrypted:false
                SSDEEP:96:CFgZlRWaS5V1QCNz283wCELQVM2lT5KU3FC90Vt:Celc1iCkQVM2lT5H3FC90Vt
                MD5:F12C1AAE0A2B9E67AD4AF38AF99F553B
                SHA1:3F125EB11A84C577007EF43A3A72DB6D3FA5E1B1
                SHA-256:E26C11FBBD9208013356DF909F4F33F3D9078BF2D972A305DAFE855F0BF0CDE6
                SHA-512:02336A072BFD98200F71B83A91E2ED11756C3B592FC577C6C29F5EBA3D07B8D4C1D6E6D12A904D42D55BA3EF2BE92A381D17827A43123CF584000B822FA20C92
                Malicious:false
                Reputation:low
                URL:https://belasting.online-factuur.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/787bc399e22f/main.js?
                Preview:(./..X\....\//.d*m..L.m9.7...-z]...?3Z%.....0$....^...ux..............m........gR.......(..5.......W.3h(..W,x.e....|..P.......{.w.0....[....p..3.n.w.{._..}Q.+..>..s<..g...}.3....!J8...%.'..&..%....+.x..,.UU.*.Q<.....K$...TW..]..e.R........"..VQS...2...FU./Lu3..N.....@.c#.......4...6.|f1{....x..'.|.m4...w8..}`...]......c.....;..l.9.....P........-3`.]....ee.@.........#.~=....1../(.l...v}./z[.p.h...../D5<.....|....eu.2p.ZQ.....#Y....n_g.!F....@.......vR..9K..v.._...?~.W........^U....7.B....UU{._...Q...g.........Op.o\...c...S....m.J#.kmRi...#8........RU...Q<..J.V..~;.,.0G...dx.E...X..\z.....E.T...'f......Ao...%sLS..P.;q......#S.<..y.M1o.8......0H7...Hw...R.$...D.tK".@.+.A.'W[H...TH.U... .Z..=GM6Kl..~!..<{....5.>...hI~..<..{...E.>..n:.....dxv..+`KU.."!.\:.&..v....c...p".*..T..T...gY\...3...N.Z.Y:..p..F5.G8S...k>....P..`<?0~....y...~....Z+*nG..xU..-T#.:....X....`....0G....j.R...I...........v.U.b....<7.......t....%..Z-.....1..].P...ZY3.....S..P..L*.....e..9p
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Dec 28, 2024 22:24:37.763066053 CET49756443192.168.11.2023.44.201.28
                Dec 28, 2024 22:24:46.447077990 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.447103977 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.447244883 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.447561979 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.447575092 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.856965065 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.857327938 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.857342005 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.858288050 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.858563900 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.859441996 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.859555006 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.912615061 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:46.912625074 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:46.959460974 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:47.700493097 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.700536013 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:47.700738907 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.700808048 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.700864077 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:47.701023102 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.701040030 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.701065063 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:47.701374054 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:47.701406002 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.293036938 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.293227911 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.293433905 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.293466091 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.295305967 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.295342922 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.295455933 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.295475006 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.295538902 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.295550108 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.297010899 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.297106981 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.297303915 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.297326088 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.297764063 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.297800064 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.391402960 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.391763926 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.391803980 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.393049002 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.448662996 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.486274958 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.493916035 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.494149923 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.494215965 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.494434118 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.501276970 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.501317024 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.593682051 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:48.593717098 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:48.593986988 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:48.594263077 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:48.594283104 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:48.723160982 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.723814964 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.724041939 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.724054098 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.733256102 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.733256102 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.733270884 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.733274937 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.774494886 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.774504900 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.830383062 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.830884933 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.830897093 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.831218958 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.831231117 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.831378937 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.932635069 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:48.934634924 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:48.934667110 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.007509947 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.007971048 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.007988930 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.009430885 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.009660006 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.010340929 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.010457993 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.010500908 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.038604021 CET49779443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.038636923 CET44349779172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.038675070 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.038700104 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.038840055 CET49779443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.038865089 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.039216995 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.039237022 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.039450884 CET49779443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.039469004 CET44349779172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.042144060 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.042679071 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.042866945 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.042885065 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.043277025 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.044684887 CET49781443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.044711113 CET44349781172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.044867992 CET49781443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.045198917 CET49781443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.045217037 CET44349781172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.054254055 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.064693928 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.064711094 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.106834888 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.106852055 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.106945038 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.106950998 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.106996059 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.107001066 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.107080936 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.107100010 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.107254028 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.109822035 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.109843969 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.221752882 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.221797943 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.221906900 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.222131968 CET49776443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.222142935 CET4434977635.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.222419977 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.222438097 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.222672939 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.223006010 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.223018885 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.308248997 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.308464050 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.308720112 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.308732033 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.350356102 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.350373030 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:24:49.354373932 CET49783443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.354403019 CET44349783172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.354618073 CET49783443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.355056047 CET49783443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.355073929 CET44349783172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.400516987 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:24:49.618244886 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.618601084 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.618618011 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.619122028 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.619580030 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.619628906 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.619705915 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.635845900 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.635868073 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.636197090 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636214972 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.636754036 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636765957 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.636869907 CET49779443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636894941 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636903048 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.636905909 CET49781443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636933088 CET49783443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.636967897 CET44349779172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.636982918 CET44349781172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.637065887 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.637078047 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.637115955 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.637115955 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.637120008 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.637125015 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.637161016 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.637165070 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.637181997 CET49779443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.637181997 CET49781443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.659645081 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.682209969 CET44349783172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.732964039 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.733367920 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.733376026 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.839409113 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.846931934 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.847254992 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.847254992 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.847264051 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.853426933 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.853523016 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.853625059 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.853663921 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.853744984 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.853744984 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.853753090 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.853763103 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.854039907 CET49782443192.168.11.2035.190.80.1
                Dec 28, 2024 22:24:49.854053020 CET4434978235.190.80.1192.168.11.20
                Dec 28, 2024 22:24:49.878792048 CET44349783172.67.171.151192.168.11.20
                Dec 28, 2024 22:24:49.879065990 CET49783443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:49.903748989 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:24:56.863761902 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:56.863830090 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:24:56.863972902 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:57.958822012 CET49773443192.168.11.20142.251.40.132
                Dec 28, 2024 22:24:57.958836079 CET44349773142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:20.164325953 CET49763443192.168.11.2023.33.40.147
                Dec 28, 2024 22:25:20.966403961 CET8049765208.89.73.21192.168.11.20
                Dec 28, 2024 22:25:20.966639042 CET4976580192.168.11.20208.89.73.21
                Dec 28, 2024 22:25:20.966639042 CET4976580192.168.11.20208.89.73.21
                Dec 28, 2024 22:25:21.089737892 CET8049765208.89.73.21192.168.11.20
                Dec 28, 2024 22:25:21.474540949 CET4976480192.168.11.20142.250.80.3
                Dec 28, 2024 22:25:21.474540949 CET4976680192.168.11.20208.89.73.21
                Dec 28, 2024 22:25:21.477663994 CET8049766208.89.73.21192.168.11.20
                Dec 28, 2024 22:25:21.477926970 CET4976680192.168.11.20208.89.73.21
                Dec 28, 2024 22:25:21.570075989 CET8049764142.250.80.3192.168.11.20
                Dec 28, 2024 22:25:21.570214987 CET4976480192.168.11.20142.250.80.3
                Dec 28, 2024 22:25:21.597543001 CET8049766208.89.73.21192.168.11.20
                Dec 28, 2024 22:25:33.396342993 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:25:33.396352053 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:25:34.364384890 CET49775443192.168.11.20104.21.63.179
                Dec 28, 2024 22:25:34.364432096 CET44349775104.21.63.179192.168.11.20
                Dec 28, 2024 22:25:34.860353947 CET49780443192.168.11.20172.67.171.151
                Dec 28, 2024 22:25:34.860402107 CET44349780172.67.171.151192.168.11.20
                Dec 28, 2024 22:25:46.409576893 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:46.409600019 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.409827948 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:46.410172939 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:46.410182953 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.816850901 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.817307949 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:46.817322016 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.818031073 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.818466902 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:46.818578959 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:46.862062931 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:48.498212099 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:25:48.498496056 CET44349774104.21.63.179192.168.11.20
                Dec 28, 2024 22:25:48.498675108 CET49774443192.168.11.20104.21.63.179
                Dec 28, 2024 22:25:48.498861074 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.498935938 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.499134064 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.499489069 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.499538898 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.595834970 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.595906973 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.596107960 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.596513987 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.596566916 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.893420935 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.893910885 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.893923998 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.894275904 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.894704103 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.894807100 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.894824982 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.935302973 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.935312986 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.993736982 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.994163036 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.994175911 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.995131016 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.995368004 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.995683908 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:48.995769978 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:48.995843887 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.042244911 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.044486046 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.044500113 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.091412067 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.120604038 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.120646000 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.120820045 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.120918036 CET49793443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.120929956 CET4434979335.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.121319056 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.121334076 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.121633053 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.121943951 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.121953011 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.121963024 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.121965885 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.227926970 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.228030920 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.228209972 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.228291988 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.228291988 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.228305101 CET4434979435.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.228470087 CET49794443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.228612900 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.228622913 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.228753090 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.229192972 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.229204893 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.516576052 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.517025948 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.517057896 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.517971992 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.518491030 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.518562078 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.518740892 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.560046911 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.631124020 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.631658077 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.631689072 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.632601023 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.633074999 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.633115053 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.633305073 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.684962034 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.741911888 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.741962910 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.742204905 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.742369890 CET49795443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.742378950 CET4434979535.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.864902020 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.864948988 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:49.865036964 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.865200043 CET49796443192.168.11.2035.190.80.1
                Dec 28, 2024 22:25:49.865211964 CET4434979635.190.80.1192.168.11.20
                Dec 28, 2024 22:25:56.826658010 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:56.826781034 CET44349792142.251.40.132192.168.11.20
                Dec 28, 2024 22:25:56.827003002 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:57.954278946 CET49792443192.168.11.20142.251.40.132
                Dec 28, 2024 22:25:57.954317093 CET44349792142.251.40.132192.168.11.20
                TimestampSource PortDest PortSource IPDest IP
                Dec 28, 2024 22:24:34.073604107 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:34.826204062 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:35.591751099 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:41.845426083 CET533311900192.168.11.20239.255.255.250
                Dec 28, 2024 22:24:41.879908085 CET53567641.1.1.1192.168.11.20
                Dec 28, 2024 22:24:41.924695969 CET53533301.1.1.1192.168.11.20
                Dec 28, 2024 22:24:42.666616917 CET53519911.1.1.1192.168.11.20
                Dec 28, 2024 22:24:42.846662045 CET533311900192.168.11.20239.255.255.250
                Dec 28, 2024 22:24:43.862093925 CET533311900192.168.11.20239.255.255.250
                Dec 28, 2024 22:24:44.216947079 CET53535721.1.1.1192.168.11.20
                Dec 28, 2024 22:24:44.877612114 CET533311900192.168.11.20239.255.255.250
                Dec 28, 2024 22:24:45.070873976 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:45.830394030 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:46.350811005 CET5081053192.168.11.201.1.1.1
                Dec 28, 2024 22:24:46.350900888 CET5061553192.168.11.201.1.1.1
                Dec 28, 2024 22:24:46.445388079 CET53508101.1.1.1192.168.11.20
                Dec 28, 2024 22:24:46.446428061 CET53506151.1.1.1192.168.11.20
                Dec 28, 2024 22:24:46.584605932 CET137137192.168.11.20192.168.11.255
                Dec 28, 2024 22:24:47.522181034 CET5671453192.168.11.201.1.1.1
                Dec 28, 2024 22:24:47.522289038 CET6423553192.168.11.201.1.1.1
                Dec 28, 2024 22:24:47.660449028 CET53567141.1.1.1192.168.11.20
                Dec 28, 2024 22:24:47.714056969 CET53642351.1.1.1192.168.11.20
                Dec 28, 2024 22:24:48.495898008 CET5579853192.168.11.201.1.1.1
                Dec 28, 2024 22:24:48.496015072 CET5982453192.168.11.201.1.1.1
                Dec 28, 2024 22:24:48.592183113 CET53598241.1.1.1192.168.11.20
                Dec 28, 2024 22:24:48.593080044 CET53557981.1.1.1192.168.11.20
                Dec 28, 2024 22:24:48.835261106 CET5622453192.168.11.201.1.1.1
                Dec 28, 2024 22:24:48.835391998 CET5906753192.168.11.201.1.1.1
                Dec 28, 2024 22:24:49.029288054 CET53590671.1.1.1192.168.11.20
                Dec 28, 2024 22:24:49.038101912 CET53562241.1.1.1192.168.11.20
                Dec 28, 2024 22:25:04.356698036 CET53646511.1.1.1192.168.11.20
                Dec 28, 2024 22:25:11.402246952 CET53609121.1.1.1192.168.11.20
                Dec 28, 2024 22:25:26.127769947 CET53553161.1.1.1192.168.11.20
                Dec 28, 2024 22:25:41.906888008 CET53645401.1.1.1192.168.11.20
                Dec 28, 2024 22:25:48.498430967 CET4972453192.168.11.201.1.1.1
                Dec 28, 2024 22:25:48.498621941 CET6310653192.168.11.201.1.1.1
                Dec 28, 2024 22:25:48.594084024 CET53497241.1.1.1192.168.11.20
                Dec 28, 2024 22:25:48.595199108 CET53631061.1.1.1192.168.11.20
                Dec 28, 2024 22:25:51.573743105 CET53500371.1.1.1192.168.11.20
                TimestampSource IPDest IPChecksumCodeType
                Dec 28, 2024 22:24:47.714293957 CET192.168.11.201.1.1.1cb96(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 28, 2024 22:24:46.350811005 CET192.168.11.201.1.1.10x270cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:46.350900888 CET192.168.11.201.1.1.10xeedcStandard query (0)www.google.com65IN (0x0001)false
                Dec 28, 2024 22:24:47.522181034 CET192.168.11.201.1.1.10x163aStandard query (0)belasting.online-factuur.comA (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:47.522289038 CET192.168.11.201.1.1.10x73edStandard query (0)belasting.online-factuur.com65IN (0x0001)false
                Dec 28, 2024 22:24:48.495898008 CET192.168.11.201.1.1.10xa955Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:48.496015072 CET192.168.11.201.1.1.10x4bccStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
                Dec 28, 2024 22:24:48.835261106 CET192.168.11.201.1.1.10x5343Standard query (0)belasting.online-factuur.comA (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:48.835391998 CET192.168.11.201.1.1.10xf148Standard query (0)belasting.online-factuur.com65IN (0x0001)false
                Dec 28, 2024 22:25:48.498430967 CET192.168.11.201.1.1.10x3378Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Dec 28, 2024 22:25:48.498621941 CET192.168.11.201.1.1.10x6107Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 28, 2024 22:24:46.445388079 CET1.1.1.1192.168.11.200x270cNo error (0)www.google.com142.251.40.132A (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:46.446428061 CET1.1.1.1192.168.11.200xeedcNo error (0)www.google.com65IN (0x0001)false
                Dec 28, 2024 22:24:47.660449028 CET1.1.1.1192.168.11.200x163aNo error (0)belasting.online-factuur.com104.21.63.179A (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:47.660449028 CET1.1.1.1192.168.11.200x163aNo error (0)belasting.online-factuur.com172.67.171.151A (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:47.714056969 CET1.1.1.1192.168.11.200x73edNo error (0)belasting.online-factuur.com65IN (0x0001)false
                Dec 28, 2024 22:24:48.593080044 CET1.1.1.1192.168.11.200xa955No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:49.029288054 CET1.1.1.1192.168.11.200xf148No error (0)belasting.online-factuur.com65IN (0x0001)false
                Dec 28, 2024 22:24:49.038101912 CET1.1.1.1192.168.11.200x5343No error (0)belasting.online-factuur.com172.67.171.151A (IP address)IN (0x0001)false
                Dec 28, 2024 22:24:49.038101912 CET1.1.1.1192.168.11.200x5343No error (0)belasting.online-factuur.com104.21.63.179A (IP address)IN (0x0001)false
                Dec 28, 2024 22:25:48.594084024 CET1.1.1.1192.168.11.200x3378No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                • a.nel.cloudflare.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.11.204977635.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:24:49 UTC571OUTOPTIONS /report/v4?s=84WOhuCZeF70ZDozQU2xqv7HitcDpiA%2BbxYxYrYE5Eo4TgI54JEaVcSXtk%2BuPkKPUq2nr88QYc5ZP5gdBPitYG2XguFMADcDXLVDAgTz9wTsaqcAnc4q4iIai%2BrfMWL6u99IySju9%2FEzHOczdxcy HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://belasting.online-factuur.com
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:24:49 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: OPTIONS, POST
                access-control-allow-origin: *
                access-control-allow-headers: content-type, content-length
                date: Sat, 28 Dec 2024 21:24:48 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.11.204978235.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:24:49 UTC500OUTPOST /report/v4?s=84WOhuCZeF70ZDozQU2xqv7HitcDpiA%2BbxYxYrYE5Eo4TgI54JEaVcSXtk%2BuPkKPUq2nr88QYc5ZP5gdBPitYG2XguFMADcDXLVDAgTz9wTsaqcAnc4q4iIai%2BrfMWL6u99IySju9%2FEzHOczdxcy HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 392
                Content-Type: application/reports+json
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:24:49 UTC392OUTData Raw: 5b 7b 22 61 67 65 22 3a 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 39 37 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 32 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 36 33 2e 31 37 39 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 62 65 6c 61 73 74 69 6e 67 2e 6f 6e 6c 69 6e 65 2d 66 61 63 74 75
                Data Ascii: [{"age":1,"body":{"elapsed_time":972,"method":"GET","phase":"application","protocol":"h2","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.63.179","status_code":403,"type":"http.error"},"type":"network-error","url":"https://belasting.online-factu
                2024-12-28 21:24:49 UTC168INHTTP/1.1 200 OK
                Content-Length: 0
                date: Sat, 28 Dec 2024 21:24:49 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.11.204979335.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:25:48 UTC577OUTOPTIONS /report/v4?s=aL9JO39GfHrwbe2z9VqwKaI1sfooELu0hz%2FfSuKSgNIn41pUwyTrJ5g5WAJK2Bp%2Ffaol%2Bpuo%2FVvxhW15RM5fd9URtYRnc8jwAuGvj6grsEU04BmwvalnwC%2B%2FnTelkLiFu6SzEsOe7VBYl%2FtdMVjL HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://belasting.online-factuur.com
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:25:49 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: POST, OPTIONS
                access-control-allow-origin: *
                access-control-allow-headers: content-type, content-length
                date: Sat, 28 Dec 2024 21:25:48 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.11.204979435.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:25:48 UTC575OUTOPTIONS /report/v4?s=CQs5dvdRm4qbTB0CTrYWqoZpFh2GoJ%2Fhj6znbq%2Fbxj3LPdpF5d8ujZL9mGOcnVJS6B9xqjZSQTYLmTflrS6s%2FucqJ%2F%2BJHAGyn7MH1xkkfYPNq4XStOfXw2t7uKKQNwTDaPSACQ5Cul2uNPMu6E%2F2 HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://belasting.online-factuur.com
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:25:49 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: OPTIONS, POST
                access-control-allow-origin: *
                access-control-allow-headers: content-length, content-type
                date: Sat, 28 Dec 2024 21:25:48 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.11.204979535.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:25:49 UTC506OUTPOST /report/v4?s=aL9JO39GfHrwbe2z9VqwKaI1sfooELu0hz%2FfSuKSgNIn41pUwyTrJ5g5WAJK2Bp%2Ffaol%2Bpuo%2FVvxhW15RM5fd9URtYRnc8jwAuGvj6grsEU04BmwvalnwC%2B%2FnTelkLiFu6SzEsOe7VBYl%2FtdMVjL HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 444
                Content-Type: application/reports+json
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:25:49 UTC444OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 39 31 38 38 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 39 39 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 32 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 62 65 6c 61 73 74 69 6e 67 2e 6f 6e 6c 69 6e 65 2d 66 61 63 74 75 75 72 2e 63 6f 6d 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 36 33 2e 31 37 39 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72
                Data Ascii: [{"age":59188,"body":{"elapsed_time":199,"method":"GET","phase":"application","protocol":"h2","referrer":"https://belasting.online-factuur.com/","sampling_fraction":1.0,"server_ip":"104.21.63.179","status_code":403,"type":"http.error"},"type":"network-err
                2024-12-28 21:25:49 UTC168INHTTP/1.1 200 OK
                Content-Length: 0
                date: Sat, 28 Dec 2024 21:25:49 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.11.204979635.190.80.14432868C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-12-28 21:25:49 UTC504OUTPOST /report/v4?s=CQs5dvdRm4qbTB0CTrYWqoZpFh2GoJ%2Fhj6znbq%2Fbxj3LPdpF5d8ujZL9mGOcnVJS6B9xqjZSQTYLmTflrS6s%2FucqJ%2F%2BJHAGyn7MH1xkkfYPNq4XStOfXw2t7uKKQNwTDaPSACQ5Cul2uNPMu6E%2F2 HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 450
                Content-Type: application/reports+json
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2024-12-28 21:25:49 UTC450OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 38 36 34 33 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 34 39 39 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 32 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 37 31 2e 31 35 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 35 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 62 65 6c 61 73 74 69 6e 67 2e 6f 6e 6c 69 6e 65 2d
                Data Ascii: [{"age":58643,"body":{"elapsed_time":499,"method":"GET","phase":"application","protocol":"h2","referrer":"","sampling_fraction":1.0,"server_ip":"172.67.171.151","status_code":405,"type":"http.error"},"type":"network-error","url":"https://belasting.online-
                2024-12-28 21:25:49 UTC168INHTTP/1.1 200 OK
                Content-Length: 0
                date: Sat, 28 Dec 2024 21:25:49 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:16:24:39
                Start date:28/12/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff7d29f0000
                File size:2'742'376 bytes
                MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:16:24:40
                Start date:28/12/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2192,i,11073809685410328450,13977048154993170284,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2204 /prefetch:3
                Imagebase:0x7ff7d29f0000
                File size:2'742'376 bytes
                MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:6
                Start time:16:24:46
                Start date:28/12/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://belasting.online-factuur.com"
                Imagebase:0x7ff7d29f0000
                File size:2'742'376 bytes
                MD5 hash:BB7C48CDDDE076E7EB44022520F40F77
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly