Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N

Overview

General Information

Sample URL:https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
Analysis ID:1587978
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Suricata IDS alerts for network traffic
HTML page contains suspicious onload / onerror event
HTML page contains hidden javascript code
Suricata IDS alerts with low severity for network traffic

Classification

  • System is w10x64
  • chrome.exe (PID: 5432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5340 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,4319773435143623355,15980974666646975416,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-10T19:20:08.637472+010020566432Possible Social Engineering Attempted192.168.2.449742131.153.174.6443TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-10T19:20:07.244849+010020573331Successful Credential Theft Detected192.168.2.449741131.153.174.6443TCP

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NHTTP Parser: (new function(atob(this.dataset.digest)))();
Source: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NHTTP Parser: Base64 decoded: (function(){var e=[],b={};try{function c(a){if("object"===typeof a&&null!==a){var f={};function n(l){try{var k=a[l];switch(typeof k){case "object":if(null===k)break;case "function":k=k.toString()}f[l]=k}catch(t){e.push(t.message)}}for(var d in a)n(d);try{...
Source: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NHTTP Parser: No favicon

Networking

barindex
Source: Network trafficSuricata IDS: 2057333 - Severity 1 - ET PHISHING MAMBA Credential Phish Landing Page 2024-11-08 : 192.168.2.4:49741 -> 131.153.174.6:443
Source: Network trafficSuricata IDS: 2056643 - Severity 2 - ET PHISHING Javascript Browser Fingerprinting POST Request : 192.168.2.4:49742 -> 131.153.174.6:443
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /files/images/Logo.png HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: news.mortgagesolutionswithsynergy.com
Source: unknownHTTP traffic detected: POST /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N HTTP/1.1Host: news.mortgagesolutionswithsynergy.comConnection: keep-aliveContent-Length: 139291Cache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1Origin: https://news.mortgagesolutionswithsynergy.comContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123NAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Fri, 10 Jan 2025 18:20:06 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0X-Frame-Options: sameoriginX-XSS-Protection: 1X-Content-Type-Options: nosniffStrict-Transport-Security: max-age=2592000Referrer-Policy: origin-when-cross-originPermissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self)Link: <https://news.mortgagesolutionswithsynergy.com/wp-json/>; rel="https://api.w.org/"
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: classification engineClassification label: mal52.phis.win@16/5@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,4319773435143623355,15980974666646975416,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,4319773435143623355,15980974666646975416,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://news.mortgagesolutionswithsynergy.com/files/images/Logo.png0%Avira URL Cloudsafe
https://news.mortgagesolutionswithsynergy.com/favicon.ico0%Avira URL Cloudsafe
https://news.mortgagesolutionswithsynergy.com/wp-includes/images/w-logo-blue-white-bg.png0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.132
truefalse
    high
    news.mortgagesolutionswithsynergy.com
    131.153.174.6
    truetrue
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://news.mortgagesolutionswithsynergy.com/wp-includes/images/w-logo-blue-white-bg.pngtrue
      • Avira URL Cloud: safe
      unknown
      https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123Ntrue
        unknown
        https://news.mortgagesolutionswithsynergy.com/files/images/Logo.pngtrue
        • Avira URL Cloud: safe
        unknown
        https://news.mortgagesolutionswithsynergy.com/favicon.icotrue
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        131.153.174.6
        news.mortgagesolutionswithsynergy.comUnited States
        19437SS-ASHUStrue
        142.250.185.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1587978
        Start date and time:2025-01-10 19:18:59 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 8s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal52.phis.win@16/5@6/5
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.250.186.174, 173.194.76.84, 172.217.18.14, 172.217.16.142, 199.232.210.172, 192.229.221.95, 216.58.212.142, 172.217.18.110, 142.250.185.195, 142.250.186.110, 142.250.185.142, 2.23.242.162, 4.175.87.197, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
        Category:downloaded
        Size (bytes):4119
        Entropy (8bit):7.949120703870044
        Encrypted:false
        SSDEEP:96:h3bdWfcmTY+aRF1pXWZL2+42HGhIUc8KeLEd:hgXTY+as02mOB8XLEd
        MD5:000BF649CC8F6BF27CFB04D1BCDCD3C7
        SHA1:D73D2F6D74EC6CDCBAE07955592962E77D8AE814
        SHA-256:6BDB369337AC2496761C6F063BFFEA0AA6A91D4662279C399071A468251F51F0
        SHA-512:73D2EA5FFC572C1AE73F37F8F0FF25E945AFEE8E077B6EE42CE969E575CDC2D8444F90848EA1CB4D1C9EE4BD725AEE2B4576AFC25F17D7295A90E1CBFE6EDFD5
        Malicious:false
        Reputation:low
        URL:https://news.mortgagesolutionswithsynergy.com/wp-includes/images/w-logo-blue-white-bg.png
        Preview:.PNG........IHDR...P...P............IDATx..].xU...[..V..*).Kk...V.k..J]jKEl?...t...!.{.,...E........@....F.%.....B...N.y..w.....I{.o...;.s..3...WH......./.zBp.o,XW.......#Z.f...|mvD..9..F........y..o....1^.743l.......v..#.c.E&.e..hU1.{..........._cZ..We.v.....f.w....(..6|.Y.. I:x..-.&.......D........<.6.6.l....T..)...|....#..$g...VN.......!'/6.w..B.h.}....EV.......k.7" f.}.G.~#..M..+....G....iB......]..?+......'.j.GB..P%......\........../..%...&.8E...".........44.J...1.........S...........d.j..]ni%._..9.{.O?.H..6T.|A.GC..g...U.oDEt,?.0....~....q=.y.~.9.Z......c...v.._....$.0.2...F.9a.L..)..l...2...w...I..&....Vg......H.I..r......./....z.`..+...Z.^U.=..5aBpb..0< ../>.9.c....".I..0.3N,}}....|]Fb...Q.......W.....OQ..y;.....|.37..}.....(c.....X..`xX).;......<5S....>.9..G.:..=..0^.......l_<G......H....C.O.*.....Hk{..{....]Nc..B.8..}%>..w....Z...).....\..>....c..2...&..0'.DZJ.'~{Y....I....?........fR.a......;.<..lRG..n.....Q......Nf.6.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
        Category:dropped
        Size (bytes):4119
        Entropy (8bit):7.949120703870044
        Encrypted:false
        SSDEEP:96:h3bdWfcmTY+aRF1pXWZL2+42HGhIUc8KeLEd:hgXTY+as02mOB8XLEd
        MD5:000BF649CC8F6BF27CFB04D1BCDCD3C7
        SHA1:D73D2F6D74EC6CDCBAE07955592962E77D8AE814
        SHA-256:6BDB369337AC2496761C6F063BFFEA0AA6A91D4662279C399071A468251F51F0
        SHA-512:73D2EA5FFC572C1AE73F37F8F0FF25E945AFEE8E077B6EE42CE969E575CDC2D8444F90848EA1CB4D1C9EE4BD725AEE2B4576AFC25F17D7295A90E1CBFE6EDFD5
        Malicious:false
        Reputation:low
        Preview:.PNG........IHDR...P...P............IDATx..].xU...[..V..*).Kk...V.k..J]jKEl?...t...!.{.,...E........@....F.%.....B...N.y..w.....I{.o...;.s..3...WH......./.zBp.o,XW.......#Z.f...|mvD..9..F........y..o....1^.743l.......v..#.c.E&.e..hU1.{..........._cZ..We.v.....f.w....(..6|.Y.. I:x..-.&.......D........<.6.6.l....T..)...|....#..$g...VN.......!'/6.w..B.h.}....EV.......k.7" f.}.G.~#..M..+....G....iB......]..?+......'.j.GB..P%......\........../..%...&.8E...".........44.J...1.........S...........d.j..]ni%._..9.{.O?.H..6T.|A.GC..g...U.oDEt,?.0....~....q=.y.~.9.Z......c...v.._....$.0.2...F.9a.L..)..l...2...w...I..&....Vg......H.I..r......./....z.`..+...Z.^U.=..5aBpb..0< ../>.9.c....".I..0.3N,}}....|]Fb...Q.......W.....OQ..y;.....|.37..}.....(c.....X..`xX).;......<5S....>.9..G.:..=..0^.......l_<G......H....C.O.*.....Hk{..{....]Nc..B.8..}%>..w....Z...).....\..>....c..2...&..0'.DZJ.'~{Y....I....?........fR.a......;.<..lRG..n.....Q......Nf.6.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:very short file (no magic)
        Category:downloaded
        Size (bytes):1
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3:v:v
        MD5:68B329DA9893E34099C7D8AD5CB9C940
        SHA1:ADC83B19E793491B1C6EA0FD8B46CD9F32E592FC
        SHA-256:01BA4719C80B6FE911B091A7C05124B64EEECE964E09C058EF8F9805DACA546B
        SHA-512:BE688838CA8686E5C90689BF2AB585CEF1137C999B48C70B92F67A5C34DC15697B5D11C982ED6D71BE1E1E7F7B4E0733884AA97C3F7A339A8ED03577CF74BE09
        Malicious:false
        Reputation:low
        URL:https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Preview:.
        No static file info
        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
        2025-01-10T19:20:07.244849+01002057333ET PHISHING MAMBA Credential Phish Landing Page 2024-11-081192.168.2.449741131.153.174.6443TCP
        2025-01-10T19:20:08.637472+01002056643ET PHISHING Javascript Browser Fingerprinting POST Request2192.168.2.449742131.153.174.6443TCP
        TimestampSource PortDest PortSource IPDest IP
        Jan 10, 2025 19:19:55.906399012 CET49675443192.168.2.4173.222.162.32
        Jan 10, 2025 19:20:03.915494919 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:03.915565968 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:03.915637016 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:03.915843964 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:03.915870905 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.569319963 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.569926977 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:04.569993019 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.571033955 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.571122885 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:04.572824001 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:04.572895050 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.625973940 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:04.626014948 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:04.672821999 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:06.447417974 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.447468996 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.447534084 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.447915077 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.447956085 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.448000908 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.448165894 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.448179007 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.448472977 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.448497057 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.915612936 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.916137934 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:06.967582941 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:06.971393108 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.127160072 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.127188921 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.127778053 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.127815008 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.128570080 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.128612041 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.128673077 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.129472017 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.129489899 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.129534960 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.144474030 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.144686937 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.144745111 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.145682096 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.145823002 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.187334061 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.187431097 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.187434912 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.187460899 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.187465906 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.233424902 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.233426094 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.244843960 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.244870901 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.244889975 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.244946003 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.244971037 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.245002985 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.245008945 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.245049953 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.245985031 CET49741443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.246006966 CET44349741131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.265460968 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.307343960 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828528881 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828551054 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828573942 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828592062 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.828609943 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828628063 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828635931 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828644037 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.828644037 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.828660965 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.828665972 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.828685045 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.828711033 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.831175089 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:07.831221104 CET44349740131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:07.831273079 CET49740443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.017251015 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.017354012 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.017440081 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.017705917 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.017731905 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.037909031 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.038042068 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.038120985 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.038578033 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.038614988 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.634849072 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.635226965 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.635256052 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.636332035 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.636390924 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.636807919 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.636863947 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.636977911 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637038946 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637065887 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.637218952 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637250900 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.637340069 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637412071 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.637531996 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637550116 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.637653112 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637705088 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637715101 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.637778044 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.637785912 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.640402079 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.640861034 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.640916109 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.641321898 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.641637087 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:08.641705990 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:08.687222958 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:09.861736059 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:09.861839056 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:09.861907959 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:09.862799883 CET49742443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:09.862819910 CET44349742131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:09.891082048 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:09.931356907 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.394320011 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.394429922 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.394803047 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.412844896 CET49743443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.412883043 CET44349743131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.415221930 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.415293932 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.415374994 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.415627956 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.415647984 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.909897089 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.910201073 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.910233974 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.911415100 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.911761045 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.911911011 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:10.911916018 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.911942959 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:10.952260017 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.020216942 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.020247936 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.020298958 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.020318985 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.020329952 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.020365000 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.021862984 CET49747443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.021881104 CET44349747131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.040421009 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.040513039 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.040591002 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.040803909 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.040839911 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.409993887 CET4972380192.168.2.42.22.50.131
        Jan 10, 2025 19:20:11.415069103 CET80497232.22.50.131192.168.2.4
        Jan 10, 2025 19:20:11.415121078 CET4972380192.168.2.42.22.50.131
        Jan 10, 2025 19:20:11.504437923 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.508522987 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.508563042 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.509641886 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.509704113 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.513154030 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.513263941 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.513360023 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.555329084 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.561976910 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.561990976 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.608905077 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.615425110 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.615457058 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.615521908 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.615545034 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.615562916 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:11.615622044 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.618199110 CET49751443192.168.2.4131.153.174.6
        Jan 10, 2025 19:20:11.618216038 CET44349751131.153.174.6192.168.2.4
        Jan 10, 2025 19:20:14.523108006 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:14.523194075 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:20:14.523350000 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:14.564513922 CET49737443192.168.2.4142.250.185.132
        Jan 10, 2025 19:20:14.564543009 CET44349737142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:03.973488092 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:03.973545074 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:03.973604918 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:03.973920107 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:03.973932028 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:04.605283976 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:04.605566025 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:04.605585098 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:04.605891943 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:04.606230021 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:04.606278896 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:04.659352064 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:14.527064085 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:14.527137995 CET44349833142.250.185.132192.168.2.4
        Jan 10, 2025 19:21:14.534557104 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:14.563740015 CET49833443192.168.2.4142.250.185.132
        Jan 10, 2025 19:21:14.563776016 CET44349833142.250.185.132192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jan 10, 2025 19:20:00.199131012 CET53621341.1.1.1192.168.2.4
        Jan 10, 2025 19:20:00.248354912 CET53536221.1.1.1192.168.2.4
        Jan 10, 2025 19:20:01.231122017 CET53596621.1.1.1192.168.2.4
        Jan 10, 2025 19:20:03.907347918 CET5262953192.168.2.41.1.1.1
        Jan 10, 2025 19:20:03.907598019 CET5847153192.168.2.41.1.1.1
        Jan 10, 2025 19:20:03.914346933 CET53526291.1.1.1192.168.2.4
        Jan 10, 2025 19:20:03.914385080 CET53584711.1.1.1192.168.2.4
        Jan 10, 2025 19:20:06.416671038 CET6174253192.168.2.41.1.1.1
        Jan 10, 2025 19:20:06.416856050 CET4943353192.168.2.41.1.1.1
        Jan 10, 2025 19:20:06.432914972 CET53617421.1.1.1192.168.2.4
        Jan 10, 2025 19:20:06.453182936 CET53494331.1.1.1192.168.2.4
        Jan 10, 2025 19:20:11.025857925 CET5096053192.168.2.41.1.1.1
        Jan 10, 2025 19:20:11.026002884 CET6390053192.168.2.41.1.1.1
        Jan 10, 2025 19:20:11.033312082 CET53509601.1.1.1192.168.2.4
        Jan 10, 2025 19:20:11.040024042 CET53639001.1.1.1192.168.2.4
        Jan 10, 2025 19:20:11.928119898 CET138138192.168.2.4192.168.2.255
        Jan 10, 2025 19:20:18.307800055 CET53597341.1.1.1192.168.2.4
        Jan 10, 2025 19:20:37.351634026 CET53545901.1.1.1192.168.2.4
        Jan 10, 2025 19:20:59.259917974 CET53617231.1.1.1192.168.2.4
        Jan 10, 2025 19:20:59.992867947 CET53616521.1.1.1192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Jan 10, 2025 19:20:06.453248978 CET192.168.2.41.1.1.1c239(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 10, 2025 19:20:03.907347918 CET192.168.2.41.1.1.10x9fa1Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 10, 2025 19:20:03.907598019 CET192.168.2.41.1.1.10xf936Standard query (0)www.google.com65IN (0x0001)false
        Jan 10, 2025 19:20:06.416671038 CET192.168.2.41.1.1.10xbb14Standard query (0)news.mortgagesolutionswithsynergy.comA (IP address)IN (0x0001)false
        Jan 10, 2025 19:20:06.416856050 CET192.168.2.41.1.1.10x4cbfStandard query (0)news.mortgagesolutionswithsynergy.com65IN (0x0001)false
        Jan 10, 2025 19:20:11.025857925 CET192.168.2.41.1.1.10xf728Standard query (0)news.mortgagesolutionswithsynergy.comA (IP address)IN (0x0001)false
        Jan 10, 2025 19:20:11.026002884 CET192.168.2.41.1.1.10x3910Standard query (0)news.mortgagesolutionswithsynergy.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 10, 2025 19:20:03.914346933 CET1.1.1.1192.168.2.40x9fa1No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
        Jan 10, 2025 19:20:03.914385080 CET1.1.1.1192.168.2.40xf936No error (0)www.google.com65IN (0x0001)false
        Jan 10, 2025 19:20:06.432914972 CET1.1.1.1192.168.2.40xbb14No error (0)news.mortgagesolutionswithsynergy.com131.153.174.6A (IP address)IN (0x0001)false
        Jan 10, 2025 19:20:11.033312082 CET1.1.1.1192.168.2.40xf728No error (0)news.mortgagesolutionswithsynergy.com131.153.174.6A (IP address)IN (0x0001)false
        • news.mortgagesolutionswithsynergy.com
        • https:
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449741131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:07 UTC761OUTGET /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:07 UTC158INHTTP/1.1 200 OK
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:06 GMT
        Content-Type: text/html; charset=UTF-8
        Transfer-Encoding: chunked
        Connection: close
        2025-01-10 18:20:07 UTC2888INData Raw: 62 33 63 0d 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 45 64 67 65 22 3e 0a 20 20 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 64 69 76 20 69 64 3d 22 72 6f 6f 74 22 3e 0a 20 20 20 20 20 20 3c 69 6d 67
        Data Ascii: b3c<!DOCTYPE html><html lang="en"> <head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta http-equiv="X-UA-Compatible" content="IE=Edge"> </head> <body> <div id="root"> <img


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449740131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:07 UTC721OUTGET /files/images/Logo.png HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:07 UTC754INHTTP/1.1 404 Not Found
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:06 GMT
        Content-Type: text/html; charset=UTF-8
        Transfer-Encoding: chunked
        Connection: close
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Frame-Options: sameorigin
        X-XSS-Protection: 1
        X-Content-Type-Options: nosniff
        Strict-Transport-Security: max-age=2592000
        Referrer-Policy: origin-when-cross-origin
        Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self)
        Link: <https://news.mortgagesolutionswithsynergy.com/wp-json/>; rel="https://api.w.org/"
        2025-01-10 18:20:07 UTC15630INData Raw: 33 66 66 61 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 21 2d 2d 5b 69 66 20 49 45 20 37 5d 3e 0a 3c 68 74 6d 6c 20 63 6c 61 73 73 3d 22 69 65 20 69 65 37 22 20 64 69 72 3d 22 6c 74 72 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 20 70 72 65 66 69 78 3d 22 6f 67 3a 20 68 74 74 70 73 3a 2f 2f 6f 67 70 2e 6d 65 2f 6e 73 23 22 3e 0a 3c 21 5b 65 6e 64 69 66 5d 2d 2d 3e 0a 3c 21 2d 2d 5b 69 66 20 49 45 20 38 5d 3e 0a 3c 68 74 6d 6c 20 63 6c 61 73 73 3d 22 69 65 20 69 65 38 22 20 64 69 72 3d 22 6c 74 72 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 20 70 72 65 66 69 78 3d 22 6f 67 3a 20 68 74 74 70 73 3a 2f 2f 6f 67 70 2e 6d 65 2f 6e 73 23 22 3e 0a 3c 21 5b 65 6e 64 69 66 5d 2d 2d 3e 0a 3c 21 2d 2d 5b 69 66 20 21 28 49 45 20 37 29 20 26 20 21 28 49 45 20
        Data Ascii: 3ffa<!DOCTYPE html>...[if IE 7]><html class="ie ie7" dir="ltr" lang="en-US" prefix="og: https://ogp.me/ns#"><![endif]-->...[if IE 8]><html class="ie ie8" dir="ltr" lang="en-US" prefix="og: https://ogp.me/ns#"><![endif]-->...[if !(IE 7) & !(IE


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.449742131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:08 UTC1041OUTPOST /n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        Content-Length: 139291
        Cache-Control: max-age=0
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        Origin: https://news.mortgagesolutionswithsynergy.com
        Content-Type: application/x-www-form-urlencoded
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: navigate
        Sec-Fetch-Dest: document
        Referer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:08 UTC16384OUTData Raw: 64 61 74 61 3d 25 37 42 25 32 32 73 63 72 65 65 6e 25 32 32 25 33 41 25 37 42 25 32 32 61 76 61 69 6c 57 69 64 74 68 25 32 32 25 33 41 31 32 38 30 25 32 43 25 32 32 61 76 61 69 6c 48 65 69 67 68 74 25 32 32 25 33 41 39 38 34 25 32 43 25 32 32 77 69 64 74 68 25 32 32 25 33 41 31 32 38 30 25 32 43 25 32 32 68 65 69 67 68 74 25 32 32 25 33 41 31 30 32 34 25 32 43 25 32 32 63 6f 6c 6f 72 44 65 70 74 68 25 32 32 25 33 41 32 34 25 32 43 25 32 32 70 69 78 65 6c 44 65 70 74 68 25 32 32 25 33 41 32 34 25 32 43 25 32 32 61 76 61 69 6c 4c 65 66 74 25 32 32 25 33 41 30 25 32 43 25 32 32 61 76 61 69 6c 54 6f 70 25 32 32 25 33 41 30 25 32 43 25 32 32 6f 72 69 65 6e 74 61 74 69 6f 6e 25 32 32 25 33 41 25 32 32 25 35 42 6f 62 6a 65 63 74 2b 53 63 72 65 65 6e 4f 72 69 65
        Data Ascii: data=%7B%22screen%22%3A%7B%22availWidth%22%3A1280%2C%22availHeight%22%3A984%2C%22width%22%3A1280%2C%22height%22%3A1024%2C%22colorDepth%22%3A24%2C%22pixelDepth%22%3A24%2C%22availLeft%22%3A0%2C%22availTop%22%3A0%2C%22orientation%22%3A%22%5Bobject+ScreenOrie
        2025-01-10 18:20:08 UTC16384OUTData Raw: 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 58 4d 4c 44 6f 63 75 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 58 4d 4c 44 6f 63 75 6d 65 6e 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 57 72 69 74 61 62 6c 65 53 74 72 65 61 6d 44 65 66 61 75 6c 74 57 72 69 74 65 72 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 57 72 69 74 61 62 6c 65 53 74 72 65 61 6d 44 65 66 61 75 6c 74 57 72 69 74 65 72 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 57 72 69 74 61 62 6c 65 53 74 72 65 61 6d 44 65 66 61 75 6c 74 43 6f 6e 74 72 6f 6c 6c 65
        Data Ascii: +%5Bnative+code%5D+%7D%22%2C%22XMLDocument%22%3A%22function+XMLDocument%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22WritableStreamDefaultWriter%22%3A%22function+WritableStreamDefaultWriter%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22WritableStreamDefaultControlle
        2025-01-10 18:20:08 UTC16384OUTData Raw: 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 53 56 47 41 45 6c 65 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 53 56 47 41 45 6c 65 6d 65 6e 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 52 65 73 70 6f 6e 73 65 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 52 65 73 70 6f 6e 73 65 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 52 65 73 69 7a 65 4f 62 73 65 72 76 65 72 53 69 7a 65 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 52 65 73 69 7a 65 4f 62 73 65 72 76 65 72 53 69 7a 65 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61
        Data Ascii: 5Bnative+code%5D+%7D%22%2C%22SVGAElement%22%3A%22function+SVGAElement%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22Response%22%3A%22function+Response%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22ResizeObserverSize%22%3A%22function+ResizeObserverSize%28%29+%7B+%5Bna
        2025-01-10 18:20:08 UTC16384OUTData Raw: 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 48 54 4d 4c 4d 65 6e 75 45 6c 65 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 48 54 4d 4c 4d 65 6e 75 45 6c 65 6d 65 6e 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 48 54 4d 4c 4d 65 64 69 61 45 6c 65 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 48 54 4d 4c 4d 65 64 69 61 45 6c 65 6d 65 6e 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 48 54 4d 4c 4d 61 72 71 75 65 65 45 6c 65 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 48 54 4d 4c 4d 61 72 71 75 65 65 45
        Data Ascii: native+code%5D+%7D%22%2C%22HTMLMenuElement%22%3A%22function+HTMLMenuElement%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22HTMLMediaElement%22%3A%22function+HTMLMediaElement%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22HTMLMarqueeElement%22%3A%22function+HTMLMarqueeE
        2025-01-10 18:20:08 UTC16384OUTData Raw: 37 44 25 32 32 25 32 43 25 32 32 41 62 6f 72 74 53 69 67 6e 61 6c 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 41 62 6f 72 74 53 69 67 6e 61 6c 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 41 62 6f 72 74 43 6f 6e 74 72 6f 6c 6c 65 72 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 41 62 6f 72 74 43 6f 6e 74 72 6f 6c 6c 65 72 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 65 76 65 6e 74 25 32 32 25 33 41 25 32 32 25 35 42 6f 62 6a 65 63 74 2b 45 76 65 6e 74 25 35 44 25 32 32 25 32 43 25 32 32 6f 66 66 73 63 72 65 65 6e 42 75 66 66 65 72 69 6e 67 25 32 32 25 33 41 74 72 75 65 25 32 43 25 32
        Data Ascii: 7D%22%2C%22AbortSignal%22%3A%22function+AbortSignal%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22AbortController%22%3A%22function+AbortController%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22event%22%3A%22%5Bobject+Event%5D%22%2C%22offscreenBuffering%22%3Atrue%2C%2
        2025-01-10 18:20:08 UTC16384OUTData Raw: 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 55 53 42 49 73 6f 63 68 72 6f 6e 6f 75 73 4f 75 74 54 72 61 6e 73 66 65 72 50 61 63 6b 65 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 55 53 42 49 73 6f 63 68 72 6f 6e 6f 75 73 4f 75 74 54 72 61 6e 73 66 65 72 50 61 63 6b 65 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 55 53 42 49 73 6f 63 68 72 6f 6e 6f 75 73 4f 75 74 54 72 61 6e 73 66 65 72 52 65 73 75 6c 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 55 53 42 49 73 6f 63 68 72 6f 6e 6f 75 73 4f 75 74 54 72 61 6e 73 66 65 72 52 65 73 75 6c 74 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32
        Data Ascii: ode%5D+%7D%22%2C%22USBIsochronousOutTransferPacket%22%3A%22function+USBIsochronousOutTransferPacket%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22USBIsochronousOutTransferResult%22%3A%22function+USBIsochronousOutTransferResult%28%29+%7B+%5Bnative+code%5D+%7D%22
        2025-01-10 18:20:08 UTC16384OUTData Raw: 64 69 61 53 74 72 65 61 6d 54 72 61 63 6b 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 74 72 65 61 6d 45 76 65 6e 74 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 74 72 65 61 6d 41 75 64 69 6f 53 6f 75 72 63 65 4e 6f 64 65 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 74 72 65 61 6d 41 75 64 69 6f 44 65 73 74 69 6e 61 74 69 6f 6e 4e 6f 64 65 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 74 72 65 61 6d 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 6f 75 72 63 65 48 61 6e 64 6c 65 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 53 6f 75 72 63 65 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 52 65 63 6f 72 64 65 72 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 51 75 65 72 79 4c 69 73 74 45 76 65 6e 74 25 32 32 25 32 43 25 32 32 4d 65 64 69 61 51 75 65 72 79 4c 69 73 74 25 32
        Data Ascii: diaStreamTrack%22%2C%22MediaStreamEvent%22%2C%22MediaStreamAudioSourceNode%22%2C%22MediaStreamAudioDestinationNode%22%2C%22MediaStream%22%2C%22MediaSourceHandle%22%2C%22MediaSource%22%2C%22MediaRecorder%22%2C%22MediaQueryListEvent%22%2C%22MediaQueryList%2
        2025-01-10 18:20:08 UTC16384OUTData Raw: 74 43 6c 75 73 74 65 72 25 32 32 25 32 43 25 32 32 63 72 65 64 65 6e 74 69 61 6c 6c 65 73 73 25 32 32 25 32 43 25 32 32 73 70 65 65 63 68 53 79 6e 74 68 65 73 69 73 25 32 32 25 32 43 25 32 32 6f 6e 63 6f 6e 74 65 6e 74 76 69 73 69 62 69 6c 69 74 79 61 75 74 6f 73 74 61 74 65 63 68 61 6e 67 65 25 32 32 25 32 43 25 32 32 6f 6e 73 63 72 6f 6c 6c 65 6e 64 25 32 32 25 32 43 25 32 32 41 6e 69 6d 61 74 69 6f 6e 50 6c 61 79 62 61 63 6b 45 76 65 6e 74 25 32 32 25 32 43 25 32 32 41 6e 69 6d 61 74 69 6f 6e 54 69 6d 65 6c 69 6e 65 25 32 32 25 32 43 25 32 32 43 53 53 41 6e 69 6d 61 74 69 6f 6e 25 32 32 25 32 43 25 32 32 43 53 53 54 72 61 6e 73 69 74 69 6f 6e 25 32 32 25 32 43 25 32 32 44 6f 63 75 6d 65 6e 74 54 69 6d 65 6c 69 6e 65 25 32 32 25 32 43 25 32 32 42 61 63
        Data Ascii: tCluster%22%2C%22credentialless%22%2C%22speechSynthesis%22%2C%22oncontentvisibilityautostatechange%22%2C%22onscrollend%22%2C%22AnimationPlaybackEvent%22%2C%22AnimationTimeline%22%2C%22CSSAnimation%22%2C%22CSSTransition%22%2C%22DocumentTimeline%22%2C%22Bac
        2025-01-10 18:20:08 UTC8219OUTData Raw: 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 63 72 65 61 74 65 41 74 74 72 69 62 75 74 65 4e 53 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 63 72 65 61 74 65 41 74 74 72 69 62 75 74 65 4e 53 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 63 72 65 61 74 65 43 44 41 54 41 53 65 63 74 69 6f 6e 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 63 72 65 61 74 65 43 44 41 54 41 53 65 63 74 69 6f 6e 25 32 38 25 32 39 2b 25 37 42 2b 25 35 42 6e 61 74 69 76 65 2b 63 6f 64 65 25 35 44 2b 25 37 44 25 32 32 25 32 43 25 32 32 63 72 65 61 74 65 43 6f 6d 6d 65 6e 74 25 32 32 25 33 41 25 32 32 66 75 6e 63 74 69 6f 6e 2b 63 72 65 61 74 65 43 6f 6d
        Data Ascii: native+code%5D+%7D%22%2C%22createAttributeNS%22%3A%22function+createAttributeNS%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22createCDATASection%22%3A%22function+createCDATASection%28%29+%7B+%5Bnative+code%5D+%7D%22%2C%22createComment%22%3A%22function+createCom
        2025-01-10 18:20:09 UTC158INHTTP/1.1 200 OK
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:08 GMT
        Content-Type: text/html; charset=UTF-8
        Transfer-Encoding: chunked
        Connection: close
        2025-01-10 18:20:09 UTC11INData Raw: 31 0d 0a 0a 0d 0a 30 0d 0a 0d 0a
        Data Ascii: 10


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.449743131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:09 UTC711OUTGET /favicon.ico HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:10 UTC775INHTTP/1.1 302 Found
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:09 GMT
        Content-Type: text/html; charset=UTF-8
        Content-Length: 0
        Connection: close
        X-Frame-Options: sameorigin
        X-XSS-Protection: 1
        X-Content-Type-Options: nosniff
        Strict-Transport-Security: max-age=2592000
        Referrer-Policy: origin-when-cross-origin
        Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self)
        Link: <https://news.mortgagesolutionswithsynergy.com/wp-json/>; rel="https://api.w.org/"
        X-Redirect-By: WordPress
        Location: https://news.mortgagesolutionswithsynergy.com/wp-includes/images/w-logo-blue-white-bg.png


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        4192.168.2.449747131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:10 UTC743OUTGET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:11 UTC205INHTTP/1.1 200 OK
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:09 GMT
        Content-Type: image/png
        Content-Length: 4119
        Connection: close
        Last-Modified: Tue, 16 Nov 2021 00:04:01 GMT
        Accept-Ranges: bytes
        2025-01-10 18:20:11 UTC4119INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 50 00 00 00 50 08 06 00 00 00 8e 11 f2 ad 00 00 0f de 49 44 41 54 78 da e5 5d 09 78 55 c5 15 0e 5b c1 c8 56 10 d1 2a 29 9b 4b 6b ad c5 da 56 ad 6b b5 1b 4a 5d 6a 4b 45 6c 3f f5 ab b5 74 b7 04 12 21 09 7b 14 2c a0 a2 11 45 83 d9 13 b2 90 90 1d 92 40 c0 b0 84 b0 46 90 25 04 08 81 10 12 42 16 12 b2 4e e7 bf 79 93 cc 9d 77 97 b9 f7 bd 87 49 7b be 6f be f0 de 9b 3b cb b9 73 e6 9c f3 9f 33 83 97 d7 57 48 d7 cf 8b 1b ff ad a5 c9 2f d3 b2 7a 42 70 d2 96 6f 2c 58 57 f2 f5 80 98 9a 81 b3 23 5a bd 66 86 11 be 7c 6d 76 44 f3 d0 39 d1 17 46 06 c6 1c a2 cf a5 8d 08 8c 79 ab 9f 6f f8 b3 f4 b7 31 5e ff 37 34 33 6c d8 d8 c5 09 af de f9 76 ca e7 23 03 63 1b 45 26 f1 65 d8 dc 68 55 31 aa 7b 8d 7f e4 05 ca e0 08 fa ef
        Data Ascii: PNGIHDRPPIDATx]xU[V*)KkVkJ]jKEl?t!{,E@F%BNywI{o;s3WH/zBpo,XW#Zf|mvD9Fyo1^743lv#cE&ehU1{


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        5192.168.2.449751131.153.174.64435340C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-01-10 18:20:11 UTC404OUTGET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1
        Host: news.mortgagesolutionswithsynergy.com
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: */*
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: cors
        Sec-Fetch-Dest: empty
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2025-01-10 18:20:11 UTC205INHTTP/1.1 200 OK
        Server: nginx
        Date: Fri, 10 Jan 2025 18:20:10 GMT
        Content-Type: image/png
        Content-Length: 4119
        Connection: close
        Last-Modified: Tue, 16 Nov 2021 00:04:01 GMT
        Accept-Ranges: bytes
        2025-01-10 18:20:11 UTC4119INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 50 00 00 00 50 08 06 00 00 00 8e 11 f2 ad 00 00 0f de 49 44 41 54 78 da e5 5d 09 78 55 c5 15 0e 5b c1 c8 56 10 d1 2a 29 9b 4b 6b ad c5 da 56 ad 6b b5 1b 4a 5d 6a 4b 45 6c 3f f5 ab b5 74 b7 04 12 21 09 7b 14 2c a0 a2 11 45 83 d9 13 b2 90 90 1d 92 40 c0 b0 84 b0 46 90 25 04 08 81 10 12 42 16 12 b2 4e e7 bf 79 93 cc 9d 77 97 b9 f7 bd 87 49 7b be 6f be f0 de 9b 3b cb b9 73 e6 9c f3 9f 33 83 97 d7 57 48 d7 cf 8b 1b ff ad a5 c9 2f d3 b2 7a 42 70 d2 96 6f 2c 58 57 f2 f5 80 98 9a 81 b3 23 5a bd 66 86 11 be 7c 6d 76 44 f3 d0 39 d1 17 46 06 c6 1c a2 cf a5 8d 08 8c 79 ab 9f 6f f8 b3 f4 b7 31 5e ff 37 34 33 6c d8 d8 c5 09 af de f9 76 ca e7 23 03 63 1b 45 26 f1 65 d8 dc 68 55 31 aa 7b 8d 7f e4 05 ca e0 08 fa ef
        Data Ascii: PNGIHDRPPIDATx]xU[V*)KkVkJ]jKEl?t!{,E@F%BNywI{o;s3WH/zBpo,XW#Zf|mvD9Fyo1^743lv#cE&ehU1{


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:13:19:53
        Start date:10/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:13:19:58
        Start date:10/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2216,i,4319773435143623355,15980974666646975416,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:13:20:05
        Start date:10/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://news.mortgagesolutionswithsynergy.com/n/?c3Y9bzM2NV8xX29uZSZyYW5kPVlXRnhjSFE9JnVpZD1VU0VSMTkxMjIwMjRVMzcxMjE5Mjc=N0123N"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly